Security Risk Management Specialist
Posted 3 days ago
virtual vocationsDenver (CO)
Security Management SpecialistsAdministrative Management and General Management Consulting Services
SENIORITY
Senior
About the role
To support the scaling of Affirm's Third Party Risk Management program, a remote full-time Security Risk Management Specialist will evaluate third-party security assessments, automate governance workflows using modern coding tools, and collaborate with cross-functional teams to enhance security governance.
Key responsibilities
Conduct third-party security assessments, reviewing vendor questionnaires and documenting risk findings
Build and maintain automation to improve efficiency in governance, risk, and compliance workflows
Partner with various departments to execute third-party risk reviews and develop reporting metrics
Required qualifications
3+ years of experience in Information Security, Risk Management, Compliance, or a related field
Familiarity with agentic coding tools and working knowledge of Python for automation
Experience with cloud environments (AWS, GCP, or Azure) and common cloud security concepts
Knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS
Professional certification such as CISSP, CISM, CISA, or CRISC, or equivalent practical experience
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
