IT Security Risk Management Lead

Posted 5 Days Ago
Easy Apply
Hiring Remotely in US
Remote
142K-210K Annually
3-5 Years Experience
Fintech
We create honest financial products that improve lives. Ready to make a difference?
The Role
Join Affirm as a Security Risk Management Lead to develop control frameworks, conduct audits, manage third-party risk, and ensure data protection and compliance. Collaborate with technical and non-technical stakeholders, communicate security risks, and establish security governance documentation. Ideal for individuals with project management skills, risk management experience, and knowledge of security frameworks.
Summary Generated by Built In

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

We are seeking a Security Risk Management Lead to join our Security Risk Management team at Affirm. The Security Risk Management team builds and deploys common governance, risk, and compliance processes and controls, conducts audits, and ensures that technologies and business processes are built with data protection and compliance in mind! Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products.

What You'll Do

  • Develop complementary control frameworks that define the security responsibilities of Affirm and its third parties, including vendors, merchants, and partners.
  • Mature our third-party security risk processes by working with a broad range of technical and non-technical stakeholders.
  • Own the end-to-end execution of third-party due diligence and issues management, ensuring alignment with stakeholders throughout.
  • Design and generate metrics and reports on risk indicators, issues, and the efficiency of our operations.
  • Support Legal in our contract reviews and negotiations to ensure appropriate security terms are in place.
  • Provide best-in-class support for our client-facing teams and security assurance to our business partners as well as find opportunities to enhance this program and build internal and external relationships.
  • Fluently communicate security risks to non-experts to empower our business with valuable, actionable information.
  • Develop, curate, and disseminate security governance documentation, ensuring awareness amongst stakeholders and employees.
  • Partner with engineering and IT to define and document policies and technical procedures for secure and compliant treatment of sensitive data.

What We Look For

  • Excellent project management and collaboration skills—setting goals and priorities, taking into account dependencies, and handling execution from start to finish.
  • A drive to solve difficult problems and evolve the status quo with technical and non-technical solutions—you’re never satisfied by just ticking a box.
  • Crystal clear verbal and written communication—people love how your emails and documentation tell them exactly what they need to know.
  • 3-5 years of risk management, information security, or other relevant experience working with technical teams and balancing risk against business need.
  • Passion for working with diverse teams and taking into account each perspective, e.g. as an auditor, engineer, business person, and more.
  • Knowledge of risk and control frameworks (e.g. NIST Cyber Security Framework, ISO 2700x, SOC1 & 2 (SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) and experience with security practices and solutions.


Pay Grade - L
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA base pay range (CA, WA, NY, NJ, CT) per year: $160,000 - $210,000
USA base pay range (all other U.S. states) per year: $142,000 - $192,000

Please note that visa sponsorship is not available for this position.
#LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include: 

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents 
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking "Submit Application," you acknowledge that you have read the Affirm Employment Privacy Policy for applicants within the United States, the EU Employee Notice Regarding Use of Personal Data (Poland) for applicants applying from Poland, the EU Employee Notice Regarding Use of Personal Data (Spain) for applicants applying from Spain, or the Affirm U.K. Limited Employee Notice Regarding Use of Personal Data for applicants applying from the United Kingdom, and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Top Skills

Nist

What the Team is Saying

Jeremy
Niki
Noam
The Company
HQ: San Francisco , CA
2,200 Employees
Remote Workplace
Year Founded: 2012

What We Do

Since our founding over a decade ago, our mission has been to deliver honest financial products that improve lives. That mission hasn’t changed—and it never will. At Affirm, we believe money shouldn’t dictate your direction in life. That it should open up options instead of limiting them, and help you get where you’re going without getting in your way. That’s why we offer people the financial flexibility to choose what works for them—in finances and in life.

Why Work With Us

Who is an Affirmer?
/noun/

Someone who believes finance shouldn’t be complicated. We come from a diverse set of backgrounds and we’re driven by the desire to improve lives through honest financial products. We define success by challenging one another to bring our best ideas to every single project—and we have fun while doing it.

Gallery

Gallery

Affirm Offices

Remote Workspace

Employees work remotely.

Affirm is a remote-first company! Our employees can work anywhere in the U.S. but if an office is more your style, we have office locations in San Francisco, Chicago, New York City, and Pittsburgh.

Typical time on-site: None
HQSan Francisco, CA
United Kingdom
Spain
Chicago, IL
New York, NY
Pittsburgh, PA
Toronto, ON
Warsaw, PL
Learn more

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account