Security Risk Management Lead

Affirm

Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$165,000–$225,000 / yr
Posted
5 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $184k
This role $195k
$124k most similar roles pay here $236k

This role pays more than 66% of similar roles. Most pay $152,300–$215,306 — the shaded band above. At the midpoint, this role pays about $195k versus about $184k for comparable roles.

Based on 239 similar postings.

Employer

About Affirm

Affirm is a buy-now, pay-later (BNPL) financial technology company that offers point-of-sale installment loans to consumers, allowing them to split purchases into fixed monthly payments with transparent terms. Industry: Financial Technology & Consumer Lending

Affirm currently has 58 open roles on FindRole.

Listed pay typically runs $195,000–$255,000 across 57 roles with salary data.

Most-posted roles

View all roles at Affirm

At a glance

TL;DR · Security Risk Management Lead

The Security Risk Management Lead role at Affirm is a senior position within the evolving Security Risk Management team, which aims to transform traditional governance into an engineering-driven security program. This individual will design and implement solutions for complex technical and business problems, focusing on automating manual GRC tasks using Python and agentic coding platforms like Cursor and Claude. They will work closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and other stakeholders to assess and manage third-party security risks, translating requirements into scalable program solutions. The ideal candidate has 5+ years of experience in Information Security or Risk Management, hands-on experience with agentic coding tools, familiarity with cloud environments (AWS/GCP), and a strong background in industry-based information security frameworks.

What you'll do

  • Lead and mature Affirm's Security Third Party Program, designing and implementing processes and controls.
  • Build automation to replace manual GRC tasks using Python and agentic coding platforms like Cursor or Claude.
  • Design workflow orchestration across systems such as ticketing, GRC platforms, and cloud control planes.
  • Partner with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders on security risk management.
  • Evaluate third party security controls and provide clear recommendations to stakeholders and leadership.

What we're looking for

  • 5+ years of experience in Information Security, Risk Management, or related field
  • Hands-on experience with agentic coding tools (Cursor, Claude) and Python scripting
  • Familiarity with cloud environments (AWS, GCP), IAM, logging, and security controls
  • Experience engineering solutions using Python, Claude, Cursor, or similar tooling
  • Knowledge of industry information security frameworks (NIST, ISO 2700x, PCI DSS)
  • Excellent communication skills for technical and non-technical teams
  • Professional certification in Information Security or Risk Management preferred

More like this

Similar roles

Security GRC Lead

Salesforce

Remote (San Francisco, CA) 17 days ago $148,500$223,900
FedRAMP NIST 800-53 AWS GovCloud Azure Government Google Cloud SOC 2 ISO 27001 PCI DSS HIPAA CMMC CI/CD DevSecOps GCP Azure AWS Terraform Docker
Remote

Cybersecurity Technical Lead

Booz Allen Hamilton

Lexington, MA 29 days ago $112,900$257,000
AWS Azure SIEM SOC Agile Python Bash REST APIs SQL NoSQL Terraform CI/CD IaC NIST RMF Elastic SIPRNet JWICS

Lead Security Operations Engineer

Take-Two Interactive

Austin, TX +1 8 days ago
SOAR Python SIEM EDR Palo Alto Networks Cortex XSOAR Tines Splunk Enterprise Security MITRE Att&CK NIST CI/CD

Lead, Cyber Defense & Incident Response

Prudential Financial

Newark, NJ 7 days ago $123,700$204,100
Splunk Kusto Query Language EDR Active Directory Entra M365 Azure AWS X-Ways EnCase Python PowerShell Bash MITRE ATT&CK Lockheed Martin’s Cyber Kill Chain CI/CD

Cybersecurity Engineering Service Lead

Pacific Life

Newport Beach, CA 30 days ago $137,610$168,190
NIST Cybersecurity Framework COBIT 2019 NIST Privacy Framework SDLC Application Security Configuration Management Kubernetes Docker CI/CD Python Go AWS Azure Google Cloud Platform PostgreSQL MongoDB Git Jira Confluence Prometheus Grafana
Hybrid

Risk Manager, Endpoint Security

Capital One Financial

McLean, VA +3 36 days ago $197,300$225,100
EDR Application Whitelisting VDI Data Loss Prevention Tools MDM MAM PAM NIST Cybersecurity Framework CISSP CISM CRISC AWS GCP