Security Risk Management Lead

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $165k - $225k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Affirm

Affirm

1001 - 5000 employees

Founded 2012

💳 Fintech

👥 B2C

🛍️ eCommerce

💰 Post-IPO Equity on 2021-01

Fintech • B2C • eCommerce

Affirm is a financial technology company that offers a 'Buy Now, Pay Later' service, allowing consumers to make purchases and pay for them over time with flexible payment plans. Affirm eliminates hidden fees and compound interest, providing clear terms and conditions for its users. The company also offers the Affirm Card, a debit card that allows users to request to pay over time for larger purchases or pay in full for smaller ones. Affirm partners with various retailers across multiple categories, including electronics, apparel, and travel, providing customers with the convenience of paying over time at checkout both online and in physical stores. Affirm's services are integrated with Apple Pay, enabling customers to make payments seamlessly from their iPhone or iPad.

📋 Description

• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.) • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management • Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership • Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence • Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance • Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering

🎯 Requirements

• 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations • Excellent written and verbal communications skills • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience • Attention to detail and experience with security practices and security tooling • Demonstrated ability to drive projects towards completion • Ability to understand and communicate technical issues to non-technical teams • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus

🏖️ Benefits

• Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

Apply Now

Similar Jobs

🔥 3 hours ago

TASC (Total Administrative Services Corporation)

501 - 1000

🤝 B2B

📋 Compliance

👥 HR Tech

Senior Security Engineer at TASC ensuring the confidentiality, integrity, and availability of systems and data. Providing leadership in security posture and developing scalable security solutions.

🔥 7 hours ago

Groundswell

201 - 500

🏛️ Government

☁️ SaaS

🏢 Enterprise

Senior Appian Developer Consultant at Groundswell, guiding federal agencies on complex Appian implementations. Leading technical teams and ensuring scalable solutions in a dynamic environment.

🔥 7 hours ago

Groundswell

201 - 500

🏛️ Government

☁️ SaaS

🏢 Enterprise

Senior Appian Developer Consultant at Groundswell providing integrated architecture support for federal agencies. Leading implementation teams and guiding clients in complex technical solutions.

🔥 7 hours ago

Motorola Solutions

10,000+ employees

🔐 Security

📡 Telecommunications

🏢 Enterprise

Cybersecurity CMMC Engineer evaluating and conducting assessments for defense contractors at Motorola Solutions. Ensuring compliance with cybersecurity standards for sensitive government information.

🔥 8 hours ago

Information Security Auditor at KirkpatrickPrice helping clients through security audits and implementing data protection controls. Seeking technologically savvy auditors who are passionate about client education.