Affirm logo

Affirm

Director, Information Technology & Security

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 9 days ago · Added 4 days ago

First listed 9 days ago and still open.

Salary

$300k to $360k per year

Location

United States only

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote US"
  • Job description states: "based in San Francisco or Los Angeles"

What Nomaders makes of it

  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

Remote US

The Director, Information Technology & Security will serve as a key member of the Bank's Management Team, serving as the Chief Information Security Officer, and will be responsible for establishing and leading the Bank's information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), this leader will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank's risk appetite, and protects customer and institutional data.

This is a blended leadership role requiring both high-level strategic influence and deep technical execution. You will lead the development of information security governance, technical controls, and oversight of infrastructure and engineering, ensuring a strong and scalable security posture from inception. This leader must be a practitioner at heart—willing to "roll up their sleeves" to lead the technical build phase, collaborate closely with engineering on architecture, and ensure security is integrated into every aspect of the Bank's systems and operations.

What You’ll Do

Oversee infrastructure design and IT Engineering

Information Security Program Development

Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.

Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.

Ensure alignment with the Bank’s overall risk management and governance frameworks.

Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.

Lead the technical build phase of the Bank's infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration.

Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance.

Cybersecurity and Threat Management

Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.

Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).

Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.

Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.

Third-Party and Affiliate Risk Oversight

Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.

Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.

Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.

Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data.

Data Governance and Privacy Protection

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

  • ·Base Pay Grade - T
  • ·Equity Grade - 14
  • ·USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Affirm, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$300k to $360k per year · You'll be taken to the employer's careers page.