Talent.com
Affirm
Director, Affirm Bank Information SecurityAffirm • Boulder, CO, United States
No longer accepting applications
Director, Affirm Bank Information Security

Director, Affirm Bank Information Security

Affirm • Boulder, CO, United States
6 days ago
Job type
  • Full-time
Job description

Overview

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The Chief Information Security Officer (CISO) will serve as a key member of the Bank’s Executive Management Team and will be responsible for establishing and leading Bank’s information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), the CISO will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank’s risk appetite, and protects customer and institutional data.

The CISO will lead the development of information security governance, technical controls, and third-party risk oversight, ensuring a strong and scalable security posture from inception through growth. This leader will collaborate closely with technology, risk, and operations teams to ensure security is integrated into every aspect of the Bank’s systems and operations.

What You’ll Do

  • Information Security Program Development
  • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
  • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
  • Ensure alignment with the Bank’s overall risk management and governance frameworks.
  • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
  • Cybersecurity and Threat Management
  • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
  • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
  • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
  • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
  • Third-Party and Affiliate Risk Oversight
  • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
  • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
  • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
  • Data Governance and Privacy Protection
  • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
  • Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
  • Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
  • Business Continuity and Resilience
  • Lead development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
  • Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
  • Support resilience planning for key systems, vendors, and communication protocols.
  • De Novo and Pre-Opening Readiness
  • Build and document the Bank’s information security program as part of the de novo application process.
  • Establish security architecture, monitoring tools, and vendor relationships prior to launch.
  • Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
  • Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
  • Leadership and Culture
  • Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
  • Provide training and guidance across the organization to enhance information security awareness.
  • Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
  • Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.

What We Look For

  • Minimum of 10 years of information security and technology risk management experience, with at least 5 years in a leadership capacity at a regulated financial institution or Fintech.
  • Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
  • Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
  • Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
  • Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
  • Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.

Core Competencies

  • Expert knowledge of information security principles, frameworks, and regulatory requirements.
  • Strategic thinker with strong operational execution and control discipline.
  • Effective communicator capable of influencing across technical and business functions.
  • Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.

Affirm Values

At Affirm, we live by our values: People Come First, No Fine Print, It’s On Us, Simplify, and Push the Envelope. As CCO, you will embody these principles while building the foundation of Affirm Bank as a trusted, transparent, and innovative financial institution.

Compensation & Benefits

Base Pay Grade - T

Equity Grade - 14

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000

USA Sapphire base pay range (all other U.S. states) per year: $267,000 - $327,000

Please note that visa sponsorship is not available for this position. Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

Benefits

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

#J-18808-Ljbffr
Create a job alert for this search

Director, Affirm Bank Information Security • Boulder, CO, United States

Similar jobs

Remote Audit Senior Manager (Digital Assets/Crypto/Exchange/Treasury/Blockchain)

BDO USABoulder, CO, United States
Remote
Full-time

The Assurance Senior Manager is responsible for developing suggestions to improve client internal controls and accounting procedures as well as advising the client on various economic and regulator... Show more

 • Promoted

Account Director

RORSuperior, CO, United States
Full-time

ROR Partners is a leading provider of data-driven marketing solutions, empowering businesses to drive growth and maximize ROI through innovative strategies and cutting-edge technologies.With expert... Show more

 • Promoted

Senior Security Data Center Network Architect

SciTec, Inc.Boulder, CO, United States
Full-time

A dynamic small business seeks a Network Architect in Boulder, CO.The ideal candidate will have extensive experience in network engineering and security, designing secure data center networks, and ... Show more

 • Promoted

Director of Autonomous Space Software & Reliability

Spire Global, Inc.Boulder, CO, United States
Full-time

A leading analytics company is seeking a Director to transform their space operations into fully autonomous systems.This role requires hands-on technical leadership and involves defining the techni... Show more

 • Promoted

Manager- Information Systems Security (ISSM)

Microchip Technology IncBoulder, CO, United States
Full-time

Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere o... Show more

 • Promoted

Senior Cloud Security Engineer - Threat Defense Lead

BEOCOM Technologies, LLC.Boulder, CO, United States
Full-time

A technology solutions firm in Boulder, Colorado, is seeking an experienced Cybersecurity Engineer to design, implement, and manage advanced security solutions.The role involves working with IT tea... Show more

 • Promoted

President & Chief Operating Officer

Ascend AnalyticsBoulder, CO, United States
Full-time

President & Chief Operating Officer.President & Chief Operating Officer.This range is provided by Ascend Analytics.Your actual pay will be based on your skills and experience — talk with your recru... Show more

 • Promoted

Operations Manager

MarriottBoulder, CO, United States
Full-time

Additional Information** **Job Number** 26047803 **Job Category** Rooms & Guest Services Operations **Location** Residence Inn by Marriott Boulder, 3030 Center Green Dr, Boulder, Colorado, Unite... Show more

 • Promoted

Manager- Information Systems Security (ISSM)

Microchip Technology Inc.Boulder, CO, United States
Permanent

Are you looking for a unique opportunity to be a part of something great? Want to join a 17,000-member team that works on the technology that powers the world around us? Looking for an atmosphere o... Show more

 • Promoted

Security Flex Officer - Aerospace

Allied UniversalBoulder, Colorado, United States
Full-time

Security Flex Officer - Aerospace.Monday - Friday, Saturday - Sunday.Afternoon, Evening, Morning, Overnight.Allied Universal, North America's leading security and facility services company, offers ... Show more

 • Promoted

Senior Director of Asset Management

CloudbreakenergyBoulder, CO, United States
Full-time

Formed by experienced renewable energy professionals in 2020, Cloudbreak is already one of the leading commercial and community solar developers in the United States.Our mission is to accelerate th... Show more

 • Promoted

Director Of People Experience Insights and Operational Effectiveness

GoogleBoulder, CO, United States
Full-time

Director Of People Experience Insights and Operational Effectiveness.The application window will be open until at least May 6, 2026.This opportunity will remain online based on business needs which... Show more

 • Promoted

Senior In Vivo Study Director

Inotiv, Inc.Boulder, CO, United States
Full-time

Boulder, Colorado, is seeking an experienced professional for a role in pharmacology research.The position involves managing studies, conducting biochemical screenings, and overseeing research proj... Show more

 • Promoted

Border Patrol Agent (BPA) Experienced - New Hire Sign-On and Retention Incentives

US Customs and Border ProtectionLyons, CO, US
Full-time

Border Patrol Agent (BPA) in the Federal Security and Public Safety Sector Experienced (GL-9 GS-11).You love protecting your community and doing your part to keep our nation safe.But maybe youre l... Show more

 • Promoted

Master at Arms

US NavyGolden, CO, US
Full-time

Security & Law Enforcement (Master-at-Arms).Master-at-Arms (MA) Sailors provide the Navy’s core security, antiterrorism, and law enforcement capability, protecting people, installations, ships, and... Show more

 • Promoted

ISSM: Security Leader for Government Systems

Microchip Technology IncBoulder, CO, United States
Full-time

A leading technology firm in Boulder, CO is seeking an Information System Security Manager (ISSM) to lead their Information Assurance team.The ISSM will ensure compliance with government standards ... Show more

 • Promoted

Director, Treasury

Viserion Grain, LLCBoulder, CO, United States
Full-time

The Director of Treasury will lead the company’s global treasury strategy.With a strong focus on building a modern treasury organization, this role is responsible for optimizing liquidity, managing... Show more

 • Promoted

Military Security Officer

U.S. NavyBoulder, CO, US
Full-time

Security & Law Enforcement (Master-at-Arms).Master-at-Arms (MA) Sailors provide the Navys core security, antiterrorism, and law enforcement capability, protecting people, installations, ships, and ... Show more

 • Promoted

Customs and Border Protection Officer (CBPO) - Experienced New Hire Sign-On and Retention Incentives

U.S. Customs and Border ProtectionLyons, CO, US
Full-time

Customs and Border Protection Officer (CBPO).Customs and Border Protection (CBP) offers those interested in a career in law enforcement an exceptional opportunity to work with an elite team of high... Show more

 • Promoted

Director, SMB Sales

Local HeroBoulder, CO, United States
Full-time

This range is provided by Local Hero.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Direct message the job poster from Local Hero.Local Hero is... Show more