Security Risk Management Specialist II

Affirm
United States
Workplace: RemoteFull timeUSD 115,000 - 180,000 annuallyFunction: Legal, Risk & ComplianceExperience: 3+ yearsEducation: bachelorsSkills: ["Collaboration","Communication","Process improvement","Cross-functional partnership","Risk analysis"]

Build and scale the Security Third Party Program by conducting third-party security assessments and translating security risk concepts for technical and non-technical stakeholders. Automate and refine code-defined GRC workflows using Python and agentic coding tools, configure integrations across ticketing/GRC/vendor systems, and maintain dashboards and metrics to improve third-party risk posture and program rigor.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Affirm
Affirm
1 day ago

Security Risk Management Specialist II

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Build and scale the Security Third Party Program by conducting third-party security assessments and translating security risk concepts for technical and non-technical stakeholders. Automate and refine code-defined GRC workflows using Python and agentic coding tools, configure integrations across ticketing/GRC/vendor systems, and maintain dashboards and metrics to improve third-party risk posture and program rigor.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Conduct third-party security assessments by reviewing vendor questionnaires, evaluating security controls, and documenting risk findings for the TPRM program.
  • •Build and maintain automation to reduce manual GRC workflows and improve program efficiency using Python and agentic coding tools.
  • •Configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent workflow execution.
  • •Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
  • •Develop and maintain dashboards, metrics, and reporting to provide stakeholders visibility into third-party risk posture.

Pay and Benefits

Salary: USD 115,000 - 180,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVisionEsppRemote Work

Key Requirements

  • •3+ years of experience in information security, risk management, compliance, or a related field.
  • •Working knowledge of Python for scripting or automation, and comfort using agentic coding tools (e.g., Cursor, Claude Code, Copilot).
  • •Familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
  • •Working knowledge of security frameworks/standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
  • •Hold (or be working toward) a professional certification such as CISSP, CISM, CISA, or CRISC (or equivalent practical experience).
Experience:3+ yearsInformation securityRisk managementComplianceThird-party riskGRC
Education:Bachelor's
Skills:CollaborationCommunicationProcess improvementCross-functional partnershipRisk analysis
Certifications:CISSPCISMCISACRISC
Languages:English
Tech Stack:PythonCursorClaudeClaude CodeCopilotAWSGCPAzureNISTISO 27001SOC 2PCI DSS

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Affirm
Provides point-of-sale lending and buy-now-pay-later (BNPL) solutions for consumers and merchants, enabling installment payments, consumer financing, and embedded financial services through APIs and partnerships with retailers and platforms.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn