Director, Affirm Bank Information Security
Affirm · Remote (United States) · Bank Strategy
About this role
Affirm is hiring a director-level Director of Engineering in the software engineering function as a remote position. The posting calls out experience with Security, Encryption, Incident Response, Vulnerability Management. Compensation is listed at $300,000–$360,000 per year.
- Role
- Director of Engineering
- Function
- software engineering
- Level
- director
- Track
- Management
- Employment
- Full-time
- Location
- Remote (United States)
- Work mode
- Remote
- Department
- Bank Strategy
More roles at Affirm
Job description
from Affirm careersAffirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
The Chief Information Security Officer (CISO) will serve as a key member of the Bank’s Executive Management Team and will be responsible for establishing and leading Bank’s information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), the CISO will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank’s risk appetite, and protects customer and institutional data.
The CISO will lead the development of information security governance, technical controls, and third-party risk oversight, ensuring a strong and scalable security posture from inception through growth. This leader will collaborate closely with technology, risk, and operations teams to ensure security is integrated into every aspect of the Bank’s systems and operations.
What You’ll Do
1. Information Security Program Development
- Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
- Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.