Senior Manager, Security Risk Management

Affirm Affirm · Fintech · United States · Remote · Information Security

Senior Manager to lead Security Governance and Security Third-Party Risk Management (TPRM) function. Owns program strategy, operational maturity, and stakeholder alignment. Drives policy and control frameworks, remediates audit findings, delivers KPIs, and grows a team for vendor diligence, monitoring, and governance at scale. Focuses on predictable, measurable operations, setting security risk posture, tightening governance, improving tooling/automation, and ensuring timely escalations.

What you'd actually do

  1. Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations).
  2. Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding.
  3. Own program KPIs, dashboards, and reporting (Jira STPRM Ops, AuditBoard, Sigma/BI, MetricStream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity.
  4. Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.
  5. Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress.

Skills

Required

  • 7+ years in information security, risk management, or GRC roles
  • minimum of 3 years managing teams
  • Demonstrated ownership of a TPRM program or security governance program
  • Strong knowledge of security frameworks (NIST, ISO)
  • Strong knowledge of compliance standards (SOC2, PCI)
  • Strong knowledge of vendor risk processes (IRQ/DDQ/SME assessments)
  • Hands-on familiarity with TPRM/GRC tooling and observability: AuditBoard (or equivalent), Jira, BI tools (Sigma/Tableau/Looker)
  • experience with integrations/APIs
  • Excellent stakeholder management
  • Proven experience translating audit findings into operational remediation plans and measurable outcomes
  • Strong communication skills
  • Practical experience with threat-modeling approaches
  • Practical experience with third-party integration security (API, SSO/OAuth/SAML, TLS)
  • Experience scaling automation for GRC/TPRM programs
  • Experience integrating security checks into CI/CD pipelines

Nice to have

  • fintech preferred
  • Certifications such as CISSP, CISM, CRISC, or similar
  • Prior experience in fintech or highly regulated industries

What the JD emphasized

  • security governance
  • third-party risk management
  • vendor risk
  • governance
  • risk management
  • security risk posture
  • governance and fourth-party oversight
  • security risk appetite
  • vendor risk and governance matters
  • program health reporting
  • security frameworks
  • compliance standards
  • vendor risk processes
  • TPRM/GRC tooling
  • third-party integration security
  • automation for GRC/TPRM programs
  • security checks into CI/CD pipelines