1

Security Risk Management Specialist Jobs (NOW HIRING)

What You'll Do We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation ...

$115K - $165K/yr

Affirm is hiring a remote candidate for Security Risk Management Specialist II. This is a full time position. Work location: USA. The role typically involves technologies such as Python, AWS, GCP ...

What You'll Do We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation ...

Senior Risk Management Specialist

Austin, TX · On-site

$97K/yr

The client is looking for Risk Management Specialist with experience in information security or cyber risk to lead the design, implementation, and optimization of enterprise and third-party risk ...

The Risk Management Specialist works within the Risk Management department and is responsible for identifying, assessing, monitoring, and making recommendations to manage and mitigate operational ...

next page

Showing results 1-20

Security Risk Management Specialist information

See salary details

$37.5K

$72.9K

$138.5K

How much do security risk management specialist jobs pay per year?

As of Sep 9, 2026, the average yearly pay for security risk management specialist in the United States is $72,927.00, according to ZipRecruiter salary data. Most workers in this role earn between $50,000.00 and $84,500.00 per year, depending on experience, location, and employer.

What is a security risk management specialist?

Security Risk Management Specialists are professionals who identify, assess, and develop strategies to mitigate risks that could threaten an organization’s assets, data, and operations. They analyze potential security threats, develop policies and procedures, and monitor compliance to ensure the safety of people and information. Their work involves collaborating with other departments to implement security measures and respond to incidents. These specialists are vital for organizations to manage risks and maintain regulatory compliance.

What are the key skills and qualifications needed to thrive as a security risk management specialist?

To thrive as a Security Risk Management Specialist, you need expertise in risk assessment, threat analysis, and security frameworks, often supported by a degree in information security or a related field. Familiarity with tools such as risk management software, SIEM systems, and certifications like CISSP or CISM are commonly expected. Strong analytical thinking, communication, and problem-solving abilities make someone stand out in this role. These skills and qualifications are crucial for identifying vulnerabilities, mitigating threats, and ensuring organizational resilience against security risks.

How does a security risk management specialist typically collaborate with other departments to enhance organizational security?

Security Risk Management Specialists frequently work cross-functionally, partnering with IT, legal, compliance, and operations teams to identify, assess, and mitigate potential security risks. They often facilitate risk assessments, lead security awareness training, and help develop incident response plans in collaboration with key stakeholders. This role requires strong communication skills to translate technical risks into business terms, ensuring all departments understand their role in maintaining security. Regular meetings and project involvement across teams are common, fostering a proactive security culture throughout the organization.

What is the difference between Security Risk Management Specialist vs Security Analyst?

AspectSecurity Risk Management SpecialistSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, security planningMonitoring security systems, incident response, vulnerability analysis
Industry UsageCorporate security, government agencies, consulting firmsIT departments, cybersecurity firms, financial institutions

The Security Risk Management Specialist focuses on identifying and mitigating security risks through strategic planning and policy development. In contrast, the Security Analyst primarily monitors security systems and responds to incidents. Both roles require similar certifications and are vital in protecting organizational assets, but their daily tasks and focus areas differ.

How much do security risk management specialists make?

Security risk management specialists typically earn a median annual salary of around $80,000 to $120,000, depending on experience, certifications, and industry. Higher salaries are common for those with advanced skills, security certifications, or in senior roles within large organizations.

What does a security risk management specialist do?

A security risk management specialist assesses and identifies potential security threats to an organization, develops strategies to mitigate risks, and implements security policies and procedures. They often use risk assessment tools, conduct audits, and may hold certifications like CISSP or CISM to ensure effective security management.
More about Security Risk Management Specialist jobs

What are popular job titles related to Security Risk Management Specialist jobs?

For Security Risk Management Specialist jobs, the most frequently searched job titles are:

Infographic showing various Security Risk Management Specialist job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $72,927 per year, or $35.1 per hour.

Security Risk Management Specialist II

Remote

Affirm
Finance and Insurance • 51 - 200 employees

$115K - $165K/yr

Full-time

Medical, Dental, Vision

Posted 22 days ago


Job description

About the Team

Affirm values security as being critical to the company's continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.


About the Role

The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will develop deep expertise across the security risk domain, partner closely with business and engineering stakeholders, and play an active role in Affirm's transformation of Security Risk Management from a compliance-oriented function into a security engineering discipline.


What You'll Do

We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm's Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.

  • You will conduct third-party security assessments, reviewing vendor questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm's TPRM program.
  • You will build and maintain automation to reduce manual GRC workflows, using Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
  • You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution.
  • You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
  • You will help develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture.
  • You will contribute to process improvements and program documentation that mature Affirm's security governance over time.

What We Look For
  • You have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
  • You are comfortable using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and have working knowledge of Python for scripting or automation.
  • You have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
  • You have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
  • You communicate clearly in writing and verbally, and can translate security risk concepts for both technical and non-technical audiences.
  • You hold (or are working toward) a professional certification such as CISSP, CISM, CISA, or CRISC or bring equivalent practical experience. A BA/BS in a relevant field, or equivalent experience, is preferred.
Compensation & Benefits

Base Pay Grade - J

Equity Grade - 4

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $130,000 - 180,000 

USA Sapphire base pay range (all other U.S. states) per year: $115,000 - 165,000 

Please note that visa sponsorship is not available for this position.

#LI-Remote