Security Risk Management Specialist II
Affirm · Remote US
About this role
**Security Risk Management Specialist II** **About Affirm** Affirm is reinventing credit to make it more honest and friendly—giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest. **About the Team** Affirm values security as critical to the company’s continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance. We’re building an engineering-driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers. --- **About the Role** You’ll evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. You’ll apply security policy to real-world vendor decisions and ship automation using modern tooling (Python and agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. You’ll develop deep expertise in the security risk domain, partner closely with business and engineering stakeholders, and help transform Security Risk Management from a compliance-oriented function into a security engineering discipline. --- **What You’ll Do** - Conduct third-party security assessments: review vendor questionnaires, evaluate security controls, and document risk findings for the TPRM program. - Build and maintain automation to reduce manual GRC workflows using Python, low-code platforms, and agentic coding tools. - Configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent, repeatable workflow execution. - Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions. - Develop and maintain dashboards, metrics, and reporting to provide clear visibility into third-party risk posture. - Contribute to process improvements and program documentation to mature Affirm’s security governance over time. --- **What We Look For** - 3+ years of experience in Information Security, Risk Management, Compliance, or a related field. - Comfort using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and working knowledge of Python for scripting/automation. - Familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts. - Working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS. - Clear written and verbal communication; able to translate security risk concepts for both technical and non-technical audiences. - Hold (or be working toward) a professional certification such as CISSP, CISM, CISA, or CRISC (or equivalent practical experience). BA/BS in a relevant field is preferred. --- **Compensation & Benefits (Highlights)** - Base Pay Grade: 3 - Equity Grade: 4 - Visa sponsorship: **not available** for this position. - Remote: **#LI-Remote** (remote-first; some roles may require occasional office presence depending on proximity) **Base Pay Range (per year)** - USA Pacific (CA, WA, NY, NJ, CT): **$130,000 – $180,000** - USA Sapphire (all other U.S. states): **$115,000 – $165,000** **Benefits include** - 100% subsidized medical coverage (you and your dependents) - Dental and vision - Flexible Spending Wallets (technology, food, lifestyle needs, and family forming expenses) - Competitive vacation and holiday schedule - ESPP (employee stock pu
Listing freshness
CronJobs last confirmed this listing 9h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.