Security Risk Specialist II - TPRM & Automation

Affirm

Chicago (IL)

On-site

USD 115,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health care coverage
Flexible Spending Wallets
Time off
ESPP

Job summary

Affirm is seeking a Security Risk professional to evaluate third-party risk and automate GRC workflows to scale the Security Third Party Program. You will work with business and engineering teams to transform security governance into an engineering-led discipline, applying policy to vendor decisions and building scalable, code-defined processes.

The role emphasizes cross-functional collaboration, dashboards, and robust risk reporting while helping to evolve the program beyond compliance into

Qualifications

  • 三+ years in Information Security, Risk Management, Compliance, or a related field.
  • Familiar with agentic coding tools and Python for scripting or automation.
  • Working knowledge of cloud environments and security frameworks (NIST, ISO 27001, SOC 2, PCI DSS).

Responsibilities

  • Conduct third-party security assessments and document risk findings.
  • Build and maintain automation to reduce manual GRC workflows.
  • Configure and maintain integrations across ticketing, GRC, and vendor management platforms.
  • Partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews and actions.
  • Develop and maintain dashboards and reporting for stakeholders.
  • Contribute to process improvements and documentation to mature security governance.

Skills

Python scripting
Agentic coding tools
Cloud security concepts
Security frameworks
Information security
Communication skills
Professional certification pursuit

Education

BA/BS in a relevant field

Tools

Cursor
Claude Code
Copilot

Job description

Affirm is seeking a Security Risk professional to evaluate third-party risk and automate GRC workflows to scale the Security Third Party Program. You will work with business and engineering teams to transform security governance into an engineering-led discipline, applying policy to vendor decisions and building scalable, code-defined processes.

The role emphasizes cross-functional collaboration, dashboards, and robust risk reporting while helping to evolve the program beyond compliance into

Get your free, confidential resume review.

or drag and drop your file here.