安全风险管理负责人
查看雇主原标题
Security Risk Management LeadAffirm · Remote US · pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-rel
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 67/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
- 检测到签证担保关键词
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 提及签证担保+7
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译在Affirm,我们为那些重要的时刻而存在——为人们提供清晰、可预测的分期付款方式,没有隐藏费用,没有意外,在最重要的事情上无需妥协。
Affirm将安全视为公司持续成功的关键。我们的使命是在Affirm培育安全文化,使公司能够成功打造诚实的金融产品。安全风险管理团队正在超越传统的治理、风险与合规;我们正在构建一个工程驱动的项目,设计、自动化并扩展保护Affirm和我们客户的管控措施、工作流程和工具。
理想的候选人将为安全第三方项目及更广泛的安全风险管理项目中的复杂技术和业务问题设计、开发、配置和实施解决方案。他们同样擅长制定政策,并使用现代工具(Python、Cursor、Claude及其他智能体编码平台)交付自动化,以可扩展的、代码定义的工作流程取代手动GRC工作。他们将作为主题专家开展工作,与业务和工程利益相关方对接,并在将安全风险管理从合规导向的职能转变为安全工程学科的过程中发挥关键作用。
岗位职责
• 领导并成熟化Affirm的安全第三方项目,包括流程、管控措施和运营工作流程的设计、实施与持续改进
• 构建并维护自动化,以取代手动GRC任务:受理、分诊、证据收集、控制验证、跟踪、升级和报告,使用Python、低代码平台和智能体编码工具(Cursor、Claude等)
• 设计并运营跨系统的流程编排和集成,如工单系统、GRC平台、供应商管理工具、身份提供商和云控制平面
• 与采购、法务、工程、IT、合规、隐私和业务利益相关方紧密合作,评估和管理第三方关系中的安全风险
• 将模糊的业务和安全需求转化为实用、可扩展的项目解决方案和决策框架
• 识别在整个项目中自动化手动流程的机会,并自行制作解决方案原型,而不是等待工程积压
• 通过为第三方安全风险管理建立可重复的流程、服务水平期望、指标和报告,推动项目运营卓越
• 评估第三方安全控制、云架构(AWS/GCP)、集成模式和风险态势,并向利益相关方和领导层提供明确的建议
• 对高风险集成进行轻量级威胁建模,并与安全主题专家合作进行更深入的尽职调查
• 同时管理和优先处理一系列复杂的安全风险审查和举措,在业务赋能与风险降低之间取得平衡
• 与技术团队合作,实施或优化支持项目自动化和流程编排的系统和工具
• 开发仪表板、报告机制和项目洞察(SQL、BI工具或定制工具),以提高对风险趋势、瓶颈和项目绩效的可见性
• 作为第三方安全风险管理的可信顾问和主题专家,帮助利益相关方做出明智的、基于风险的决策
• 通过识别通过工程扩展、简化和加强安全治理流程的机会,为更广泛的安全风险管理战略做出贡献
我们寻找什么样的人
• 5年以上信息安全、风险管理、工程和/或相关岗位经验
• 具有使用智能体编码工具(Cursor、Claude Code、Copilot等)的实操经验,并具备Python的实用知识;你不需要是软件工程师,但应足够熟练,能够阅读、修改和运行脚本、构建自动化,并端到端交付小型工具
• 熟悉云环境(AWS、GCP或Azure)——IAM、日志记录、常见服务,以及适用于云部署第三方和集成的安全风险/控制
• 出色的书面和口头沟通能力
• 具有通过Python、Claude、Cursor或其他智能体编码工具进行工程解决方案的经验
• 具有行业信息安全与控制框架的经验(NIST网络安全框架、ISO 2700x、SOC1&2(SSAE18)、PCI DSS、NIST-800-53、FFIEC网络安全评估工具、SANS Top 20等)
• 信息安全、网络安全、计算机科学或相关领域的学士学位,或同等经验
• 注重细节,并具有安全实践和安全工具方面的经验
• 具有推动项目完成的证明能力
• 能够理解技术问题并向非技术团队传达
• 拥有信息安全或风险管理专业认证(如CISSP、CISM、CISA、CRISC等)者优先
福利待遇
我们的福利体现了我们对关怀、透明和灵活性的承诺。以下是一些亮点:
• 免费健康保险:我们为员工及其家属支付100%的保费。
• 支出津贴:每月津贴支持你的技术设备配置,并可选择适合你的健康与保健选项。
• 充电休假:灵活休假和慷慨的节假日安排帮助你在需要时休息。
• 拥有你所建设的一部分:我们的员工购股计划(ESPP)让你以折扣价购买Affirm股票。
我们致力于提供包容性的面试流程,包括为残障候选人提供便利。如果你需要支持,我们很乐意提供帮助。
对于位于旧金山或洛杉矶的职位:根据法律要求,Affirm会考虑有逮捕和定罪记录的合格申请人。
点击“提交申请”,即表示你确认已阅读Affirm的《全球候选人隐私声明》,并同意按其中所述使用你的个人信息。
薪资
股权等级 - 5
新加入Affirm的员工通常从薪酬区间的起点开始。Affirm专注于提供简单透明的薪酬结构,该结构基于多种因素,包括地点、经验和工作相关技能。基本工资是总薪酬方案的一部分,总薪酬方案可能包括股权奖励、用于健康、保健和技术支出的月度津贴,以及福利(包括为你和你的家属提供100%补贴的医疗保险、牙科和视力保险)。
美国太平洋地区基本工资范围(CA、WA、NY、NJ、CT)每年:$165,000 - $225,000
美国Sapphire地区基本工资范围(美国其他所有州)每年:$146,000 - $206,000
请注意,该职位不提供签证担保。
#LI-Remote
远程优先,内置灵活性 Affirm自豪地成为一家远程优先的公司。大多数职位几乎可以在就业国家内的任何地方完成。某些职位可能偶尔需要在Affirm办公室现场工作,少数职位因工作性质而需要在办公室工作。所有新员工都将被邀请参加现场入职体验。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.
Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
岗位职责
• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
• Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
• Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
• Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
• Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
• Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
• Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
• Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
• Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
• Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
• Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
• Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
• Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
• Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
• 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
• Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
• Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
• Excellent written and verbal communications skills
• Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
• Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
• BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
• Attention to detail and experience with security practices and security tooling
• Demonstrated ability to drive projects towards completion
• Ability to understand and communicate technical issues to non-technical teams
• Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
福利待遇
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
• Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
• Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
• Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
• Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.
For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.
薪资
Equity Grade - 5
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.