```html
Affirm is seeking a Security Risk Management Lead to oversee and evolve the company's Security Third Party Program in a remote US-based role. You will design and implement controls, workflows, and automation to manage security risk across vendor relationships, partnering with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business teams. This position bridges security engineering and governance, replacing manual processes with scalable, code-defined solutions.
Responsibilities
- Lead design, implementation, and continuous improvement of Affirm's Security Third Party Program, including processes, controls, and operational workflows
- Build and maintain automation to replace manual GRC tasks—intake, triage, evidence collection, control validation, tracking, escalations, and reporting—using Python, low-code platforms, or agentic coding tools (Cursor, Claude, etc.)
- Design and operate workflow orchestration and system integrations across ticketing platforms, GRC tools, vendor management systems, identity providers, and cloud control planes
- Assess and manage security risk across third-party relationships in collaboration with Procurement, Legal, Engineering, IT, Compliance, and Privacy teams
- Translate business and security requirements into practical, scalable program solutions and decision frameworks
- Identify opportunities to automate manual processes and prototype solutions independently rather than waiting on engineering resources
- Establish repeatable processes, service-level expectations, metrics, and reporting to drive operational excellence in third-party security risk management
- Evaluate third-party security controls, cloud architectures (AWS/GCP), integration patterns, and overall risk posture; provide clear recommendations to stakeholders and leadership
- Conduct threat modeling on high-risk integrations and partner with Security teams on risk mitigation
Requirements
- Demonstrated experience designing and implementing security governance, risk, and compliance (GRC) programs or third-party risk management frameworks
- Proficiency in Python or equivalent programming language for automation and scripting
- Experience with GRC platforms, ticketing systems, vendor management tools, and identity provider integrations
- Hands-on knowledge of cloud security controls and architectures (AWS and/or GCP)
- Ability to evaluate third-party security posture, control frameworks, and integration risk
- Experience with workflow automation, orchestration tools, or low-code/no-code platforms
```