Security Risk Management Specialist II

Affirm

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$130,000–$180,000 / yr
Posted
24 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $166k
This role $155k
$115k most similar roles pay here $212k

This role pays less than 53% of similar roles. Most pay $134,487–$197,400 — the shaded band above. At the midpoint, this role pays about $155k versus about $166k for comparable roles.

Based on 238 similar postings.

Employer

About Affirm

Affirm is a buy-now, pay-later (BNPL) financial technology company that offers point-of-sale installment loans to consumers, allowing them to split purchases into fixed monthly payments with transparent terms. Industry: Financial Technology & Consumer Lending

Affirm currently has 60 open roles on FindRole.

Listed pay typically runs $195,000–$255,000 across 60 roles with salary data.

Most-posted roles

View all roles at Affirm

At a glance

TL;DR · Security Risk Management Specialist II

As a Security Risk Management Specialist II on the Security Risk Management team, you will help transform security risk management into an engineering-driven discipline by building, automating, and scaling controls and workflows. You will perform third-party security assessments, review vendor questionnaires, evaluate security controls, and document findings to manage risks within the Third Party Program. Your daily work involves replacing manual GRC tasks with code-defined workflows using Python, low-code platforms, and agentic coding tools like Cursor and Claude. You will also maintain integrations across ticketing and vendor management systems while developing dashboards for risk visibility. To succeed, you must possess knowledge of cloud environments, security frameworks such as NIST and ISO 27001, and the ability to communicate complex risks to both technical and non-technical stakeholders in a collaborative environment.

What you'll do

  • Conduct third-party security assessments by reviewing vendor questionnaires and evaluating security controls.
  • Document risk findings and provide evidence for the Third Party Risk Management program.
  • Build and maintain automation using Python and agentic coding tools to replace manual GRC workflows.
  • Configure and maintain integrations across ticketing, GRC, and vendor management platforms.
  • Partner with cross-functional teams like Legal, Engineering, and Procurement on risk-informed decisions.
  • Develop dashboards and metrics to provide stakeholders with visibility into third-party risk posture.
  • Create process improvements and documentation to mature the company's security governance.

What we're looking for

  • You must have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
  • You must be comfortable using agentic coding tools and have working knowledge of Python for scripting or automation.
  • You must have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
  • You must have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
  • You must be able to communicate clearly in writing and verbally to both technical and non-technical audiences.
  • You must hold or be working toward a professional certification like CISSP, CISM, CISA, or CRISC, or have equivalent experience.
  • A BA/BS in a relevant field or equivalent experience is preferred.

More like this

Similar roles

Security Risk Management Lead

Affirm

Remote 98 days ago $165,000$225,000
Python AWS GCP Azure Cursor Claude SQL SOC1&2 PCI DSS IAM BI Tools low code platforms Security Risk Management
5+ yrs exp Remote

Information Security Risk Specialist

Booz Allen Hamilton

Fort Belvoir, VA +1 1 day ago $99,000$225,000
RMF NIST SP 800-53 DevSecOps CI/CD AWS Azure Kubernetes ACAS SCAP STIGs eMASS Xacta Red Hat Enterprise Linux Windows Server Container Orchestration Cloud Security Risk Assessment
5+ yrs exp

IT Security Specialist II

University of Miami

Miami, FL 95 days ago
Vulnerability Management Threat Intelligence Incident Response PCI-DSS Qualys Tenable Rapid7 Malware Analysis Threat Hunting Digital Forensics CISA Advisories ISACs Security Assessment Risk Management
5+ yrs exp

Information Systems Security Manager II

General Dynamics

Fort Walton Beach, FL +7 34 days ago $108,800$147,200
Risk Management Framework (RMF) JSIG Information Security Management Configuration Management Security Assessment cyber security Network Security
7+ yrs exp

Security Representative II

General Dynamics

Colorado Springs, CO 50 days ago $125,375$169,625
SAP SCI NISPOM Operations Security Facility Security Physical Security System Security Compliance Review Security Education & Awareness
8+ yrs exp