Назад
2 дня назад

Security Risk Management Specialist II

115 000 - 180 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Risk Management Specialist II (Third-Party Risk and GRC Automation): Evaluating vendor security controls and building scalable workflows to strengthen Affirm's third-party risk management program with an accent on security assessments, Python automation, cloud security, and governance frameworks. Focus on replacing manual GRC work with code-defined workflows, integrating ticketing and vendor management platforms, and improving visibility into third-party risk posture.

Location: Remote US; work must be performed within the country of employment

Salary: $115,000–$165,000 per year in most U.S. states; $130,000–$180,000 per year in CA, WA, NY, NJ, and CT

Company

Affirm is a fintech company providing transparent buy-now-pay-later credit without hidden fees or compounding interest.

What you will do

  • Conduct third-party security assessments, review vendor questionnaires, evaluate controls, and document risk findings.
  • Build and maintain GRC automation using Python, low-code platforms, Cursor, Claude Code, Copilot, and other agentic coding tools.
  • Configure and maintain integrations across ticketing, GRC, and vendor management platforms.
  • Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews and decisions.
  • Develop dashboards, metrics, and reporting on third-party risk posture.
  • Improve processes and documentation supporting the maturity of security governance.

Requirements

  • 3+ years of experience in information security, risk management, compliance, or a related field.
  • Working knowledge of Python for scripting or automation and comfort with agentic coding tools.
  • Familiarity with AWS, GCP, or Azure and common cloud security concepts.
  • Knowledge of NIST, ISO 27001, SOC 2, and PCI DSS.
  • Strong written and verbal communication skills, including the ability to explain security risk concepts to technical and non-technical audiences.
  • CISSP, CISM, CISA, or CRISC certification in progress or completed, or equivalent practical experience.

Nice to have

  • BA/BS degree in a relevant field or equivalent experience.

Culture & Benefits

  • Remote-first work model for roles that can be performed remotely.
  • 100% subsidized medical, dental, and vision coverage for employees and dependents.
  • Stipends for technology, food, lifestyle, wellness, and family-forming expenses.
  • Competitive vacation and holiday schedules.
  • Employee stock purchase plan with discounted shares.
  • Visa sponsorship is not available for this position.

Hiring process

  • Inclusive interview experience with reasonable accommodations available for candidates with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →