SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 115,000 - 180,000 / annual
Affirm is seeking a Security Risk Management Specialist II to scale and evolve its Third Party Risk Management (TPRM) program. This role bridges security governance and engineering, combining hands-on risk assessment with modern automation tooling.
You will conduct third-party security assessments by reviewing vendor questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm's TPRM program. A key part of this role is building and maintaining automation to reduce manual GRC workflows using Python, low-code platforms, and agentic coding tools (Cursor, Claude) to improve program efficiency and scale operations.
You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution. Cross-functional partnership is essential—you'll work closely with Procurement, Legal, Engineering, IT, Compliance, and Privacy teams on third-party risk reviews, follow-up actions, and risk-informed business decisions.
Additionally, you will develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture, and contribute to process improvements and program documentation that mature Affirm's security governance over time.
The ideal candidate has 3+ years of experience in Information Security, Risk Management, Compliance, or a related field. You should be comfortable with agentic coding tools and have working knowledge of Python for scripting and automation. Familiarity with cloud environments (AWS, GCP, Azure) and cloud security concepts is required. Knowledge of security frameworks such as NIST, ISO 27001, SOC 2, and PCI DSS is essential. Strong written and verbal communication skills are critical for translating security risk concepts to both technical and non-technical audiences. Professional certifications such as CISSP, CISM, CISA, or CRISC are preferred, or equivalent practical experience. A BA/BS in a relevant field is preferred.