Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Risk Management Lead (Cybersecurity): Leading and maturing the Security Third Party Program by replacing manual GRC tasks with automated, code-defined workflows with an accent on security engineering. Focus on building automation using Python and agentic coding tools to scale security controls and risk assessments.
Location: Remote (US). Visa sponsorship is not available for this position.
Salary: $146,000 - $225,000 per year
Company
Affirm is a fintech company reinventing credit to provide honest and transparent financial products without hidden fees.
What you will do
- Lead and mature the Security Third Party Program, designing and implementing operational workflows and controls.
- Build automation using Python and agentic coding tools (Cursor, Claude) to replace manual GRC tasks like intake, triage, and reporting.
- Design workflow orchestrations across ticketing systems, GRC platforms, and cloud control planes.
- Partner with Procurement, Legal, and Engineering to assess and manage third-party security risks.
- Evaluate cloud architectures (AWS/GCP) and integration patterns to provide risk-based recommendations.
- Develop dashboards and reporting mechanisms using SQL and BI tools to track risk trends and program performance.
Requirements
- 5+ years of experience in Information Security, Risk Management, or Engineering.
- Must be based in the US; visa sponsorship is not available.
- Fluency in Python and hands-on experience with agentic coding tools (Cursor, Claude Code, Copilot).
- Familiarity with cloud environments (AWS, GCP, or Azure), specifically IAM and logging.
- Experience with security frameworks such as NIST, ISO 2700x, SOC1&2, and PCI DSS.
- BA/BS degree in Cyber Security, Computer Science, or a related field.
Nice to have
- Professional certifications such as CISSP, CISM, CISA, or CRISC.
Culture & Benefits
- 100% subsidized medical, dental, and vision coverage for employees and dependents.
- Generous flexible spending stipends for Technology, Food, and Lifestyle.
- Competitive vacation and holiday schedules.
- Employee Stock Purchase Plan (ESPP) to buy company shares at a discount.
- Remote-first culture with flexibility to work almost anywhere within the US.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →