✦ Luna Orbit — Cybersecurity

Senior Manager, Security Risk Management

at Affirm

📍 Remote, US Remote 💰 $223K – $300K USD / year Posted April 09, 2026
Salary $223K – $300K USD / year
Type Full-Time
Experience senior
Exp. Years 7+ years in information security, risk management, or GRC roles, with a minimum of 3 years managing teams
Education Not specified
Category Cybersecurity

Lead Security Governance and Third-Party Risk Management programs; own policy, controls, and KPIs; scale governance across vendor life cycle; build and lead a team; report to executives and regulators.

  • Own program strategy & governance
  • Lead Security TPRM across vendor lifecycle
  • Oversee fourth-party oversight and remediation cycles
  • Manage KPIs and dashboards
  • Build and scale Governance and TPRM teams

Focus on governance frameworks (NIST, ISO 27001), TPRM tooling (AuditBoard, Jira, BI tools), CI/CD integration security, threat modeling, regulatory engagements

The ideal candidate is a senior security leader with a proven track record delivering governance and TPRM programs in fintech or regulated environments; strong relationship management with executive stakeholders; hands-on tooling experience (AuditBoard, Jira, BI tools).

7+ years in information securityrisk managementor GRC roleswith a minimum of 3 years managing teamsDemonstrated ownership of a TPRM program or security governance program in a regulated or high-growth technology environment (fintech preferred)Strong knowledge of security frameworks (NISTISO)compliance standards (SOC2PCI)and vendor risk processes (IRQ/DDQ/SME assessments)Hands-on familiarity with TPRM/GRC tooling and observability: AuditBoard (or equivalent)JiraBI tools (Sigma/Tableau/Looker)and experience with integrations/APIsExcellent stakeholder management across legalprocurementengineeringproductand executive leadershipCertifications such as CISSPCISMCRISCor similarPractical experience with threat-modeling approaches and third-party integration security (APISSO/OAuth/SAMLTLS)Experience scaling automation for GRC/TPRM programs and integrating security checks into CI/CD pipelinesPrior experience in fintech or highly regulated industries
CISSPCISMCRISC
AuditBoardJiraSigmaTableauLookerMetricStreamAPIsCI/CD
Security governancesecurity risk managementthird-party risk managementGRCNIST CSFISO 27001SOC 2PCIAuditBoardJiraSigmaTableauLookerMetricStreamthreat modelingCI/CDAPIsSSO/OAuth/SAMLTLSfintechvendor riskinternal audit liaisonregulatory engagementsCISSPCISMCRISC
Security GovernanceSecurity Third-Party Risk Management (TPRM)NIST CSFISO 27001SOC 2PCIAuditBoardJiraSigmaTableauLookerMetricStreamThreat modelingAPIsCI/CD checksApexREST APISOAP API
Excellent stakeholder managementStrong communicationLeadershipStrategic thinkingAbility to influence decisionsProblem solvingTeam buildingCross-functional collaboration

Required

CISSPCISMCRISC
Industry Fintech
Job Function Lead security governance and third-party risk management programs for a fintech tech company
Role Subtype Security governance lead
Tech Domains NIST CSF, ISO 27001, SOC 2, PCI, AuditBoard, Jira, Tableau, Looker, APIs, CI/CD
senior managersecurity governancesecurity third-party risk managementTPRMNIST CSFISO 27001SOC 2PCIAuditBoardJiraSigmaTableauLookerMetricStreamAPIsCI/CDThreat modelingSSO/OAuth/SAMLTLSfintechvendor riskinternal audit liaisonregulatory engagementsCISSPCISMCRISCthird-party risk managementnist csfiso 27001soc 2pciauditboardjiratableau

Lack of 7+ years information security experience, No experience managing teams (3+ years), No fintech or regulated industry experience, Lack of knowledge of NIST/ISO frameworks, Inability to work with remote/hybrid environment

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile