Affirm logo

Affirm

Security Risk Management Lead

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 6 weeks ago · Added 5 days ago

Been open since 6 weeks ago, still being checked, but it has been live a while.

Salary

$165k to $225k per year

Location

United States only

Timezone

Not stated

Contract

Full-time

Experience

Lead

Category

Software

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "Remote US"
  • Job description states: "based in San Francisco or Los Angeles"

What Nomaders makes of it

  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.

The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.

What You'll Do

Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows

Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)

Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes

Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships

Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks

Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog

Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management

Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership

Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence

Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction

Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration

Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance

Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions

Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering

What We Look For

5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles

Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end

Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations

Excellent written and verbal communications skills

Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling

Requirements

  • ·Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
  • ·Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
  • ·BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
  • ·Attention to detail and experience with security practices and security tooling
  • ·Demonstrated ability to drive projects towards completion

Benefits

No benefits package published with this listing. Ask about it at first interview.

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Affirm, mentioning your remote working experience.
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$165k to $225k per year · You'll be taken to the employer's careers page.