安全风险管理负责人
Security Risk Management Lead
在Affirm,我们为那些重要的时刻而存在——让人们能够以清晰、可预测的方式分期付款,没有隐藏费用、没有意外,也不会在最重要的事情上做出妥协。
Affirm将安全视为公司持续成功的关键。我们的使命是培养一种安全文化,使公司能够成功构建诚实的金融产品。安全风险管理部门正在超越传统的治理、风险和合规;我们正在建立一个由工程驱动的项目,设计、自动化并扩展保护Affirm和我们客户的控制措施、工作流程和工具。
理想的候选人将在安全第三方计划和更广泛的安全部分风险管理工作范围内,设计、开发、配置和实施解决复杂技术和业务问题的解决方案。他们同样擅长使用现代工具(Python、Cursor、Claude和其他代理编码平台)制定政策并交付自动化,以用可扩展的、代码定义的工作流程取代手动的GRC工作。他们将作为专家,与业务和工程利益相关者进行沟通,并在将安全风险管理从合规导向的职能转变为安全工程学科的过程中发挥关键作用。
你将负责
- 领导并完善Affirm的安全第三方计划,包括流程、控制措施和操作工作流的设计、实施和持续改进
- 构建和维护自动化系统,以替代手动的GRC任务:受理、分类、证据收集、控制验证、跟踪、升级和报告,使用Python、低代码平台和代理编码工具(如Cursor、Claude等)
- 设计并运行跨系统的流程编排和集成,如工单系统、GRC平台、供应商管理工具、身份提供商和云控制平面
- 与采购、法律、工程、IT、合规、隐私和业务利益相关者紧密合作,评估和管理第三方关系中的安全风险
- 将模糊的业务和安全需求转化为实际的、可扩展的项目解决方案和决策框架
- 识别项目中手动流程的自动化机会,并亲自原型化解决方案,而不是等待工程队列
- 通过建立可重复的过程、服务级别预期、指标和报告来推动项目的运营卓越性
查看英文原文
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.
Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
What You'll Do
- Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
- Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
- Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
- Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
- Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
- Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
- Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
- Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
- Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
- Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
- Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
- Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
- Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
- Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
- 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
- Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
- Excellent written and verbal communications skills
- Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
- Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
- BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
- Attention to detail and experience with security practices and security tooling
- Demonstrated ability to drive projects towards completion
- Ability to understand and communicate technical issues to non-technical teams
- Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
Base Pay Grade - L
Equity Grade - 5
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Remote-first with flexibility built in
Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.
Benefits designed for you
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
- Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
- Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
- Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
- Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.
For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.