信息技术与安全总监
查看雇主原标题
Director, Information Technology & SecurityAffirm · Remote US · Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidiz
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 67/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
- 检测到签证担保关键词
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 提及签证担保+7
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译在Affirm,我们存在的意义在于那些重要时刻——为人们提供清晰、可预测的分期付款方式,没有隐藏费用,没有意外,在最重要的事情上无需妥协。
美国远程
信息技术与安全总监将作为银行管理团队的重要成员,担任首席信息安全官,并负责建立和领导银行的信息安全和网络安全项目。在银行准备作为一家新设工业贷款公司(ILC)启动之际,该领导者将设计并实施一套覆盖全企业的安全框架,以满足FDIC和各州监管机构的期望,支持银行的风险偏好,并保护客户和机构数据。
这是一个兼具双重职责的领导岗位,既需要高层次的战略影响力,也需要深入的技术执行能力。您将领导信息安全治理、技术控制以及基础设施和工程监督的制定,确保从成立之初就具备强大且可扩展的安全态势。该领导者本质上必须是一名实践者——愿意“撸起袖子”领导技术建设阶段,与工程团队在架构方面密切合作,并确保安全融入银行系统和运营的各个方面。
岗位职责
• 监督基础设施设计和IT工程
• 信息安全项目开发
• 设计、实施并维护一套全面的信息安全项目,使其符合FDIC指南(例如FIL-66-2019、FIL-13-2021)以及《建立信息安全标准的跨机构指南》。
• 制定并监督管理网络安全、数据保护和事件响应的政策、标准和程序。
• 确保与银行整体风险管理和治理框架保持一致。
• 定期向高管层和董事会报告银行的安全态势、新兴风险和缓解措施。
• 领导银行基础设施的技术建设阶段,为云安全和DevOps集成提供直接监督和实操指导。
• 与工程团队深度合作,定义并实施安全技术架构,包括网络分段、加密标准和身份治理。
• 网络安全与威胁管理
• 建立并管理威胁监控和检测能力,以识别、评估和应对网络安全风险。
• 监督分层安全控制的实施(例如网络分段、加密、访问控制、终端保护、漏洞管理)。
• 领导银行的事件响应项目,确保及时升级并在需要时与监管机构协调。
• 维护与信息共享组织(例如FS-ISAC)和执法机构的关系,以及时了解新兴威胁。
• 第三方和关联方风险监督
• 根据银行的供应商管理项目和FDIC第三方风险指南,评估第三方和关联方服务提供商的信息安全态势。
• 为处理敏感数据或执行关键服务的供应商建立尽职调查、持续监控和合同要求。
• 与运营、合规和内部审计部门协调,确保第三方风险得到识别、评估和缓解。
• 管理安全关键型第三方服务提供商的技术生命周期,确保对处理敏感金融数据的供应商进行严格的运营监督。
• 数据治理与隐私保护
• 确保遵守适用的隐私和数据保护要求(例如GLBA、Regulation P、各州隐私法)。
• 实施流程以保护客户信息,并防止未经授权的访问、披露或滥用。
• 与业务和技术团队合作,将隐私设计原则融入新产品和服务。
• 业务连续性与韧性
• 协助风险官制定和测试银行的业务连续性与灾难恢复(BC/DR)计划,确保其与信息安全目标相结合。
• 协调定期测试和模拟,以验证对网络事件和系统中断的准备情况。
• 支持关键系统、供应商和通信协议的韧性规划。
• 新设机构与开业前准备
• 作为新设申请流程的一部分,建立并记录银行的技术和信息安全项目。
• 在开业前建立安全架构、监控工具和供应商关系。
• 为与网络安全和运营韧性相关的FDIC和州审查准备就绪材料。
• 确保完成安全风险评估和第三方审查,并将其纳入开业前里程碑。
• 领导力与文化
• 作为银行网络安全和数据保护的高级倡导者,推动安全意识和问责文化。
• 在全组织范围内提供培训和指导,以提升信息安全意识。
• 与风险、合规、运营和技术部门的同行合作,使安全优先事项与业务战略保持一致。
• 建立并领导一支有能力、以使命为导向的安全团队,以支持银行不断变化的需求。
我们寻找什么样的人
• 至少10年信息技术以及安全和技术风险管理经验,并具有在战略规划和实操技术执行之间切换的可靠业绩记录。
• 具有设计和实施符合FDIC和FFIEC标准的信息安全项目的经验。
• 熟悉第三方风险框架和金融服务网络安全期望。
• 具有在基于云和混合环境中领导事件响应、渗透测试和安全运营的经验。
• 具有向高管层、董事会和监管机构沟通复杂技术主题的可靠能力。
• 强大的领导力、分析能力和解决问题的能力,并以基于风险且务实的方式做出决策。
• 在云原生基础设施(AWS/GCP)、DevOps实践和软件定义安全控制方面具有深厚专业知识。
• 具有“撸起袖子”直接参与技术建设,同时管理高管利益相关者和监管机构的可靠能力。
核心能力
• 信息安全原则、框架和监管要求方面的专家级知识。
• 具有强大运营执行力和控制纪律的战略思考者。
• 能够在技术和业务职能之间施加影响的高效沟通者。
• 能够培养问责、意识和持续改进文化的协作型领导者。
Affirm价值观
在Affirm,我们践行我们的价值观:以人为本、没有细则、由我们负责、简化、突破边界。作为CCO,您将在构建Affirm Bank作为值得信赖、透明且创新的金融机构基础时体现这些原则。
福利待遇
我们的福利体现了我们对关怀、透明和灵活性的承诺。以下是一些亮点:
• 免费健康保险:我们为员工及其家属支付100%的保费。
• 支出津贴:每月津贴支持您的技术设备配置,并可选择适合您的健康与保健选项。
• 充电休假:灵活休假和慷慨的节假日安排帮助您在需要时休息。
• 拥有您所建设成果的一部分:我们的员工购股计划(ESPP)让您能够以折扣价购买Affirm股票。
我们致力于提供包容性的面试流程,包括为残障候选人提供便利。如果您需要支持,我们很乐意提供帮助。
对于位于旧金山或洛杉矶的职位:根据法律要求,Affirm会考虑有逮捕和定罪记录的合格申请人。
点击“提交申请”,即表示您确认已阅读Affirm的《全球候选人隐私声明》,并同意按其中所述使用您的个人信息。
薪资
股权等级 - 14
新加入Affirm的员工通常从薪酬区间的起点开始。Affirm专注于提供简单透明的薪酬结构,该结构基于多种因素,包括地点、经验和工作相关技能。
基本工资是总薪酬方案的一部分,其中可能包括用于健康、保健和技术支出的月度津贴,以及福利(包括为您和您的家属提供100%补贴的医疗、牙科和视力保险)。此外,员工可能有资格获得Affirm Holdings, Inc.(母公司)提供的股权奖励。
美国太平洋地区基本工资范围(CA、WA、NY、NJ、CT)每年:$300,000 - $360,000
美国Sapphire地区基本工资范围(美国所有其他州)每年:$267,000 - $327,000
请注意,该职位不提供签证担保。
#LI-Remote
远程优先,内置灵活性 Affirm很自豪是一家远程优先公司。大多数职位几乎可以在雇佣国家内的任何地方完成。部分职位可能偶尔需要在Affirm办公室现场工作,少数职位因工作性质需要在办公室办公。所有新员工都将被邀请参加现场入职体验。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.
Remote US
The Director, Information Technology & Security will serve as a key member of the Bank's Management Team, serving as the Chief Information Security Officer, and will be responsible for establishing and leading the Bank's information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), this leader will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank's risk appetite, and protects customer and institutional data.
This is a blended leadership role requiring both high-level strategic influence and deep technical execution. You will lead the development of information security governance, technical controls, and oversight of infrastructure and engineering, ensuring a strong and scalable security posture from inception. This leader must be a practitioner at heart—willing to "roll up their sleeves" to lead the technical build phase, collaborate closely with engineering on architecture, and ensure security is integrated into every aspect of the Bank's systems and operations.
岗位职责
• Oversee infrastructure design and IT Engineering
• Information Security Program Development
• Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
• Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
• Ensure alignment with the Bank’s overall risk management and governance frameworks.
• Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
• Lead the technical build phase of the Bank's infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration.
• Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance.
• Cybersecurity and Threat Management
• Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
• Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
• Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
• Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
• Third-Party and Affiliate Risk Oversight
• Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
• Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
• Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
• Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data.
• Data Governance and Privacy Protection
• Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
• Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
• Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
• Business Continuity and Resilience
• Assist Risk Officer in development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
• Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
• Support resilience planning for key systems, vendors, and communication protocols.
• De Novo and Pre-Opening Readiness
• Build and document the Bank’s technology and information security program as part of the de novo application process.
• Establish security architecture, monitoring tools, and vendor relationships prior to launch.
• Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
• Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
• Leadership and Culture
• Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
• Provide training and guidance across the organization to enhance information security awareness.
• Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
• Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.
What We Look For
• Minimum of 10 years of experience in information technology, and security and technology risk management, with a proven track record of moving between strategic planning and hands-on technical execution.
• Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
• Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
• Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
• Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
• Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.
• Deep expertise in cloud-native infrastructure (AWS/GCP), DevOps practices, and software-defined security controls.
• Demonstrated ability to "roll up sleeves" and contribute directly to the technology build while simultaneously managing executive stakeholders and regulators.
Core Competencies
• Expert knowledge of information security principles, frameworks, and regulatory requirements.
• Strategic thinker with strong operational execution and control discipline.
• Effective communicator capable of influencing across technical and business functions.
• Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.
Affirm Values
At Affirm, we live by our values: People Come First, No Fine Print, It’s On Us, Simplify, and Push the Envelope. As CCO, you will embody these principles while building the foundation of Affirm Bank as a trusted, transparent, and innovative financial institution.
福利待遇
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
• Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
• Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
• Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
• Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.
For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.
薪资
Equity Grade - 14
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000
USA Sapphire base pay range (all other U.S. states) per year: $267,000 - $327,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.