安全风险管理专员 II
查看雇主原标题
Security Risk Management Specialist IIAffirm · Remote 加拿大 · Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidiz
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 60/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译在Affirm,我们存在的意义在于那些重要时刻——为人们提供清晰、可预测的分期付款方式,没有隐藏费用,没有意外,也不会在最重要的事情上做出妥协。
岗位职责
理想候选人将评估、构建并完善针对第三方风险与安全治理挑战的解决方案,覆盖安全第三方项目以及更广泛的安全风险管理项目。他们同样擅长将安全政策应用于现实世界的供应商决策,并使用现代工具(Python、Cursor、Claude 以及其他代理式编码平台)交付自动化,以可扩展、代码定义的工作流取代手动 GRC 工作。他们将在安全风险领域发展深厚的专业知识,与业务和工程利益相关方紧密合作,并在 Affirm 将安全风险管理从以合规为导向的职能转变为安全工程学科的过程中发挥积极作用。
• 我们正在寻找一位充满好奇心、善于协作的安全风险管理专员,通过流程严谨性、动手自动化和强大的跨职能合作,帮助扩展 Affirm 的第三方风险管理项目。
• 你将开展第三方安全评估,审查供应商问卷、评估安全控制并记录风险发现,作为 Affirm TPRM 项目的核心贡献者。
• 你将构建并维护自动化,以减少手动 GRC 工作流,使用 Python、低代码平台和代理式编码工具来提升项目效率和规模。
• 你将配置并维护工单、GRC 和供应商管理平台之间的集成,以支持一致且可重复的工作流执行。
• 你将与采购、法务、工程、IT、合规和隐私团队合作,开展第三方风险审查、后续行动和基于风险知情的决策。
• 你将帮助开发和维护仪表板、指标和报告,让利益相关方清晰了解第三方风险态势。
• 你将参与流程改进和项目文档建设,随着时间推移使 Affirm 的安全治理更加成熟。
我们寻找什么样的人
• 你拥有 3 年以上信息安全、风险管理、合规或相关领域经验。
• 你能够熟练使用代理式编码工具(例如 Cursor、Claude Code、Copilot),并具备用于脚本编写或自动化的 Python 实用知识。
• 你熟悉云环境(AWS、GCP 或 Azure)以及常见的云安全概念。
• 你具备安全框架和标准的实用知识,例如 NIST、ISO 27001、SOC 2 和 PCI DSS。
• 你具备清晰的书面和口头沟通能力,并能向技术和非技术受众解释安全风险概念。
• 你持有(或正在考取)CISSP、CISM、CISA 或 CRISC 等专业认证,或具备同等实践经验。相关领域的 BA/BS 学位或同等经验优先。
福利待遇
我们的福利体现了我们对关怀、透明和灵活性的承诺。以下是一些亮点:
• 免费健康保险:我们为员工及其家属支付 100% 的保费。
• 支出津贴:每月津贴支持你的技术设备配置,并可选择适合你的健康与保健选项。
• 充电休假:灵活休假和慷慨的假期日历帮助你在需要时休息。
• 拥有你所构建成果的一部分:我们的员工购股计划(ESPP)让你能够以折扣价购买 Affirm 股票。
我们致力于提供包容性的面试流程,包括为残障候选人提供便利。如果你需要支持,我们很乐意提供帮助。
对于位于 San Francisco 或 Los Angeles 的职位:根据法律要求,Affirm 会考虑有逮捕和定罪记录的合格申请人。
点击“Submit Application”,即表示你确认已阅读 Affirm 的 Global Candidate Privacy Notice,并同意按其中所述使用你的个人信息。
薪资
股权等级 - 3
新加入 Affirm 的员工通常从薪酬区间的起点开始。Affirm 专注于提供简单透明的薪酬结构,该结构基于多种因素,包括地点、经验和与工作相关的技能。
基本工资是总薪酬方案的一部分,总薪酬方案可能包括用于健康、保健和技术支出的月度津贴,以及福利(包括为你和你的家属提供 100% 补贴的医疗、牙科和视力保险)。此外,员工可能有资格获得 Affirm Holdings, Inc.(母公司)提供的股权奖励。
CAN 年度基本工资范围:CAD $101,000 - $151,000
地点 - Remote Canada 该远程职位仅面向居住在 Alberta、British Columbia、Manitoba、New Brunswick、Newfoundland and Labrador、Nova Scotia、Ontario、Prince Edward Island 或 Saskatchewan 的候选人开放。
#LI-Remote
远程优先,内置灵活性 Affirm 很自豪是一家远程优先公司。大多数职位几乎可以在雇佣国家内的任何地方完成。部分职位可能偶尔需要在 Affirm 办公室现场工作,少数职位由于工作性质需要在办公室办公。所有新员工都将被邀请参加线下入职体验。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.
岗位职责
The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will develop deep expertise across the security risk domain, partner closely with business and engineering stakeholders, and play an active role in Affirm's transformation of Security Risk Management from a compliance-oriented function into a security engineering discipline.
• We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.
• You will conduct third-party security assessments, reviewing vendor questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm's TPRM program.
• You will build and maintain automation to reduce manual GRC workflows, using Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
• You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution.
• You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
• You will help develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture.
• You will contribute to process improvements and program documentation that mature Affirm's security governance over time.
What We Look For
• You have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
• You are comfortable using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and have working knowledge of Python for scripting or automation.
• You have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
• You have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
• You communicate clearly in writing and verbally, and can translate security risk concepts for both technical and non-technical audiences.
• You hold (or are working toward) a professional certification such as CISSP, CISM, CISA, or CRISC or bring equivalent practical experience. A BA/BS in a relevant field, or equivalent experience, is preferred.
福利待遇
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
• Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
• Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
• Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
• Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.
For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.
薪资
Equity Grade - 3
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).
CAN base pay range per year: CAD $101,000 - $151,000
Location - Remote Canada This remote role is open only to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.
#LI-Remote
Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.