Affirm Logo

Affirm

Director, Information Technology & Security

Reposted One Month Ago
Easy Apply
Remote
Hiring Remotely in United States
267K-360K Annually
Expert/Leader
Easy Apply
Remote
Hiring Remotely in United States
267K-360K Annually
Expert/Leader
The CISO will develop and manage the Bank's information security programs, ensuring compliance and protecting customer data while mitigating risks. They will also lead a security team, oversee third-party risk, and promote a culture of security awareness across the organization.
The summary above was generated by AI

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

Remote US

The Director, Information Technology & Security will serve as a key member of the Bank's Management Team, serving as the Chief Information Security Officer, and will be responsible for establishing and leading the Bank's information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), this leader will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank's risk appetite, and protects customer and institutional data.

This is a blended leadership role requiring both high-level strategic influence and deep technical execution. You will lead the development of information security governance, technical controls, and oversight of infrastructure and engineering, ensuring a strong and scalable security posture from inception. This leader must be a practitioner at heart—willing to "roll up their sleeves" to lead the technical build phase, collaborate closely with engineering on architecture, and ensure security is integrated into every aspect of the Bank's systems and operations.

What You’ll Do
  1. Oversee infrastructure design and IT Engineering 
  2. Information Security Program Development
  • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
  • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
  • Ensure alignment with the Bank’s overall risk management and governance frameworks.
  • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
  • Lead the technical build phase of the Bank's infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration.
  • Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance.
  1. Cybersecurity and Threat Management
  • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
  • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
  • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
  • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
  1. Third-Party and Affiliate Risk Oversight
  • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
  • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
  • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
  • Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data.
  1. Data Governance and Privacy Protection
  • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
  • Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
  • Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
  1. Business Continuity and Resilience
  • Assist Risk Officer in development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
  • Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
  • Support resilience planning for key systems, vendors, and communication protocols.
  1. De Novo and Pre-Opening Readiness
  • Build and document the Bank’s technology and information security program as part of the de novo application process.
  • Establish security architecture, monitoring tools, and vendor relationships prior to launch.
  • Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
  • Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
  1. Leadership and Culture
  • Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
  • Provide training and guidance across the organization to enhance information security awareness.
  • Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
  • Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.
What We Look For
  • Minimum of 10 years of experience in information technology, and security and technology risk management, with a proven track record of moving between strategic planning and hands-on technical execution.
  • Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
  • Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
  • Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
  • Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
  • Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.
  • Deep expertise in cloud-native infrastructure (AWS/GCP), DevOps practices, and software-defined security controls.
  • Demonstrated ability to "roll up sleeves" and contribute directly to the technology build while simultaneously managing executive stakeholders and regulators.
Core Competencies
  • Expert knowledge of information security principles, frameworks, and regulatory requirements.
  • Strategic thinker with strong operational execution and control discipline.
  • Effective communicator capable of influencing across technical and business functions.
  • Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.
Affirm Values

At Affirm, we live by our values: People Come First, No Fine Print, It’s On Us, Simplify, and Push the Envelope. As CCO, you will embody these principles while building the foundation of Affirm Bank as a trusted, transparent, and innovative financial institution.

Compensation & Benefits

Base Pay Grade - T

Equity Grade - 14

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. 

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000

USA Sapphire base pay range (all other U.S. states) per year: $267,000 - $327,000

Please note that visa sponsorship is not available for this position.

#LI-Remote


Remote-first with flexibility built in
Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for you
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
  • Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.

We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.

For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.

Similar Jobs at Affirm

3 Days Ago
Easy Apply
Remote
United States
Easy Apply
204K-290K Annually
Mid level
204K-290K Annually
Mid level
Big Data • Fintech • Mobile • Payments • Financial Services
Own and deliver engineering onboarding across North America and EMEA, including technical learning, hands-on programming, onboarding plans, and community building. Partner with Engineering, Developer Productivity, SRE, Security, Architecture, Product, and corporate teams to create credible content covering AI-assisted development, testing, deployment, observability, and production support. Coordinate cohort logistics, gather feedback, and continuously improve onboarding operations and experiences.
Top Skills: Ai-Assisted DevelopmentCode ReviewContinuous IntegrationDeploymentIncident ResponseObservabilitySoftware Testing
3 Days Ago
Easy Apply
Remote
United States
Easy Apply
173K-255K Annually
Senior level
173K-255K Annually
Senior level
Big Data • Fintech • Mobile • Payments • Financial Services
Build and scale backend data platforms and services for real-time loan origination and financial reporting. Lead quarterly delivery, guide engineers, define technical plans, collaborate with product and design partners, improve reliability and operational practices, monitor service metrics, participate in on-call support, uphold engineering quality standards, and mentor team members. The role requires developing highly available distributed systems and scalable data pipelines using technologies such as Python, Kotlin, AWS, MySQL, Kubernetes, Spark, and Airflow.
Top Skills: AirflowAWSKotlinKubernetesMySQLPythonSpark
3 Days Ago
Easy Apply
Remote
United States
Easy Apply
173K-255K Annually
Senior level
173K-255K Annually
Senior level
Big Data • Fintech • Mobile • Payments • Financial Services
Senior frontend-focused software engineer responsible for authentication, verification, and fraud experiences across web, mobile, and backend systems. The role owns team goals, designs and delivers highly available systems, collaborates with product and design partners, improves engineering standards, supports operations and on-call efforts, and mentors engineers. Candidates should have strong web application architecture experience, proficiency with React or Vue and JavaScript or TypeScript, and excellent communication skills.
Top Skills: JavaScriptReactTypescriptVue

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account