Security Risk Management Lead

Affirm

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$165,000–$225,000 / yr
Posted
98 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $182k
This role $195k
$123k most similar roles pay here $236k

This role pays more than 64% of similar roles. Most pay $154,600–$208,900 — the shaded band above. At the midpoint, this role pays about $195k versus about $182k for comparable roles.

Based on 239 similar postings.

Employer

About Affirm

Affirm is a buy-now, pay-later (BNPL) financial technology company that offers point-of-sale installment loans to consumers, allowing them to split purchases into fixed monthly payments with transparent terms. Industry: Financial Technology & Consumer Lending

Affirm currently has 60 open roles on FindRole.

Listed pay typically runs $195,000–$255,000 across 60 roles with salary data.

Most-posted roles

View all roles at Affirm

At a glance

TL;DR · Security Risk Management Lead

The Security Risk Management Lead joins the Security Risk Management team to transform traditional governance into an engineering-driven discipline. This role focuses on designing, developing, and implementing solutions for the Security Third Party Program by replacing manual GRC tasks with scalable, code-defined workflows. The individual will build automation for intake, triage, evidence collection, and reporting while managing a portfolio of complex security risk reviews. Key responsibilities include evaluating third-party cloud architectures in AWS or GCP environments and conducting light threat models on high-risk integrations. To succeed, the candidate must be proficient in Python and agentic coding tools like Cursor and Claude to build custom scripts and tools. The role requires expertise in information security frameworks such as NIST, ISO 2700x, and PCI DSS to manage risk across diverse third-party relationships and technical systems.

What you'll do

  • Lead and mature the Security Third Party Program by designing and implementing processes, controls, and operational workflows.
  • Build and maintain Python-based automations and agentic coding tools to replace manual GRC tasks like triage and evidence collection.
  • Design and operate workflow orchestrations across ticketing systems, GRC platforms, and cloud control planes.
  • Evaluate third-party security controls, cloud architectures (AWS/GCP), and integration patterns to provide risk recommendations.
  • Conduct light threat models on high-risk integrations in partnership with Security SMEs.
  • Develop dashboards and reporting mechanisms using SQL or BI tools to track risk trends and program performance.
  • Translate ambiguous business requirements into scalable technical solutions and decision frameworks for internal stakeholders.

What we're looking for

  • 5+ years of experience in Information Security, Risk Management, Engineering, or related roles.
  • Proficiency in Python to read, modify, run scripts, and build end-to-end automations.
  • Experience using agentic coding tools such as Cursor, Claude Code, or Copilot.
  • Familiarity with cloud environments including AWS, GCP, or Azure and associated security controls.
  • Experience with industry frameworks like NIST CSF, ISO 2700x, SOC1&2, PCI DSS, or NIST-800-53.
  • BA or BS degree in Information Security, Cyber Security, Computer Science, or a related field.
  • Professional certifications such as CISSP, CISM, CISA, or CRISC are preferred.
  • Excellent communication skills to translate technical issues for non-technical stakeholders.

More like this

Similar roles

Security Risk Management Specialist II

Affirm

Remote 24 days ago $130,000$180,000
Python Cursor Claude Agentic Coding Platforms AWS GCP Azure Low-code Platforms NIST ISO 27001 SOC 2 PCI DSS GRC Third Party Risk Management Security Governance Automation
3+ yrs exp Remote

Security Role Strategy Lead

Microsoft

Redmond, WA 36 days ago $106,400$203,600
AI Machine Learning Data Analytics Cybersecurity Risk Management Predictive Modeling Enterprise Software Technical Sales Governance Frameworks Automation
4+ yrs exp Hybrid

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Security Architecture & Engineering Lead

Leidos

Remote 42 days ago $107,900$195,050
Risk Management Framework (RMF) STIG ACAS eMASS Zero Trust Architecture DevSecOps Continuous ATO SDLC Systems Engineering Cybersecurity Architecture Vulnerability Management COTS GOTS Software Engineering
8+ yrs exp Remote

Lead, Information Security Regulatory & Compliance

Prudential Financial

Newark, NJ 16 days ago $114,500$188,900
ISO 27001 NIST SOC 1 NYDFS 23 NYCRR 500 FFIEC GRC Platforms Jira ServiceNow IAM ASM CDR Cloud Security Data Protection Information Security Governance
Hybrid

Senior Lead, Cloud Security Engineering

Northern Trust

Chicago, IL 99 days ago $114,500$194,700
Terraform Python AWS Azure GCP CI/CD GitHub Actions Wiz Microsoft Defender for Cloud Policy as Code Infrastructure as Code CSPM Okta Ping NIST 800-53 CIS Git
8+ yrs exp