Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Risk Management Lead

$165k - $225k

Affirm

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

Affirm values security as being critical to the company's continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.

The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
What You'll Do
  • Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
  • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
  • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
  • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
  • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
  • Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
  • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
  • Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
  • Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
  • Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
  • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
  • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
  • Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
  • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
  • 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
  • Familiarity with cloud environments (AWS, GCP, or Azure) - IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
  • Excellent written and verbal communications skills
  • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
  • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
  • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
  • Attention to detail and experience with security practices and security tooling
  • Demonstrated ability to drive projects towards completion
  • Ability to understand and communicate technical issues to non-technical teams
  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
Base Pay Grade - L

Equity Grade - 5

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000

USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000

Please note that visa sponsorship is not available for this position.

#LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We're extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It's On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Security Risk Management Lead in United States vacancy
  • $220k - $275k

     ...Global Safety, Intelligence, and Security (GSIS) team is responsible for...  ...health and safety, and crisis management — and it’s growing quickly as...  ...Threat Intelligence Lead to build and lead GSIS’s enterprise...  ...individuals and groups who may pose a risk to our people — this role owns... 
    Suggested
    For contractors
    Work at office
    Worldwide
    Visa sponsorship
    Flexible hours

    Anthropic

    San Francisco, CA
    4 days ago
  • $81.65k - $124.6k

     ...The Security Lead is a highly responsible and visible role within the company. It provides tactical...  ...support to the Security Operations Manager to ensure the security of teammates, capital...  ...enforcement agencies. Evaluates the risks faced by the company and use this... 
    Suggested
    Permanent employment
    Full time
    Work at office
    Local area
    Flexible hours
    Shift work
    Weekend work
    Afternoon shift

    Virgin Galactic

    Phoenix, AZ
    6 days ago
  • $164.78k - $314.96k

     ...empower our members to achieve financial security through highly competitive products,...  ...Principle-Based Reserving Life Actuary Lead, you will be responsible for technical leadership...  ...models for pricing, valuation, and/or risk management. Reviews laws and regulations to... 
    Suggested
    H1b
    Work at office
    Remote work
    Relocation package
    3 days per week

    USAA

    Charlotte, NC
    12 days ago
  •  ...brands, Toyota is growing and leading the future of mobility through...  ...versatile Senior Productivity Security Engineer to serve as a key technical...  ...-hand partner to the National Manager of Productivity Security. This...  .... Conduct threat modeling, risk assessments, control reviews,... 
    Suggested
    Relocation package

    Toyota

    Plano, TX
    4 days ago
  • $127k - $159k

     ...Title: Risk, Issue, and Opportunity Management Lead Belong. Connect. Grow. with KBR! KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities... 
    Suggested
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Flexible hours

    KBR

    El Segundo, CA
    12 hours ago
  • $124.3k - $234.6k

     ...Opportunity Adobe's Technology Governance, Risk & Compliance Organization plays a...  ...at scale. We seek a GRC Strategy & Security Insights Lead to drive a data driven shift in our...  ...expertise, sharp analytical and program management skills, and the ability to engage,... 
    Temporary work
    Local area
    Worldwide
    Shift work

    Adobe

    San Jose, CA
    2 days ago
  • $127.5k

     ...land, sea and cyber domains in the interest of national security. Job Title: Lead, Program Management Job Code: 36827 Job Location: Clifton, NJ Job...  ...documentation, and presentations Perform Risk Management and Mitigation in a pro-active fashion. Pro... 
    Contract work
    For subcontractor
    Local area
    Flexible hours

    L3Harris Technologies

    Clifton, NJ
    15 days ago
  •  ...land, sea and cyber domains in the interest of national security. Job Title: Lead, Program Management Job Code: 37046 Job Location: Palm Bay, FL...  ...expertise will shine as you support teams in crafting risk management and opportunity plans and collaborate with... 
    Local area

    L3Harris Technologies

    Palm Bay, FL
    10 days ago
  •  ...foundation underpins a compliance-first approach to risk management, ensuring the integrity and security of all financial activity within its systems. Bastion...  ...Overview We are hiring a Brand and Communications Lead to make Bastion known. Today, we have proven product-... 
    For contractors
    Local area
    Remote work

    Bastion LLC

    United States
    2 days ago
  • $185k - $200k

     ...Treasury Lead New York, New York, United States; San Francisco...  ...and production inference, with security, observability, and control...  ...investments, vendor obligations, cash management, hedging, and financial...  ..., and new capital raises Risk management Establish counterparty... 
    Temporary work
    Work at office
    Work from home
    Flexible hours
    2 days per week

    Lightning AI

    New York, NY
    5 days ago
  • $127.5k - $236.5k

     ...land, sea and cyber domains in the interest of national security. Job Title: Lead, Program Management Job Code: 37830 Job Location: Mason, OH Job...  ...earned value management, integrated master schedules, risk management, and formal gate or milestone reviews Experience... 
    Contract work
    Local area
    Flexible hours

    L3Harris

    Mason, OH
    1 day ago
  • $106.1k - $214.6k

    Fraud Strategy Lead, Sr Job Locations US-IL-Chicago | US-IN-Evansville | US-MN-Lake Elmo Category/Function Risk/Security Position Type Regular Full-Time Requisition ID...  ...role partners closely with Risk Management, Technology, Compliance, and product... 
    Full time

    Old National Bank

    Evansville, IN
    14 days ago
  • $185k - $200k

     ...of the world's preeminent specialty risk underwriting organizations. Designed...  ...to be resilient, Ascot offers clients leading financial security while delivering bespoke products and...  ..., UK/EU guidance, model risk management) * Continue to improve and define governance... 
    Temporary work
    Work at office
    Local area
    Flexible hours

    Ascot Group

    Iselin, NJ
    12 hours ago
  • $137.61k - $168.19k

     ...Senior Security Engineer Providing for loved ones, planning rewarding...  ...within our Operational Risk and Resilience (OR&R) team. In...  ...support effective enterprise risk management. Owning the design, governance...  ...with the Engineering Service Lead and Service Manager, you'll help... 
    Work at office
    Remote work
    Flexible hours

    Pacific Life

    Newport Coast, CA
    3 days ago
  •  ...is seeking a Cybersecurity Assessment Lead for an upcoming program supporting a US...  ...cybersecurity assessment activities supporting Risk Management Framework (RMF) authorization processes...  ...This position leads independent security control validation activities, ensures RMF... 

    ANALYGENCE Inc

    Coronado, CA
    12 hours ago
  •  ...SOC Vulnerability Management AESS Lead - Senior ECS is seeking a SOC Vulnerability Management AESS...  ..., this senior role leads endpoint security scanning and validation operations, directs...  ...governance, and enterprise risk management objectives. Support Task... 
    Contract work

    ECS

    Fairfax, VA
    2 days ago
  •  ...Information Intel and Defense Lead Requisition ID: req...  ...) Division: Information Security Office Compensation: Depends...  ...remediation, and patch management. • Performs security monitoring...  ...actions. • Supports security risk assessments, audits, and compliance... 
    Full time
    Work at office
    Remote work

    Teacher Retirement System of Texas

    Austin, TX
    12 hours ago
  • $132.06k - $186.44k

     ...create great digital experiences quickly, securely, and reliably by processing, serving,...  ...trustworthy Internet. Come join us. Security Risk Lead Fastly helps people stay better...  ...experience and a Bachelor's degree in Management Information Systems, Computer Science,... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Fastly

    Denver, CO
    3 days ago
  •  ...the Role We are looking for a Security Architecture Lead to serve as the primary technical authority...  ...the overhead of administrative management. Project Steering: Lead cross-functional...  .... Architecture Strategy & Risk Management Maintain the Source... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    3 days ago
  •  ...Everforth ECS is seeking a Product Manager SME to work in the National Capital Region...  ...and operational analysts. • The Cloud Security Lead SME is a senior subject matter expert responsible...  ...voice on Zero Trust compliance, Risk Management Framework execution, and cloud... 
    Contract work

    ECS Limited

    Falls Church, VA
    3 days ago
  •  ...seeking a highly skilled and experienced AWS Security Lead to join our team. This position will be...  ...sensitive data, mitigate security risks, and ensure compliance with security...  ...implementing corrective measures. Risk Management: Identify, evaluate, and mitigate... 

    Photon

    Dallas, TX
    4 days ago
  • $110.5k - $205k

     ...sea and cyber domains in the interest of national security. Job Title: Lead, Supply Chain Program Manager Job Code : 38057 Job Location: Anaheim, CA (...  ...efforts, to complete product life cycle with a focus risk and opportunity management to ensure top notch... 
    Temporary work
    For subcontractor
    Local area
    Flexible hours

    L3Harris Technologies

    Anaheim, CA
    10 days ago
  • $98.4k - $199k

    PCI Compliance Lead Job Locations US-IN-Lafayette | US-MN-Lake Elmo | US-IL-Chicago...  ...-Evansville Category/Function Risk/Security Position Type Regular Full-Time...  ...Responsibilities The PCI Compliance Manager role is responsible for leading the organization... 
    Full time

    Old National Bank

    Indianapolis, IN
    14 days ago
  •  ...cyber domains in the interest of national security. Job Title: Lead, Subcontracts Job Code: 37930 Job...  ...Job Description: The Subcontracts Manager (SCM) is responsible for the overall...  ...material, labor hour, etc.) to best manage risk for both L3Harris and our customers.... 
    Contract work
    Work experience placement
    For subcontractor
    Work at office
    Local area

    L3Harris

    Palm Bay, FL
    3 days ago
  •  ...Oracle OTC Lead Procom is a leading provider of professional...  ...Application Development, Project Management, Quality Assurance, Business/...  ...Infrastructure & Network Services, Risk Management & Compliance,...  ...Continuity & Disaster Recovery, Security & Privacy Specialties,... 
    Permanent employment
    Contract work
    For contractors
    Flexible hours

    Procom

    Olmsted Falls, OH
    12 hours ago
  •  ...delivers effects-as-a-service to national security partners across five domains and more...  ...the tanker fleet. AIRMOB oversees fleet management, maintenance, and airworthiness, working...  ...training and technology. • Integrate SMS and risk management practices into training.... 
    Full time
    Temporary work
    Work at office
    Monday to Friday
    Shift work

    Metrea Management LLC

    Temecula, CA
    4 days ago
  •  ...delivers effects-as-a-service to national security partners across five domains and more...  ...the tanker fleet. AIRMOB oversees fleet management, maintenance, and airworthiness, working...  ...training resources. Integrate SMS and risk management practices into training. Stay... 
    Full time
    Temporary work
    Work at office
    Monday to Friday
    Shift work

    Metrea Management LLC

    Temecula, CA
    4 days ago
  • $141.3k - $211.9k

     ...that connect the world. Our Chief Security Office ensures that our assets are...  ...Bring your bold ideas and fearless risk-taking to redefine connectivity and...  ...As a Technology Risk: Vulnerability Management & Application Security Domain Lead, you will be responsible for overseeing... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Relocation

    AT&T

    Dallas, TX
    4 days ago
  • $101.6k - $152.4k

     ...Cybersecurity Governance, Risk and Regulations Specialist We're hiring a Cybersecurity Governance, Risk and Regulations Specialist to lead how we manage enterprise security risks and navigate the evolving regulatory landscape. If you thrive at the intersection of policy... 
    Full time
    Temporary work
    Flexible hours

    Schneider Electric

    Andover, MA
    2 hours ago
  • $78.75 - $113.75 per hour

     ...TS SCI W/ CI Poly Cleared Vulnerability/GRC Lead Our client, a leader in the HCM space is in need of a GRC/Vulnerability...  ...be working a hybrid schedule out of Reston VA, support security, compliance, and risk management initiatives. The Lead will be responsible for... 
    Hourly pay
    Contract work

    ClearBridge Technology Group

    Reston, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Risk Management Lead. Be the first to apply!