... assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • ...
... assess and manage security risk across third party relationships • Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks • ...
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
As a(an) Security Risk Application Engineer with HCA Healthcare you can be a part of an ... Conducts solutions to build technical security reviews and assessments of applications, processes ...
New
Security Analyst
Brentwood, TN · On-site
The Security Analyst will also work to continually monitor compliance aspects, assisting in risk assessments, monitoring, and security projects to support effective implementation and support. You ...
Security Analyst
Brentwood, TN · On-site
The Security Analyst will also work to continually monitor compliance aspects, assisting in risk assessments, monitoring, and security projects to support effective implementation and support. You ...
Security Leadership & Program Oversight * Provide strategic leadership for all GMS security ... Risk Assessment & Operational Support * Monitor national and international events to identify ...
Security Leadership & Program Oversight * Provide strategic leadership for all GMS security ... Risk Assessment & Operational Support * Monitor national and international events to identify ...
... risk assessments and identify potential threats and vulnerabilities - Monitor and analyze security systems, including CCTV, access control and alarm systems, and take appropriate action in response ...
New
Quick apply
... risk assessments and identify potential threats and vulnerabilities - Monitor and analyze security systems, including CCTV, access control and alarm systems, and take appropriate action in response ...
New
Cybersecurity Risk Analyst
Nashville, TN · On-site
Produce a comprehensive, written, security assessment of vendors security posture * Experience ... Familiarity with using Third Party Risk Management tools/processes such as OneTrust, SIG or similar ...
Cybersecurity Risk Analyst
Nashville, TN · On-site
Produce a comprehensive, written, security assessment of vendors security posture * Experience ... Familiarity with using Third Party Risk Management tools/processes such as OneTrust, SIG or similar ...
Produce a comprehensive, written, security assessment of vendors security posture * Experience ... Familiarity with using Third Party Risk Management tools/processes such as OneTrust, SIG or similar ...
Produce a comprehensive, written, security assessment of vendors security posture * Experience ... Familiarity with using Third Party Risk Management tools/processes such as OneTrust, SIG or similar ...
Vulnerability & Risk Management Specialist with Security Clearance
Oak Ridge, TN · On-site
$85K - $145K/yr
Performs risk assessments for changes, new systems, and emerging threats; Maintains the ... SOC (Security Operations Center) Capabilities: Reviews and monitors SIEM alerts, logs, and security ...
Vulnerability & Risk Management Specialist with Security Clearance
Oak Ridge, TN · On-site
$85K - $145K/yr
Performs risk assessments for changes, new systems, and emerging threats; Maintains the ... SOC (Security Operations Center) Capabilities: Reviews and monitors SIEM alerts, logs, and security ...
... Security, Risk Assessments, Security Technologies, Web Application Security Competencies Analytical Thinking, Effective Communications, Information Security Management, Information Security ...
... Security, Risk Assessments, Security Technologies, Web Application Security Competencies Analytical Thinking, Effective Communications, Information Security Management, Information Security ...
You'll partner with technology and business stakeholders to support audit readiness efforts, manage security controls, assess risk, and ensure alignment with industry frameworks and regulatory ...
You'll partner with technology and business stakeholders to support audit readiness efforts, manage security controls, assess risk, and ensure alignment with industry frameworks and regulatory ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Meaningful Use Security Risk Analyses, HIPAA), and managing risk assessment activities (e.g. HIPAA, PCI, NIST Cyber Security Framework). In addition, this position will ensure all parts of the risk ...
Cyber Security Analyst
Columbia, TN · On-site
$50.25/hr
Support HIPAA Security Rule compliance activities and security risk assessments * Maintain security documentation, policies, standards, and procedures * Partner with infrastructure and leadership ...
Cyber Security Analyst
Columbia, TN · On-site
$50.25/hr
Support HIPAA Security Rule compliance activities and security risk assessments * Maintain security documentation, policies, standards, and procedures * Partner with infrastructure and leadership ...
Global Security Director
Nashville, TN · On-site
Provide executive protection oversight, including risk assessments, travel security, and event security. * Support Board and C-suite meetings, site visits, and global travel with appropriate security ...
Global Security Director
Nashville, TN · On-site
Provide executive protection oversight, including risk assessments, travel security, and event security. * Support Board and C-suite meetings, site visits, and global travel with appropriate security ...
Provide executive protection oversight, including risk assessments, travel security, and event security. * Support Board and Csuite meetings, site visits, and global travel with appropriate security ...
Provide executive protection oversight, including risk assessments, travel security, and event security. * Support Board and Csuite meetings, site visits, and global travel with appropriate security ...
Freelance Security Risk Assessment information
What is the difference between Freelance Security Risk Assessment vs Security Consultant?
| Aspect | Freelance Security Risk Assessment | Security Consultant |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or CEH often required | Similar certifications, often with additional experience requirements |
| Work Environment | Independent, project-based, often remote or on-site at client locations | Typically employed by firms or consulting agencies, may work on multiple projects |
| Industry Usage | Used by organizations seeking independent risk assessments | Engaged for broader security strategy, policy development, and consulting |
While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.
Job description
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The Security Risk Management Lead will design, develop, and implement solutions to complex technical and business problems while transforming Security Risk Management into a security engineering discipline.
Responsibilities:
• Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
• Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
• Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
• Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
• Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
• Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
• Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
• Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
• Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
• Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
• Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
• Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
• Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
• Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
Qualifications:
Required:
• 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
• Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
• Familiarity with cloud environments (AWS, GCP, or Azure) — IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
• Excellent written and verbal communications skills
• Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
• Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
• BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
• Attention to detail and experience with security practices and security tooling
• Demonstrated ability to drive projects towards completion
• Ability to understand and communicate technical issues to non-technical teams
Preferred:
• Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)
Company:
Affirm is a financial technology services company that offers installment loans to consumers at the point of sale. Founded in 2012, the company is headquartered in San Francisco, USA, with a team of 1001-5000 employees. The company is currently Late Stage.
About Affirm
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US
Year founded
2012