Security Risk Management Lead

🕒 6 dias atrás

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $165.000 - $225.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Affirm

Affirm

1001 - 5000 funcionários

Fundada em 2012

💳 Fintech

👥 B2C

🛍️ Comércio Eletrônico

💰 Post-IPO Equity em 2021-01

Fintech • B2C • eCommerce

A Affirm é uma empresa de tecnologia financeira que oferece um serviço de Buy Now, Pay Later (BNPL), permitindo que os consumidores façam compras e paguem ao longo do tempo com planos de pagamento flexíveis. A Affirm elimina taxas ocultas e juros compostos, fornecendo termos e condições claros aos seus usuários. A empresa também oferece o Affirm Card, um cartão de débito que permite solicitar o pagamento ao longo do tempo para compras de maior valor ou pagar à vista as menores. A Affirm faz parcerias com diversos varejistas em várias categorias, incluindo eletrônicos, vestuário e viagens, proporcionando aos clientes a conveniência de pagar ao longo do tempo no checkout, tanto online quanto em lojas físicas. Os serviços da Affirm são integrados ao Apple Pay, permitindo que os clientes efetuem pagamentos de forma fluida diretamente do iPhone ou iPad.

Descrição

• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.) • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management • Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership • Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence • Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance • Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering

🎯 Requisitos

• 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations • Excellent written and verbal communications skills • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience • Attention to detail and experience with security practices and security tooling • Demonstrated ability to drive projects towards completion • Ability to understand and communicate technical issues to non-technical teams • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus

🏖️ Benefícios

• Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

Candidatar-se

Vagas Similares

🕒 6 dias atrás

TASC (Total Administrative Services Corporation)

501 - 1000

🤝 B2B

📋 Conformidade

👥 RH Tech

Senior Security Engineer at TASC ensuring the confidentiality, integrity, and availability of systems and data. Providing leadership in security posture and developing scalable security solutions.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 6 dias atrás

Switzerland Global Enterprise

51 - 200

🤝 B2B

🛍️ Comércio Eletrônico

Sr Staff Cyber Security Researcher leveraging cyber security knowledge to protect GE Vernova's global brand and business partners. Collaborating to create high-fidelity threat detection solutions.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $128.900 - $214.900 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 6 dias atrás

The Home Depot

10.000+ funcionários

🛒 Varejo

👥 B2C

Cybersecurity Engineer responsible for securing sensitive data and critical assets at The Home Depot. Troubleshooting incidents and collaborating on cybersecurity solutions to mitigate risks.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $50.000 - $130.000 / ano

💰 Debt Financing em 2007-07

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 6 dias atrás

Groundswell

201 - 500

🏛️ Governo

☁️ SaaS

🏢 Corporativo

Senior Appian Developer Consultant at Groundswell, guiding federal agencies on complex Appian implementations. Leading technical teams and ensuring scalable solutions in a dynamic environment.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $115.439 - $162.293 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 6 dias atrás

Groundswell

201 - 500

🏛️ Governo

☁️ SaaS

🏢 Corporativo

Senior Appian Developer Consultant at Groundswell providing integrated architecture support for federal agencies. Leading implementation teams and guiding clients in complex technical solutions.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $115.439 - $162.293 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório