Affirm
Security Risk Management Specialist II
Remote Canada · Mid
Stay score
odds of building a lasting career here
Sponsors, but it's cap-subject — you still face the weighted lottery (~45% per draw at Level III). Good if you win; have a cap-exempt backup on your list.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card intent detected
Files H-1B transfers
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows.
- Affirm values security as being critical to the company's continued success.
Responsibilities
- You will build and maintain automation to reduce manual GRC workflows, using Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
- You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution.
- You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
- You will help develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture.
- We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
Requirements
- You have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
- You are comfortable using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and have working knowledge of Python for scripting or automation.
- You have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
- You have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
- Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office.
Nice to have
- You hold (or are working toward) a professional certification such as CISSP, CISM, CISA, or CRISC or bring equivalent practical experience.
- A BA/BS in a relevant field, or equivalent experience, is preferred.
Compensation
- Employees new to Affirm typically come in at the start of the pay range.
- Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
- Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents).
- CAN base pay range per year: CAD $101,000 - $151,000
Benefits
- Equity Grade - 3
- In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).
- We're extremely proud to offer competitive benefits that are anchored to our core value of people come first.
- Some key highlights of our benefits package include:
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
Company info
- The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
- We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.
This listing is sourced directly from Affirm's careers page and normalized into a canonical job model.