CronJobs

security jobs

Security Risk Management Specialist II

Affirm · Remote US

remotemid$115,000–$165,000Posted Aug 18, 2026PythonAWSGCPAzureNISTISO 27001SOC 2PCI DSS

Apply on the employer site

About this role

**Security Risk Management Specialist II** **About Affirm** Affirm is reinventing credit to make it more honest and friendly—giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest. **About the Team** Affirm values security as critical to the company’s continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance. We’re building an engineering-driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers. --- **About the Role** You’ll evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. You’ll apply security policy to real-world vendor decisions and ship automation using modern tooling (Python and agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. You’ll develop deep expertise in the security risk domain, partner closely with business and engineering stakeholders, and help transform Security Risk Management from a compliance-oriented function into a security engineering discipline. --- **What You’ll Do** - Conduct third-party security assessments: review vendor questionnaires, evaluate security controls, and document risk findings for the TPRM program. - Build and maintain automation to reduce manual GRC workflows using Python, low-code platforms, and agentic coding tools. - Configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent, repeatable workflow execution. - Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions. - Develop and maintain dashboards, metrics, and reporting to provide clear visibility into third-party risk posture. - Contribute to process improvements and program documentation to mature Affirm’s security governance over time. --- **What We Look For** - 3+ years of experience in Information Security, Risk Management, Compliance, or a related field. - Comfort using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and working knowledge of Python for scripting/automation. - Familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts. - Working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS. - Clear written and verbal communication; able to translate security risk concepts for both technical and non-technical audiences. - Hold (or be working toward) a professional certification such as CISSP, CISM, CISA, or CRISC (or equivalent practical experience). BA/BS in a relevant field is preferred. --- **Compensation & Benefits (Highlights)** - Base Pay Grade: 3 - Equity Grade: 4 - Visa sponsorship: **not available** for this position. - Remote: **#LI-Remote** (remote-first; some roles may require occasional office presence depending on proximity) **Base Pay Range (per year)** - USA Pacific (CA, WA, NY, NJ, CT): **$130,000 – $180,000** - USA Sapphire (all other U.S. states): **$115,000 – $165,000** **Benefits include** - 100% subsidized medical coverage (you and your dependents) - Dental and vision - Flexible Spending Wallets (technology, food, lifestyle needs, and family forming expenses) - Competitive vacation and holiday schedule - ESPP (employee stock pu

Listing freshness

CronJobs last confirmed this listing 9h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord