SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 101,000 - 151,000 / annual
Affirm is seeking a Security Risk Management Specialist II to scale and evolve its Third Party Risk Management (TPRM) program. This role bridges security governance and engineering, combining hands-on vendor risk assessment with modern automation and tooling.
You will conduct third-party security assessments by reviewing vendor questionnaires, evaluating security controls, and documenting risk findings. A core responsibility is building and maintaining automation to reduce manual GRC workflows using Python, low-code platforms, and agentic coding tools (Cursor, Claude) to improve efficiency and scale the program.
You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent workflow execution. Cross-functional partnership is essential—you'll collaborate with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
Additionally, you will develop and maintain dashboards, metrics, and reporting that provide stakeholders clear visibility into third-party risk posture, and contribute to process improvements and documentation that mature Affirm's security governance.
The ideal candidate has 3+ years in Information Security, Risk Management, Compliance, or related field. You are comfortable with agentic coding tools and have working knowledge of Python for scripting. Familiarity with cloud environments (AWS, GCP, Azure) and security frameworks (NIST, ISO 27001, SOC 2, PCI DSS) is required. Professional certifications such as CISSP, CISM, CISA, or CRISC are preferred, or equivalent practical experience. Strong written and verbal communication skills are essential for translating security concepts to technical and non-technical audiences.