Role details
- At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.
- Affirm values security as being critical to the company's continued success.
- Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products.
- The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
- The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program.
- They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows.
- They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
What You'll Do
- Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
- Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
- Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
- Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
- Translate ambiguous business and security
requirements
into practical, scalable program solutions and decision frameworks
- Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
- Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
- Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
- Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
- Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
- Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
- Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
- Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
- Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
- 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
- Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
- Excellent written and verbal communications skills
- Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
- Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
- BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
- Attention to detail and experience with security practices and security tooling
- Demonstrated ability to drive projects towards completion
- Ability to understand and communicate technical issues to non-technical teams
- Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
Base Pay Grade - L
Equity Grade - 5
- Employees new to Affirm typically come in at the start of the pay range.
- Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
- Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
- USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
- USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000
- Please note that visa sponsorship is not available for this position.
#LI-Remote
Remote-first with flexibility built in
- Affirm is proud to be a remote-first company.
- Most roles can be done from almost anywhere within the country of employment.
- Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work.
- All new hires will be invited to attend an in-person onboarding experience.
Benefits
designed for you
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
- Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
- Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
- Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
- Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
- We're committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we're happy to help.
- For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
- By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.