Security Risk Management Lead

🕒 Junho 5

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $165.000 - $225.000 / ano

⏰ Tempo Integral

🟠 Sênior

🔒 Seguros

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Affirm

Affirm

1001 - 5000 funcionários

Fundada em 2012

💳 Fintech

👥 B2C

🛍️ Comércio Eletrônico

💰 Post-IPO Equity em 2021-01

Fintech • B2C • eCommerce

A Affirm é uma empresa de tecnologia financeira que oferece um serviço de Buy Now, Pay Later (BNPL), permitindo que os consumidores façam compras e paguem ao longo do tempo com planos de pagamento flexíveis. A Affirm elimina taxas ocultas e juros compostos, fornecendo termos e condições claros aos seus usuários. A empresa também oferece o Affirm Card, um cartão de débito que permite solicitar o pagamento ao longo do tempo para compras de maior valor ou pagar à vista as menores. A Affirm faz parcerias com diversos varejistas em várias categorias, incluindo eletrônicos, vestuário e viagens, proporcionando aos clientes a conveniência de pagar ao longo do tempo no checkout, tanto online quanto em lojas físicas. Os serviços da Affirm são integrados ao Apple Pay, permitindo que os clientes efetuem pagamentos de forma fluida diretamente do iPhone ou iPad.

Descrição

• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.) • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management • Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership • Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence • Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance • Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering

🎯 Requisitos

• 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations • Excellent written and verbal communications skills • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience • Attention to detail and experience with security practices and security tooling • Demonstrated ability to drive projects towards completion • Ability to understand and communicate technical issues to non-technical teams • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus

🏖️ Benefícios

• Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

Candidatar-se

Vagas Similares

🕒 Junho 5

American Health Marketplace

1001 - 5000

🏥 Saúde

🛡️ Seguros

⚕️ Seguro de Saúde

Licensed Insurance Agent educating clients on Medicare plans and guiding them through the enrollment process. Join Catch Health's dedicated team in a supportive, remote environment with potential for advancement.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $20 / hora

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🔒 Seguros

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 4

KASHIO

51 - 200

💳 Fintech

☁️ SaaS

🤝 B2B

Compliance & Risk Management Director leading compliance strategy in fintech expansion across LATAM and U.S. Responsible for regulatory frameworks and risk management in a dynamic environment.

🇺🇸 Estados Unidos – Remoto (EUA)

💰 $500.000 Seed Round - KashIO em 2021-04

⏰ Tempo Integral

🟠 Sênior

🔴 Especialista

🔒 Seguros

🗣️🇺🇸🇬🇧 Inglês obrigatório

🗣️🇪🇸 Espanhol obrigatório

🕒 Junho 4

Recruit CRM

201 - 500

👥 RH Tech

🤖 Inteligência Artificial

☁️ SaaS

Insurance Reviewer II responsible for handling insurance calls, processing vouchers, and ensuring correct billing. Focus on securing payments from third-party payors with excellent customer service.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $18 - $26 / hora

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🔒 Seguros

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 4

Oscar

51 - 200

💼 Consultoria

🏗️ Construção

🏥 Saúde

Manager for Insurance Product Innovation at Oscar Health, leading development of insurance lifestyle product concepts. Collaborating cross-functionally to create scalable health solutions.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $122.212 - $160.404 / ano

💰 $140.000.000 Private Equity Round em 2020-12

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🔒 Seguros

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Junho 3

International Insurance Group, Inc.

51 - 200

💼 Consultoria

📦 Logística

🛡️ Seguros

Insurance Service Agent assisting bilingual customers at International Insurance Group. Offering personalized service and maintaining customer records while working remotely.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $37.500 - $45.000 / ano

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

🔒 Seguros

🗣️🇷🇴 Romeno obrigatório

🗣️🇺🇸🇬🇧 Inglês obrigatório