Security Risk Management Specialist II
Affirm- Total compensation
- $115k–$180k Published total compensation range
- Location
- Remote - US Remote eligibility
- Employment
- Full-time Mid-level
About the job
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest. The Security Risk Management team is evolving beyond traditional GRC into an engineering-driven program that designs, automates, and scales controls, workflows, and tooling.
About the Role
The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They will apply security policy to vendor decisions and ship automation using Python, Cursor, Claude, and other agentic coding platforms to replace manual GRC work with scalable, code-defined workflows.
What You'll Do
- Conduct third-party security assessments, reviewing vendor questionnaires, evaluating security controls, and documenting risk findings.
- Build and maintain automation to reduce manual GRC workflows using Python, low-code platforms, and agentic coding tools.
- Configure and maintain integrations across ticketing, GRC, and vendor management platforms.
- Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews.
- Develop and maintain dashboards, metrics, and reporting for third-party risk posture.
- Contribute to process improvements and program documentation.
What We Look For
- 3+ years of experience in Information Security, Risk Management, Compliance, or related field.
- Comfort with agentic coding tools (e.g., Cursor, Claude Code, Copilot) and working knowledge of Python for scripting or automation.
- Familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
- Working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
- Clear communication and ability to translate security risk concepts for technical and non-technical audiences.
- Professional certification (CISSP, CISM, CISA, CRISC) or equivalent practical experience preferred.
Compensation & Benefits
Base pay ranges: USA Pacific (CA, WA, NY, NJ, CT): $130,000 - $180,000; USA Sapphire (all other U.S. states): $115,000 - $165,000. Total compensation may include equity rewards, monthly stipends for health, wellness, and tech spending, and benefits including 100% subsidized medical, dental, and vision coverage for you and your dependents. Visa sponsorship is not available.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.