The opportunity
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
What you'll do
Lead and mature Affirm's Security Third Party Program, including the design,: implementation, and continuous improvement of processes, controls, and operational workflows
Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
Design and operate workflow orchestration and integrations across systems: like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
Partner closely with Procurement, Legal, Engineering, IT, Compliance,: Privacy, and business stakeholders to assess and manage security risk across third party relationships
Translate ambiguous business and security requirements into practical,: scalable program solutions and decision frameworks
Identify opportunities to automate manual processes across the program and: prototype solutions yourself rather than waiting on an engineering backlog
What they're looking for
- Drive program operational excellence by establishing repeatable processes,: service-level expectations, metrics, and reporting for third party security risk management
- Evaluate third party security controls, cloud architectures (AWS/GCP),: integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
- Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
- Manage and prioritize a portfolio of complex security risk reviews and: initiatives simultaneously, balancing business enablement with risk reduction