Affirm logo
Affirm

We create honest financial products that improve lives.

Security Risk Management Lead

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 2012H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

10 days ago

Salary

$165K - $225K / year

Seniority

Senior

Job Description

Security Risk Management Lead

Affirm

• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows • Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.) • Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes • Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog • Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management • Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership • Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence • Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction • Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration • Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance • Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions • Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering

Job Requirements

  • 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
  • Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
  • Excellent written and verbal communications skills
  • Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
  • Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
  • BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
  • Attention to detail and experience with security practices and security tooling
  • Demonstrated ability to drive projects towards completion
  • Ability to understand and communicate technical issues to non-technical teams
  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus

Benefits

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 501-1,000Since 1996H1B No Sponsor

• Gestión de plataformas Netskope SWG/ZTNA/DLP • Trabajar en un entorno remoto

Colombia
Devsu logo

Cybersecurity Leader

Devsu

Devsu is a technology agency that provides software development services, IT augmentation and staffing.

Full TimeRemoteTeam 51-200H1B No Sponsor

Role Description Somos una empresa de tecnología en crecimiento con alrededor de 300 ingenieros, y actualmente estamos buscando un Líder de TI y Ciberseguridad para unirse a nuestro equipo. En esta función, serás responsable de supervisar a nuestro ingeniero de soporte de TI y garantizar el diseño, desarrollo, implementación, operación, mantenimiento y monitoreo de nuestros controles de ciberseguridad. Esta es una posición tanto práctica como gerencial (50/50), por lo que debes estar dispuesto/a a tomar ambas responsabilidades. - Supervisar a nuestro Equipo de Soporte de TI (Actualmente 3 personas) - Diseñar, desarrollar, implementar, operar, mantener y monitorear los controles de seguridad de TI. - Realizar evaluaciones de riesgos, mantener un registro de riesgos, coordinar el desarrollo de políticas y estándares de seguridad de la información. - Supervisar el mantenimiento, cumplimiento y renovación de estándares y marcos de seguridad de la información y privacidad de datos adoptados por la empresa, incluidos SOC 2 e ISO 27001. - Velar por el cumplimiento de los compromisos contractuales y la normativa de seguridad y privacidad de datos. (GRPD, CCPA) - Supervisar los registros de seguridad y realizar evaluaciones de vulnerabilidad. - Trabajar en colaboración con ingenieros IT y DevOps para implementar nuevas políticas y procedimientos en procesos de desarrollo de software. - Garantizar la protección y disponibilidad de los datos y sistemas. Qualifications - Licenciatura en Informática, Tecnologías de la Información o carreras afines. - Mínimo de 4 años de experiencia en roles de TI y Ciberseguridad. - Experiencia en gestión de riesgos, evaluación de vulnerabilidades y respuesta a incidentes. - Experiencia en la implementación de marcos y estándares de seguridad de la información (por ejemplo, SOC 2, ISO 27001, NIST). - Experiencia con seguridad en la nube, privacidad de datos y regulaciones de cumplimiento. - Fuerte comunicación y habilidades interpersonales. - Inglés intermedio (Mínimo B1). - Capacidad para trabajar bien en un entorno orientado al equipo. - Experiencia en administración de TI y Cloud es una ventaja. - Certificaciones relevantes como CISSP, CISM o equivalentes son una ventaja. Benefits - Contrato estable a largo plazo, con amplias oportunidades de crecimiento profesional. - Programas continuos de capacitación, mentoría y aprendizaje, para mantenerte actualizado/a en las últimas tecnologías y metodologías. - Acceso gratuito a recursos de formación en inteligencia artificial y herramientas de IA de última generación para potenciar tu trabajo diario. - Política flexible de tiempo libre remunerado (PTO), además de los días festivos pagos. - Colaboración con algunos de los ingenieros de software más talentosos de la región, en un entorno diverso, inclusivo y colaborativo. Company Description Únete a Devsu y descubre un lugar de trabajo que valora tu crecimiento, apoya tu bienestar y te empodera para generar un impacto global.

Guatemala
Job Closed
UKG logo

Director of Services Architects

UKG

HR, Pay, & Workforce Management

Full TimeRemoteTeam 10,001+H1B Sponsor

Role Description As Director, Service Architecture, you will lead a team that shapes service strategies for complex customer opportunities. You will guide how we assess customer needs, define services scope, and build implementation approaches that are practical, scalable, and aligned to business value. - Lead and coach Service Architects to create clear, high-quality service strategies for complex customer engagements. - Partner with sales, services, product, and delivery leaders to align solution approach, services scope, risk, and customer outcomes. - Review customer requirements and translate them into implementation strategies, staffing models, timelines, and service recommendations. - Build repeatable methods, tools, and governance that improve consistency, speed, and quality across service design work. - Use data and team feedback to improve win rates, project readiness, and delivery success. - Support executive-level customer conversations by explaining service approaches, tradeoffs, and value in simple business terms. Qualifications - Experience leading teams that design services, solutions, or implementation strategies for enterprise software customers. - Experience partnering across sales, consulting, and delivery functions to support complex customer opportunities. - Experience presenting recommendations and influencing decisions with senior leaders and customers. - Bachelor’s degree or equivalent practical experience. Requirements - Experience with workforce management, human capital management, payroll, or adjacent enterprise software solutions. - Experience creating operating models, governance, and quality standards for solution design or service architecture teams. - Experience improving pre-sales to delivery handoffs and reducing implementation risk. - Experience working in a fast-paced, matrixed organization. Benefits - The pay range for this position is $163,900 to $235,550. - Employees may be eligible to participate in a performance-based bonus plan. - Employees may receive restricted stock unit awards as part of total compensation. - Learn more about UKG’s benefits and rewards at UKG Benefits . Company Description UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips our customers with the intelligence to solve any challenge in any industry — because great organizations know their workforce is their competitive edge.

United States
$163.9K - $235.6K / year

Microsoft Entra ID Architect

KeyData Cyber

KeyData Associates is a leading provider of identity security services, helping businesses navigate the complex challenges of protecting critical information. Founded with a commit

Role Description We are seeking a highly skilled Entra ID Architect specializing in Microsoft Entra ID (formerly Azure Active Directory) to design, implement, and manage our cloud-based and hybrid identity infrastructures. In this role, you will serve as the subject matter expert for our identity ecosystem, ensuring seamless user access while maintaining a robust security posture. You will be responsible for defining access management strategies, enforcing governance policies, and securing our enterprise resources across hybrid environments. Location: USA, Remote Employment Type: Contract Key Responsibilities - Identity Infrastructure & Hybrid Management - Design, deploy, and maintain Microsoft Entra ID and hybrid identity architectures, including Entra Connect / Cloud Sync environments. - Manage corporate directory integration between on-premises Active Directory (AD) and Entra ID. - Oversee Enterprise Applications, App Registrations, and Service Principals, ensuring secure API permissions and consent frameworks. - Troubleshoot complex authentication, synchronization, and replication issues across hybrid infrastructure. - Access Management & Security Policies - Design and enforce zero-trust security architectures using Entra Conditional Access Policies, risk-based policies, and Continuous Access Evaluation (CAE). - Deploy and manage Multi-Factor Authentication (MFA), Passwordless authentication, and Windows Hello for Business. - Configure and maintain Privileged Identity Management (PIM) to enforce just-in-time (JIT) and just-enough-access (JEA) for administrative roles. - Implement Entra ID Governance, including Access Reviews, Entitlement Management (Access Packages), and Lifecycle Workflows to automate user onboarding/offboarding. - Automation, Monitoring & Compliance - Automate routine identity management tasks using PowerShell, Microsoft Graph API, and Azure Automation runbooks. - Monitor identity security logs using Entra ID Protection, Log Analytics, and integrate logs with enterprise SIEM platforms (e.g., Microsoft Sentinel). - Conduct regular access audits to ensure compliance with corporate policies, regulatory standards (e.g., SOC2, ISO 27001), and identity best practices. Qualifications - Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent professional experience). - 5+ years of dedicated experience in Identity and Access Management (IAM), with at least 3 years focusing heavily on Microsoft Entra ID / Azure AD. - Deep understanding of modern authentication protocols (SAML 2.0, OIDC, OAuth 2.0, WS-Fed, FIDO2). - Hands-on experience configuring Entra ID Governance tools (PIM, Access Reviews). - Strong proficiency in scripting and automation using PowerShell and interfacing with the Microsoft Graph API. - Solid understanding of network security concepts relating to identity (e.g., Managed Identities, Application Proxy, Private Access). Preferred Certifications & Skills - Microsoft Certified: Identity and Access Administrator Associate (SC-300) - Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Azure Solutions Architect Expert (AZ-305) - CISSP, CISA, or CCSP designations are highly valued. - Familiarity with integrating Entra ID with governance platforms (such as SailPoint Identity Security Cloud or IdentityIQ) for advanced identity lifecycle workflows is a strong plus. - Strong analytical mindset, excellent documentation skills, and the ability to collaborate effectively with security compliance officers and infrastructure teams. Benefits - Valuing learning, growth, and work-life balance. - Extensive opportunities to advance your career through leading digital identity projects across North America. - A culture built on respect, inclusion, and equal opportunity for everyone. Accessibility & Accommodations If you require accommodation due to a disability at any time during the recruitment and/or assessment process, please contact Talent Acquisition, and we will make all reasonable efforts to accommodate your request. Fraud Prevention & Identity Verification We may use information provided during the application process to help prevent fraud and verify identity. These checks may be conducted automatically through trusted third-party service providers as part of our standard application screening process. BrightHire technology is used during the preliminary interview stage for recording, transcription, and candidate evaluation as part of our hiring process. Apply now to join the KeyData Cyber team and be part of our mission to secure the future of digital identity across North America.

United States