The opportunity
Affirm values security as being critical to the company's continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls,…
What you'll do
We are looking for a curious, collaborative Security Risk Management: Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.
You will conduct third-party security assessments, reviewing vendor: questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm's TPRM program.
You will build and maintain automation to reduce manual GRC workflows, using: Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
You will configure and maintain integrations across ticketing, GRC, and: vendor management platforms to support consistent and repeatable workflow execution.
You will partner with Procurement, Legal, Engineering, IT, Compliance, and: Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
You will help develop and maintain dashboards, metrics, and reporting that: give stakeholders clear visibility into third-party risk posture.
What they're looking for
- You will contribute to process improvements and program documentation that: mature Affirm's security governance over time.