The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls ...
The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls ...
Data Center Security Manager, Compliance, Safety, and Risk Management
Pryor Creek, OK Β· On-site
$144K/yr
Data Center Security Manager, Compliance, Safety, and Risk Management Google Pryor, OK 74361, USA Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper ...
New
Data Center Security Manager, Compliance, Safety, and Risk Management
Pryor Creek, OK Β· On-site
$144K/yr
Data Center Security Manager, Compliance, Safety, and Risk Management Google Pryor, OK 74361, USA Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper ...
New
Senior Security Risk Management Analyst - Remote Location: Remote Duration: 6 Months Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered ...
Senior Security Risk Management Analyst - Remote Location: Remote Duration: 6 Months Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered ...
Information Security Manager
Rochester, NY Β· On-site
$105K - $125K/yr
Risk Management: * Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies. * Advise senior management on risk levels and security posture. * Ensure that ...
Information Security Manager
Rochester, NY Β· On-site
$105K - $125K/yr
Risk Management: * Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies. * Advise senior management on risk levels and security posture. * Ensure that ...
Information Security Manager
Rochester, NY Β· On-site
$105K - $125K/yr
Risk Management: * Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies. * Advise senior management on risk levels and security posture. * Ensure that ...
New
Information Security Manager
Rochester, NY Β· On-site
$105K - $125K/yr
Risk Management: * Identify vulnerabilities, conduct threat assessments, and implement mitigation strategies. * Advise senior management on risk levels and security posture. * Ensure that ...
New
Risk Management Specialist
$90K - $118K/yr
Summary This position is located in the Risk Management Agency (RMA), Deputy Administrator for Insurance Services (DAIS), Raleigh, NC Risk Management Region which serves the states of CT, DE, ME, MD ...
Risk Management Specialist
$90K - $118K/yr
Summary This position is located in the Risk Management Agency (RMA), Deputy Administrator for Insurance Services (DAIS), Raleigh, NC Risk Management Region which serves the states of CT, DE, ME, MD ...
... risk assessments and vulnerability management β’ Ensure compliance with regulatory requirements and standards β’ Manage security incidents and respond to breaches β’ Lead a team of security ...
... risk assessments and vulnerability management β’ Ensure compliance with regulatory requirements and standards β’ Manage security incidents and respond to breaches β’ Lead a team of security ...
Security Manager
Colorado Springs, CO Β· On-site
Accreditation, Risk, & Documentation * Oversee the ongoing maintenance of SCIFs and other classified spaces at your site. * Conduct and manage security risk assessments, audits, and vulnerability ...
Security Manager
Colorado Springs, CO Β· On-site
Accreditation, Risk, & Documentation * Oversee the ongoing maintenance of SCIFs and other classified spaces at your site. * Conduct and manage security risk assessments, audits, and vulnerability ...
Security Manager
Colorado Springs, CO Β· On-site
Accreditation, Risk, & Documentation * Oversee the ongoing maintenance of SCIFs and other classified spaces at your site. * Conduct and manage security risk assessments, audits, and vulnerability ...
Security Manager
Colorado Springs, CO Β· On-site
Accreditation, Risk, & Documentation * Oversee the ongoing maintenance of SCIFs and other classified spaces at your site. * Conduct and manage security risk assessments, audits, and vulnerability ...
IT Security Manager (GRC)
Chicago, IL Β· On-site
... security risk management program. The role involves managing risk-related activities, leading a team of security professionals, and advising business leaders on information security risks.
IT Security Manager (GRC)
Chicago, IL Β· On-site
... security risk management program. The role involves managing risk-related activities, leading a team of security professionals, and advising business leaders on information security risks.
Knowledge of security risk management, regulatory requirements, and compliance obligations. * Strong stakeholder management, relationship-building, problem-solving, and communication skills.
Knowledge of security risk management, regulatory requirements, and compliance obligations. * Strong stakeholder management, relationship-building, problem-solving, and communication skills.
Demonstrated expertise in governance, risk management, and cybersecurity compliance, including the development and implementation of policies, standards, and control frameworks. * Strong working ...
Quick apply
Demonstrated expertise in governance, risk management, and cybersecurity compliance, including the development and implementation of policies, standards, and control frameworks. * Strong working ...
Knowledge of security risk management, regulatory requirements, and compliance obligations. * Strong stakeholder management, relationship-building, problem-solving, and communication skills.
Knowledge of security risk management, regulatory requirements, and compliance obligations. * Strong stakeholder management, relationship-building, problem-solving, and communication skills.
$70K - $102K/yr
... security and actively participates in risk-related activities in this area. Provides assistance with claims investigation, management and litigation. Facilitates reporting of safety data/events.
$70K - $102K/yr
... security and actively participates in risk-related activities in this area. Provides assistance with claims investigation, management and litigation. Facilitates reporting of safety data/events.
Support all Risk Management Framework (RMF) authorization and accreditation activities, including ... Conduct security evaluations, audits, and reviews; support development of system contingency and ...
Support all Risk Management Framework (RMF) authorization and accreditation activities, including ... Conduct security evaluations, audits, and reviews; support development of system contingency and ...
Senior Manager, Information Security
Berkeley Heights, NJ Β· On-site
$130K - $170K/yr
Cybersecurity governance and risk management; security operations & incident response; Microsoft 365 & cloud security; vendor risk management; security architecture; executive communication ...
Senior Manager, Information Security
Berkeley Heights, NJ Β· On-site
$130K - $170K/yr
Cybersecurity governance and risk management; security operations & incident response; Microsoft 365 & cloud security; vendor risk management; security architecture; executive communication ...
Spain Security Manager
Misenheimer, NC Β· On-site
Proven experience in security management, investigations, or risk management Strong analytical and reporting skills Experience supervising teams or coordinating security staff High level of integrity ...
Spain Security Manager
Misenheimer, NC Β· On-site
Proven experience in security management, investigations, or risk management Strong analytical and reporting skills Experience supervising teams or coordinating security staff High level of integrity ...
Retail Security Supervisor - Eastern - PT
Las Vegas, NV Β· On-site
$15.50 - $17.75/hr
Security Manager > Director of Risk Management PositionSummary The Retail Security Supervisor supports retail operations by serving in a dual-function role that combines reception and security ...
Retail Security Supervisor - Eastern - PT
Las Vegas, NV Β· On-site
$15.50 - $17.75/hr
Security Manager > Director of Risk Management PositionSummary The Retail Security Supervisor supports retail operations by serving in a dual-function role that combines reception and security ...
... risk assessments and vulnerability management β’ Ensure compliance with regulatory requirements ... of security professionals β’ Provide regular reports and updates to senior management ...
... risk assessments and vulnerability management β’ Ensure compliance with regulatory requirements ... of security professionals β’ Provide regular reports and updates to senior management ...
Associates within TDRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a ...
Associates within TDRM are highly-skilled information security, cybersecurity, site reliability engineering, technology, data analyst, data scientist, and risk management professionals. They have a ...
Risk Management Security Manager information
See salary details
$43.5K - $54.8K
8% of jobs
$54.8K - $66K
14% of jobs
$71.2K is the 25th percentile. Wages below this are outliers.
$66K - $77.3K
6% of jobs
$77.3K - $88.6K
8% of jobs
$88.6K - $99.9K
11% of jobs
The median wage is $102.2K / yr.
$99.9K - $111.1K
13% of jobs
$111.1K - $122.4K
11% of jobs
$125.8K is the 75th percentile. Wages above this are outliers.
$122.4K - $133.7K
15% of jobs
$133.7K - $145K
8% of jobs
$145K - $156.2K
4% of jobs
$156.2K - $167.5K
2% of jobs
$43.5K
$103.7K
$167.5K
How much do risk management security manager jobs pay per year?
What does a risk management security manager do?
How does a risk management security manager typically collaborate with other departments to ensure organizational security?
What are the key skills and qualifications needed to thrive as a risk management security manager, and why are they important?
What is the difference between Risk Management Security Manager vs Security Analyst?
| Aspect | Risk Management Security Manager | Security Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CISSP, Security+ |
| Work Environment | Strategic, managerial, policy-focused | Operational, technical, monitoring |
| Employer & Industry Usage | Corporate, government, large organizations | IT firms, security service providers, corporate |
The Risk Management Security Manager focuses on developing security policies, managing risks, and overseeing security programs at a strategic level. In contrast, a Security Analyst handles day-to-day security monitoring, incident response, and technical analysis. Both roles require relevant certifications, but the Manager's role is broader and more strategic, while the Analyst's role is more technical and operational.
What do you need to be a risk management security manager?
What is a risk management security manager?
What cities are hiring for Risk Management Security Manager jobs?
Cities with the most Risk Management Security Manager job openings:
What states have the most Risk Management Security Manager jobs?
States with the most job openings for Risk Management Security Manager jobs include:
What are popular job titles related to Risk Management Security Manager jobs?
For Risk Management Security Manager jobs, the most frequently searched job titles are:
Security Risk Management Lead
Remote
Full-time
Medical, Dental, Vision
Re-posted 9 days ago
Job description
Affirm values security as being critical to the company's continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
The ideal candidate will design, develop, configure, and implement solutions to complex technical and business problems across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable shaping policy and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will operate as a subject matter expert, interface with business and engineering stakeholders, and play a key role in transforming Security Risk Management from a compliance oriented function into a security engineering discipline.
What You'll Do
- Lead and mature Affirm's Security Third Party Program, including the design, implementation, and continuous improvement of processes, controls, and operational workflows
- Build and maintain automation that replaces manual GRC tasks: intake, triage, evidence collection, control validation, tracking, escalations, and reporting, using either Python, low code platforms, and agentic coding tools (Cursor, Claude, etc.)
- Design and operate workflow orchestration and integrations across systems like ticketing, GRC platforms, vendor management tools, identity providers, and cloud control planes
- Partner closely with Procurement, Legal, Engineering, IT, Compliance, Privacy, and business stakeholders to assess and manage security risk across third party relationships
- Translate ambiguous business and security requirements into practical, scalable program solutions and decision frameworks
- Identify opportunities to automate manual processes across the program and prototype solutions yourself rather than waiting on an engineering backlog
- Drive program operational excellence by establishing repeatable processes, service-level expectations, metrics, and reporting for third party security risk management
- Evaluate third party security controls, cloud architectures (AWS/GCP), integration patterns, and risk posture, and provide clear recommendations to stakeholders and leadership
- Conduct light threat models on high risk integrations and partner with Security SMEs for deeper diligence
- Manage and prioritize a portfolio of complex security risk reviews and initiatives simultaneously, balancing business enablement with risk reduction
- Partner with technical teams to implement or optimize systems and tools that support program automation and workflow orchestration
- Develop dashboards, reporting mechanisms, and program insights (SQL, BI tools, or custom tooling) that improve visibility into risk trends, bottlenecks, and program performance
- Act as a trusted advisor and SME on third party security risk management, helping stakeholders make informed, risk based decisions
- Contribute to the broader Security Risk Management strategy by identifying opportunities to scale, simplify, and strengthen security governance processes through engineering
What We Look For
- 5+ years of experience in Information Security, Risk Management, Engineering and/or relevant roles
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python; you don't need to be a software engineer, but you should be fluent enough to read, modify, and run scripts, build automations, and ship small tools end-to-end
- Familiarity with cloud environments (AWS, GCP, or Azure) - IAM, logging, common services, and the security risks/controls that apply to cloud-deployed third parties and integrations
- Excellent written and verbal communications skills
- Experience engineering solutions via Python, Claude, Cursor or other agentic coding tooling
- Experience with industry based information security & control frameworks (NIST Cyber Security Framework, ISO 2700x, SOC1&2(SSAE18), PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, etc.)
- BA or BS degree in Information Security, Cyber Security, Computer Science or related field or commensurate experience
- Attention to detail and experience with security practices and security tooling
- Demonstrated ability to drive projects towards completion
- Ability to understand and communicate technical issues to non-technical teams
- Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) is a plus
Base Pay Grade - L
Equity Grade - 5
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000
USA Sapphire base pay range (all other U.S. states) per year: $146,000 - $206,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Remote-first with flexibility built inAffirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.
Benefits designed for youOur benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:
- Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
- Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
- Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
- Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.
We're committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we're happy to help.
For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.
About Affirm
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US
Year founded
2012