wagey.ggwagey.ggv1.0-68eec7a-3-May
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs/Director of Security Role/Affirm - Director, Affirm Bank Information Security
Affirm

Affirm - Director, Affirm Bank Information Security

Remote US - Hybrid$300k - $360k+ Equity2mo ago
In OfficeDirectorNABankingFintechDirector of SecurityCCODue DiligenceReportingRisk ManagementVendor ManagementData Governance

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Responsibilities

• 1. Information Security Program Development • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards. • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response. • Ensure alignment with the Bank’s overall risk management and governance frameworks. • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts. • 2. Cybersecurity and Threat Management • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks. • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management). • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required. • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats. • 3. Third-Party and Affiliate Risk Oversight • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance. • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services. • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated. • 4. Data Governance and Privacy Protection • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws). • Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse. • Partner with business and technology teams to integrate privacy-by-design principles into new products and services. • 5. Business Continuity and Resilience • Lead development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives. • Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions. • Support resilience planning for key systems, vendors, and communication protocols. • 6. De Novo and Pre-Opening Readiness • Build and document the Bank’s information security program as part of the de novo application process. • Establish security architecture, monitoring tools, and vendor relationships prior to launch. • Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience. • Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones. • 7. Leadership and Culture • Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability. • Provide training and guidance across the organization to enhance information security awareness. • Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy. • Build and lead a capable, mission-driven security team to support the Bank’s evolving needs. • What We Look For • What We Look For • What We Look For • Minimum of 10 years of information security and technology risk management experience, with at least 5 years in a leadership capacity at a regulated financial institution or Fintech. • Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards. • Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations. • Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments. • Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators. • Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making. • Core Competencies • Core Competencies • Core Competencies • Expert knowledge of information security principles, frameworks, and regulatory requirements. • Strategic thinker with strong operational execution and control discipline. • Effective communicator capable of influencing across technical and business functions. • Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement. • Affirm Values • At Affirm, we live by our values: People Come First, No Fine Print, It’s On Us, Simplify, and Push the Envelope. As CCO, you will embody these principles while building the foundation of Affirm Bank as a trusted, transparent, and innovative financial institution.

Benefits

• Base Pay Grade - T • Base Pay Grade • Equity Grade - 14 • Equity Grade • USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000 • USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: • USA Sapphire base pay range (all other U.S. states) per year: $267,000 - $327,000 • USA Sapphire base pay range (all other U.S. states) per year: • Please note that visa sponsorship is not available for this position. • Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities. • We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include: • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount • We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process. • [For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records. • By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Similar Jobs

OlssonOlsson - Mergers & Acquisitions Analyst2d ago
·Remote - USA *·$80k - $80k/year
RemoteNAMidInvestment BankingBankingQA AnalystFinancial ModelingDue DiligenceClose
CensysCensys - Director of Security/GRC2d ago
·Remote - USA·$206k - $237k/year + Equity
RemoteNADirectorCybersecurityCloud ComputingDirector of SecurityTeam ManagementTraining DevelopmentAWSGCPAzure
ZscalerZscaler - Director, Revenue Enablement2d ago
·Remote - France - Hybrid
In OfficeEMEADirectorEducationSales Enablement ManagerDirector of SecurityLearning & DevelopmentStorytellingInstructional DesignNew Hire Onboarding
clearbankclearbank - Due Diligence Analyst - Corporate Customers2d ago
·London, Hybrid, United Kingdom
In OfficeEMEABankingPaymentsQA AnalystExcelDue DiligenceProspectingACCA
rularula - Director of B2B Activation (Remote)3d ago
·Remote - USA·$182k - $203k/year
RemoteNADirectorPharmaceuticalsTelemedicineDirector of SecurityCoachingProduct MarketingB2BHubSpotSalesforce
Get Started Free

No credit card. Takes 10 seconds.

Privacy·Terms··Contact·FAQ·Wagey on X