IT Security Risk Management Lead

7 days ago


remote us Affirm, Inc. Full time

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.We are seeking a Security Risk Management Lead to join our Security Risk Management team at Affirm. The Security Risk Management team builds and deploys common governance, risk, and compliance processes and controls, conducts audits, and ensures that technologies and business processes are built with data protection and compliance in mind Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products.What You'll Do Develop complementary control frameworks that define the security responsibilities of Affirm and its third parties, including vendors, merchants, and partners.Mature our third-party security risk processes by working with a broad range of technical and non-technical stakeholders.Own the end-to-end execution of third-party due diligence and issues management, ensuring alignment with stakeholders throughout.Design and generate metrics and reports on risk indicators, issues, and the efficiency of our operations.Support Legal in our contract reviews and negotiations to ensure appropriate security terms are in place.Provide best-in-class support for our client-facing teams and security assurance to our business partners as well as find opportunities to enhance this program and build internal and external relationships.Fluently communicate security risks to non-experts to empower our business with valuable, actionable information.Develop, curate, and disseminate security governance documentation, ensuring awareness amongst stakeholders and employees.Partner with engineering and IT to define and document policies and technical procedures for secure and compliant treatment of sensitive data. What We Look For Excellent project management and collaboration skills—setting goals and priorities, taking into account dependencies, and handling execution from start to finish.A drive to solve difficult problems and evolve the status quo with technical and non-technical solutions—you’re never satisfied by just ticking a box.Crystal clear verbal and written communication—people love how your emails and documentation tell them exactly what they need to know.3-5 years of risk management, information security, or other relevant experience working with technical teams and balancing risk against business need.Passion for working with diverse teams and taking into account each perspective, e.g. as an auditor, engineer, business person, and more.Knowledge of risk and control frameworks (e.g. NIST Cyber Security Framework, ISO 2700x, SOC1 & 2 (SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.) and experience with security practices and solutions. Pay Grade - LEmployees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)USA base pay range (CA, WA, NY, NJ, CT) per year: $160,000 - $210,000USA base pay range (all other U.S. states) per year: $142,000 - $192,000Please note that visa sponsorship is not available for this position.



  • Remote, Oregon, United States Fortress Information Security Full time $120,000 - $180,000 per year

    Security Risk AssessorLocation: RemoteCompensation: $90,000 - $150,000 per year, depending on experience and qualifications.Employment Type: Full-TimeWhat you can expect as a Senior Security Risk Assessor at Fortress:The Security Risk Assessor, Cybersecurity TPRM role is an individual contributor role responsible for the timely and effective review of...


  • Remote, Oregon, United States SentinelOne Full time $120,000 - $180,000 per year

    What are we looking for?We are looking for a highly motivated, collaborative and experienced Senior InfoSec Risk Specialist with a security-focused mindset who can balance risk, business drivers and timelines. This position will be responsible for understanding and supporting the design of SentinelOne's organizational, procedural and technological security...


  • Remote, Oregon, United States GuidePoint Security Full time $120,000 - $180,000 per year

    GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...


  • remote, remote, us Dynapar Full time

    Responsibilities : Develop and implement security policies, procedures, and guidelines to ensure the effectiveness of Security and Compliance operations. Evaluate security systems and identify opportunities for security automation and improvements on a continuous basis. Test and identify potential network and system security vulnerabilities. Develop and...


  • remote, us HealthEdge Full time

    Overview : The Chief Information Security Officer (CISO) is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. This position is responsible for identifying, evaluating and reporting on information security risks in a manner that meets compliance and...


  • remote, us Epam Full time

    Description We are in search of a Lead Application Security Engineer to become a part of our team. The preferred candidate should possess a background in software development along with substantial experience in application security. In this role, you will be accountable for overseeing the application security program for a worldwide investment company. In...


  • remote, us USI Insurance Services Full time

    The PRS National Operations Leader is responsible for driving operational best practices and fundamental process improvement across our Personal Risk Services insurance operations in conjunction with the efforts of the PRS National Director of Operations. In this role, individual will coordinate with national and regional PRS practice and operational leaders...


  • Remote, United States ThinkBAC Consulting LLC Full time

    Lead Energy Storage Cyber Security Engineer - REMOTE Please make sure you read the following details carefully before making any applications. Full time | ThinkBAC Consulting | United States Work Experience 5+ years Energy and Utilities Lead Energy Storage Cybersecurity Engineer / Cybersecurity Architect FULLY REMOTE (Anywhere in the USA) This is...


  • Remote, United States Arctic Wolf Full time

    At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on theForbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60lists, and we...


  • us Cloud Security Services Full time

    Cloud Security Services is currently looking for an experienced external Identity and Access Management (xIAM / CIAM) architect with background in global, complex, and diverse xIAM environments to assist with the development of a program that will design, develop, and deploy xIAM solutions. Experience with business architecture is a plus as the right...