More jobs:
Security Risk Management Lead
Job in
Portland, Multnomah County, Oregon, 97204, USA
Listed on 2026-06-13
Listing for:
Affirm
Full Time
position Listed on 2026-06-13
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm
, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
- Lead and mature Affirm
's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows - Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
- Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
- Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
- Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
- Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
- Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
- Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
- Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
- Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
- Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
- Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
- Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
- Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
- 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
- Hands‑on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end‑to‑end
- Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud‑deployed third parties and integrations
- Excellent written and verbal communications skills
- Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
- Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE
18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) - BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
- Attention to detail and experience with security practices and security tooling
- Demonstrated ability to drive projects towards completion
- Ability to understand and communicate technical issues to non‑technical teams
- Professional certification in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×