368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$300k – $360k per year
Location
Remote (United States)
Seniority
Architect · 10+ years exp
Overview
Company
Impact
Profile match
Affirm is a U.S. fintech company founded in 2012 and headquartered in San Francisco. It offers buy now, pay later and installment payment products that let consumers split purchases into transparent, fixed payments. The company also provides merchant tools and a consumer app to support checkout financing and payment management.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

Remote US

The Director, Information Technology & Security will serve as a key member of the Bank's Management Team, serving as the Chief Information Security Officer, and will be responsible for establishing and leading the Bank's information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), this leader will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank's risk appetite, and protects customer and institutional data.

This is a blended leadership role requiring both high-level strategic influence and deep technical execution. You will lead the development of information security governance, technical controls, and oversight of infrastructure and engineering, ensuring a strong and scalable security posture from inception. This leader must be a practitioner at heart-willing to "roll up their sleeves" to lead the technical build phase, collaborate closely with engineering on architecture, and ensure security is integrated into every aspect of the Bank's systems and operations.

What You’ll Do

  • Oversee infrastructure design and IT Engineering 
  • Information Security Program Development
  • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
  • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
  • Ensure alignment with the Bank’s overall risk management and governance frameworks.
  • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
  • Lead the technical build phase of the Bank's infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration.
  • Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance.
  • Cybersecurity and Threat Management
  • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
  • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
  • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
  • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
  • Third-Party and Affiliate Risk Oversight
  • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
  • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
  • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
  • Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data.
  • Data Governance and Privacy Protection
  • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
  • Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
  • Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
  • Business Continuity and Resilience
  • Assist Risk Officer in development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
  • Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
  • Support resilience planning for key systems, vendors, and communication protocols.
  • De Novo and Pre-Opening Readiness
  • Build and document the Bank’s technology and information security program as part of the de novo application process.
  • Establish security architecture, monitoring tools, and vendor relationships prior to launch.
  • Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
  • Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
  • Leadership and Culture
  • Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
  • Provide training and guidance across the organization to enhance information security awareness.
  • Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
  • Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.

What We Look For

  • Minimum of 10 years of experience in information technology, and security and technology risk management, with a proven track record of moving between strategic planning and hands-on technical execution.
  • Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
  • Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
  • Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
  • Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
  • Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.
  • Deep expertise in cloud-native infrastructure (AWS/GCP), DevOps practices, and software-defined security controls.
  • Demonstrated ability to "roll up sleeves" and contribute directly to the technology build while simultaneously managing executive stakeholders and regulators.

Core Competencies

  • Expert knowledge of information security principles, frameworks, and regulatory requirements.
  • Strategic thinker with strong operational execution and control discipline.
  • Effective communicator capable of influencing across technical and business functions.
  • Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.

Affirm Values

At Affirm, we live by our values: People Come First, No Fine Print, It’s On Us, Simplify, and Push the Envelope. As CCO, you will embody these principles while building the foundation of Affirm Bank as a trusted, transparent, and innovative financial institution.

Compensation & Benefits

Base Pay Grade  - T

Equity Grade   - 14

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. 

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $300,000 - $360,000

USA Sapphire base pay range (all other U.S. states) per year: $267,000 - $327,000

Please note that visa sponsorship is not available for this position.

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include: 

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents 
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking "Submit Application," you acknowledge that you have read Affirm's  Global Candidate Privacy Notice  and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
up to $48k per year (net) • Remote/Hybrid • Moscow
Node JS
Python
TypeScript
JavaScript
Node JS
Nest.JS
Python
Django
FastAPI
Databases
Apache Kafka
pgvector
Pinecone
PostgreSQL
Qdrant
RabbitMQ
Redis
AI/ML
Chain-of-Thought
Claude
Claude Code
Copilot
Cursor
LangChain
LlamaIndex
LLM
Prompt Engineering
RAG
Anthropic
Function Calling
OpenAI
Structured Outputs
Frontend
GraphQL
Next.js
React.js
Redux
Redux Toolkit
Zustand
Mobile
State Management
DevOps
AWS
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Kubernetes
Prometheus
Yandex Cloud
GitHub
GitLab
Apply
$24k – $64k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chennai
Python
Scala
SQL
TypeScript
JavaScript
Java
Python
pySpark
Java
Spring Boot
Databases
Apache Kafka
Databricks
AI/ML
AI Agents
Copilot
Google ADK
LLM
NLP
Prompt Engineering
Spark
Devin
Model Context Protocol
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
Kubernetes
OpenShift
GitHub
Analytics
ETL/ELT
Apply
Data Engineer 1 day ago
In office • Full-Time • Singapore
Node JS
Python
SQL
JavaScript
Python
Beautiful Soup
Databases
Apache Kafka
MySQL
PostgreSQL
RabbitMQ
SQLite
AI/ML
Hadoop
Spark
DevOps
AWS
AWS Lambda
Azure
CI/CD
GCP
Amazon ECS
Amazon EventBridge
Amazon S3
Analytics
ETL/ELT
QA
Selenium
Apply
$170k – $318k per year (Estimated) • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
JavaScript
Python
TypeScript
Python
pySpark
AI/ML
Prompt Engineering
Spark
DevOps
AWS
Azure
CI/CD
GCP
Git
Jenkins
GitHub
GitLab
Analytics
ETL/ELT
Apply
In office • Full-Time • 3+ years exp • Indonesia
DevOps
AWS
Azure
GCP
IAM
Apply
$117k – $167k per year • Equity • Remote • 2+ years exp
Python
SQL
Apply
$145k – $205k per year • Equity • Remote • 2+ years exp
Python
SQL
Apply
$192k – $257k per year • Equity • Remote • Internship • 8+ years exp
Kotlin
Python
Databases
MySQL
AI/ML
Spark
DevOps
AWS
Kubernetes
Apply
$104k – $182k per year (Estimated) • Equity • Remote • Internship • 8+ years exp
Kotlin
Python
Databases
MySQL
AI/ML
Spark
DevOps
AWS
Kubernetes
Apply
$86k – $179k per year (Estimated) • Equity • Remote • Internship • 8+ years exp
Kotlin
Python
Databases
MySQL
AI/ML
Spark
DevOps
AWS
Kubernetes
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.