About the company
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees. We value security as critical to our success.
Responsibilities
- Conduct third-party security assessments, reviewing vendor questionnaires and evaluating security controls.
- Build and maintain automation to reduce manual GRC workflows using Python and agentic coding tools.
- Configure and maintain integrations across ticketing, GRC, and vendor management platforms.
- Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews.
- Develop and maintain dashboards, metrics, and reporting for third-party risk posture.
- Contribute to process improvements and program documentation.
Requirements
- 3+ years of experience in Information Security, Risk Management, Compliance, or related field.
- Comfortable using agentic coding tools (Cursor, Claude Code, Copilot) and working knowledge of Python.
- Familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
- Working knowledge of security frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS.
- Clear communication skills, able to translate security risk concepts.
- Professional certification (CISSP, CISM, CISA, CRISC) or equivalent experience preferred.
Conditions
- Base pay range: $115,000 - $180,000 per year depending on location
- Equity rewards
- Monthly stipends for health, wellness, and tech spending
- 100% subsidized medical coverage, dental, and vision for you and dependents
- Flexible spending wallets
- Competitive vacation and holiday schedules
- Employee stock purchase plan (ESPP)