Skip to main content

Security Risk Management Lead

Affirm
Remote - USUpdated 44d ago
Total compensation
$146k–$225k
Published total compensation range
Location
Remote - US
Remote eligibility
Employment
Full-time
Lead / Manager
Role family
Security
Fintech
Role skills
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About Affirm

Affirm is a financial technology company that provides a clear, predictable way to pay over time, with no hidden fees or surprises. Security is critical to the company's success, and the Security Risk Management team is evolving beyond traditional governance, risk, and compliance into an engineering-driven program that designs, automates, and scales controls, workflows, and tooling.

Role Overview

As the Security Risk Management Lead, you will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. You will shape policy and ship automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. You will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance-oriented function into a security engineering discipline.

Responsibilities

  • Lead and mature Affirm's Security Third Party Program, including design, implementation, and continuous improvement of processes, controls, and operational workflows.
  • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using Python, low-code platforms, and agentic coding tools (Cursor, Claude, etc.).
  • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes.
  • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third-party relationships.
  • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks.
  • Identify opportunities to automate manual processes and prototype solutions yourself.
  • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting.
  • Evaluate third-party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations.
  • Conduct light threat models on high-risk integrations and partner with Security SMEs for deeper diligence.
  • Manage and prioritize a portfolio of complex security risk reviews and initiatives.
  • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration.
  • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) to improve visibility into risk trends, bottlenecks, and program performance.
  • Act as a trusted advisor and SME on third-party security risk management.
  • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering.

Qualifications

  • 5+ years of experience in Information Security, Risk Management, Engineering, or relevant roles.
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end.
  • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and security risks/controls.
  • Excellent written and verbal communication skills.
  • Experience engineering solutions via Python, Claude, Cursor, or other agentic coding tooling.
  • Experience with industry-based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2 (SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.).
  • BA or BS degree in Information Security, Cyber Security, Computer Science, or related field, or commensurate experience.
  • Attention to detail and experience with security practices and security tooling.
  • Demonstrated ability to drive projects towards completion.
  • Ability to understand and communicate technical issues to non-technical teams.
  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus.

Compensation & Benefits

Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness, and tech spending, and benefits (including 100% subsidized medical coverage, dental, and vision for you and your dependents).

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000

Benefits include: health coverage at no cost (100% of premiums for employees and dependents), spending stipends for tech setup and health/wellness, flexible time off and generous holiday calendars, and an employee stock purchase plan (ESPP) that lets you buy Affirm stock at a discount.

Application Instructions

To apply, click the 'Submit Application' button on the job posting page. By clicking 'Submit Application,' you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.