채용
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
We’re hiring a Senior Manager to lead Security Governance and the Security Third-Party Risk Management (TPRM) function. This role owns program strategy, operational maturity, and stakeholder alignment for security governance, vendor risk, and third-party integration risk. The manager will drive policy and control frameworks, remediate audit findings, deliver measurable program KPIs, and grow a high-performing team that executes vendor diligence, monitoring, and governance at scale.
Our Security Governance and TPRM programs must move from tactical firefighting to predictable, measurable operations that scale with the business. This leader will set the security risk posture, tighten governance and fourth-party oversight, improve tooling and automation adoption, and ensure timely, actionable escalations so senior leadership can make the right business decisions.
What You'll Do
Program strategy & governance
- Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations).
- Lead program maturity planning, roadmaps, and cross-functional governance forums (e.g., security steering committee, risk council).
- Define and enforce security risk appetite and decision criteria for third-party relationships and integrations.
Third-party risk management
- Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding.
- Ensure robust fourth-party oversight, including subprocessors, and manage remediation/QA cycles driven by Internal Audit and regulators.
- Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria.
Operational excellence & tooling
- Own program KPIs, dashboards, and reporting (Jira STPRM Ops, Audit Board, Sigma/BI, Metric Stream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity.
- Partner with Automation/TPRM Ops to operationalize threat-modeling outputs, integration inventories, pre-integration gates, and CI/CD checks; prioritize automations that reduce manual work and surface strategic escalations.
- Implement and maintain QA processes (quarterly QA), runbooks, SOPs for ticket ownership, and evidence standards.
People & stakeholder leadership
- Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.
- Act as the primary security contact for Legal, Procurement, Privacy, Product, and Engineering on vendor risk and governance matters.
- Represent Security in executive forums, audit meetings, and regulatory engagements; own remediation commitments and timelines.
Audit, compliance & risk reporting
- Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress.
- Produce regular program health reporting for senior leadership and Board-level stakeholders.
Success metrics (examples)
- Vendors reviewed per month and % critical vendors reviewed on schedule
- Average review turnaround time and backlog age distribution
- % tickets with clear owner and SLA met
- Time to remediate Internal Audit findings and completion rate
- Implementation count of automated checks/runbooks and pre-integration gates
- Team engagement / retention and time-to-productivity for new hires
What We Look For
-
7+ years in information security, risk management, or GRC roles, with a minimum of 3 years managing teams (or equivalent leadership experience).
-
Demonstrated ownership of a TPRM program or security governance program in a regulated or high-growth technology environment (fintech preferred).
-
Strong knowledge of security frameworks (NIST, ISO), compliance standards (SOC2, PCI), and vendor risk processes (IRQ/DDQ/SME assessments).
-
Hands-on familiarity with TPRM/GRC tooling and observability: Audit Board (or equivalent), Jira, BI tools (Sigma/Tableau/Looker), and experience with integrations/APIs.
-
Excellent stakeholder management across legal, procurement, engineering, product, and executive leadership.
-
Proven experience translating audit findings into operational remediation plans and measurable outcomes.
-
Strong communication skills — able to present risk to technical and non-technical audiences and to influence decisions.
-
Certifications such as CISSP, CISM, CRISC, or similar.
-
Practical experience with threat-modeling approaches and third-party integration security (API, SSO/OAuth/SAML, TLS).
-
Experience scaling automation for GRC/TPRM programs and integrating security checks into CI/CD pipelines.
-
Prior experience in fintech or highly regulated industries.
-
Pay Grade
-
Q
Equity Grade - 10
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA base pay range (CA, WA, NY, NJ, CT) per year: $250,000 - $300,000
USA base pay range (all other U.S. states) per year: $223,000 - $273,000
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
- Health care coverage
- Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
For U.S. positions that could be performed in Los Angeles or San Francisco Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
총 조회수
0
총 지원 클릭 수
0
모의 지원자 수
0
스크랩
0
비슷한 채용공고

Senior Regional Strategy & Operations Manager, Merchant Onboarding and Activations - EMEA
Uber · Amsterdam, Netherlands

Senior Consultant, Procurement Demand Management
Northern Trust · Tempe, AZ

Senior Process Consultant - Travel & Expenses (AI-Driven)
SAP ·

Senior Analyst, AML Know Your Customer
Circle · Ireland

Principal, Ad Operation (Coupang Ads)
Coupang · Taipei, Taiwan
Affirm 소개

Affirm
PublicAffirm Holdings, Inc. is an American financial technology company and a point-of-sale lender. Founded in 2012 by PayPal co-founder Max Levchin, it is the largest U.S. based buy now, pay later (BNPL) financier.
1,001-5,000
직원 수
San Francisco
본사 위치
$2.7B
기업 가치
리뷰
4.0
10개 리뷰
워라밸
3.2
보상
3.8
문화
4.3
커리어
3.5
경영진
3.7
72%
친구에게 추천
장점
Great colleagues and collaborative team environment
Flexible work arrangements and remote options
Good benefits and competitive compensation
단점
Work-life balance challenges and long hours
High pressure and stressful deadlines
Fast-paced overwhelming environment
연봉 정보
37개 데이터
M3
M4
M5
M6
Mid/L4
Senior/L5
M3 · Business Operations Manager M3
0개 리포트
$147,400
총 연봉
기본급
$58,960
주식
$73,700
보너스
$14,740
$103,180
$191,620
면접 경험
3개 면접
난이도
3.7
/ 5
소요 기간
14-28주
경험
긍정 0%
보통 67%
부정 33%
면접 과정
1
Application Review
2
Recruiter Screen
3
Technical Phone Screen
4
Onsite/Virtual Interviews
5
Team Matching
6
Offer
자주 나오는 질문
Coding/Algorithm
Behavioral/STAR
Technical Knowledge
Past Experience
뉴스 & 버즈
Our opinion: Grand Forks School Board should affirm that graduation attire can't be altered - Grand Forks Herald
Grand Forks Herald
News
·
3d ago
Do you affirm for only one topic until it manifests? Please help me out.
Okay I have a doubt and I wanted to know how you guys actually do this in practice. I know about the list method where you write everything down and then just assume you already have it. But what if there are a couple of things that are really important to you and you feel like actively affirming for them? Like for example, one is an SP situation and the other is a job interview where I really want to do well and get the offer. Both matter a lot to me. So how do you structure it? Do you guys
·
3d ago
·
1
·
4
Buy Affirm Stock Now, Morgan Stanley Says. Why It’s a ‘Top Pick.’ - Barron's
Barron's
News
·
3d ago
This Is Why Affirm Stock (AFRM) Is Up 10% Today - TipRanks
TipRanks
News
·
3d ago