Security Risk Management Lead

Affirm Affirm · Fintech · United States · Remote · Information Security

This role focuses on building an engineering-driven security risk management program, automating manual GRC tasks using AI tools like Python, Cursor, and Claude, and integrating systems for workflow orchestration. The goal is to transform the function into a security engineering discipline.

What you'd actually do

  1. Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
  2. Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
  3. Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
  4. Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
  5. Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks

Skills

Required

  • 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
  • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
  • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
  • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
  • Demonstrated ability to drive projects towards completion
  • Ability to understand and communicate technical issues to non-technical teams

Nice to have

  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
  • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
  • Attention to detail and experience with security practices and security tooling

What the JD emphasized

  • security as being critical
  • engineering driven program
  • agentic coding platforms
  • security engineering discipline
  • agentic coding tools
  • security risk management

Other signals

  • AI-driven automation
  • Agentic workflows
  • Security engineering discipline