Home › Companies › Affirm › Security Risk Management Lead
Security Risk Management Lead
Affirm · Remote US · Remote · Active · $165,000–$225,000 / year · Greenhouse
Job facts
| Field | Value |
|---|---|
| Company | Affirm |
| Title | Security Risk Management Lead |
| Normalized title | - |
| Department / team | Information Security |
| Location | United States |
| Work model | Remote / Remote |
| Employment type | - |
| Salary | $165,000–$225,000 / year |
| Status | active |
| ATS provider | Greenhouse |
| Posted / first seen | 2026-06-05 / 2026-06-06 |
| Changed / last seen | 2026-06-06 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Affirm. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through Greenhouse. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| Department jobs | Active postings in Information Security. | Open |
| Work model jobs | Active Remote postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Affirm |
| Source | d75e74c2-8678-44e5-952f-d8f3f2802a53 |
| ATS provider | Greenhouse |
Description
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
What You'll Do
Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
Excellent written and verbal communications skills
Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
Attention to detail and experience with security practices and security tooling
Demonstrated ability to drive projects towards completion
Ability to understand and communicate technical issues to non-technical teams
Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
Base Pay Grade - L
Equity Grade - 5
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Full job record
| Job ID | 28d35780d71f902ecfec27cfc97e6b66251b1599 |
| Org ID | d0e2d504-3368-4b33-b253-c085fb0af06e |
| Source ID | d75e74c2-8678-44e5-952f-d8f3f2802a53 |
| Board ID | d75e74c2-8678-44e5-952f-d8f3f2802a53 |
| Provider | greenhouse |
| Provider Job Key | 7718808003 |
| Title | Security Risk Management Lead |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Remote US |
| Department | Information Security |
| Team | — |
| Employment Type | — |
| Workplace Type | remote |
| Remote Policy | remote |
| Country | United States |
| Region | — |
| City | — |
| Salary Raw | base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000 USA Sapphire base pay range (all other U |
| Salary Min | 165,000 |
| Salary Max | 225,000 |
| Salary Currency | USD |
| Salary Period | year |
| Source URL | https://job-boards.greenhouse.io/affirm/jobs/7718808003 |
| Apply URL | https://job-boards.greenhouse.io/affirm/jobs/7718808003 |
| First Seen At | 2026-06-06 07:35:17Z |
| Last Seen At | 2026-06-06 07:35:17Z |
| Last Checked At | 2026-06-06 07:35:17Z |
| Last Changed At | 2026-06-06 07:35:17Z |
| Inactive At | — |
| Source Posted At | 2026-06-05 14:29:43Z |
| Source Updated At | 2026-06-05 14:29:43Z |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=greenhouse/board=affirm/date=2026-06-06/2026-06-06T07-35-16-782Z-7407a32524bfdc26922d7404954e7cc29daba13af1a46009b6fed215b9387706.json |
Event Fields
{
"content_hash": "43d7f1f58211f79ff398f99f0fb1787efd568e037980568eb3c93641c310d7be",
"source_hash": "5b8bc180d6ec28ff4817920403332e1fd4a4c878959525cae626f7d205a27d1f",
"last_changed_at": "2026-06-06T07:35:17.230Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Remote US",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"salary_max": 225000,
"salary_min": 165000,
"inferred_at": "2026-06-06T07:35:17.162Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "Remote US",
"city": null,
"region": null,
"country": "United States",
"is_remote": true,
"confidence": 0.95
},
"countries": [
"United States"
]
},
"remote_policy": "remote",
"salary_period": "year",
"workplace_type": "remote",
"salary_currency": "USD"
}Extensions
{}Native Structured
{
"title": "Security Risk Management Lead",
"offices": [
{
"id": 4013021003,
"name": "Remote US",
"location": null,
"child_ids": [],
"parent_id": 4025301003
}
],
"language": "en",
"location": {
"name": "Remote US"
},
"metadata": [
{
"id": 4128552003,
"name": "External Department",
"value": "Information Security & IT",
"value_type": "single_select"
},
{
"id": 28890347003,
"name": "PERM Job?",
"value": false,
"value_type": "yes_no"
}
],
"updated_at": "2026-06-05T10:29:43-04:00",
"departments": [
{
"id": 4035727003,
"name": "Information Security",
"child_ids": [],
"parent_id": 4057206003
}
],
"company_name": "Affirm",
"requisition_id": 5757569003,
"first_published": "2026-06-05T10:29:43-04:00",
"application_deadline": null
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/28d35780d71f902ecfec27cfc97e6b66251b1599?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/d0e2d504-3368-4b33-b253-c085fb0af06eJSONGET https://api.bluedoor.sh/job-postings/v1/sources/d75e74c2-8678-44e5-952f-d8f3f2802a53JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/28d35780d71f902ecfec27cfc97e6b66251b1599/eventsJSON