Head of Product Security at Affirm (Remote)
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. Affirm, Inc. proudly includes Affirm, PayBright, and Returnly.
Affirm values security as being critical to the company’s continued success. Our mission is to cultivate a culture of security at Affirm, enabling the company to succeed in building honest financial products.
The Product Security team provides a strategic, business-focused approach to secure Affirm products by building security into design, build, testing, and maintenance. This team is responsible for improving the security of Affirm products and solutions, developing, overseeing and directing the adoption of product security and various other aspects of the overarching product security program: risk assessment, awareness/training, incident response, and strategic initiatives.
What you'll do
- Hire, retain, and manage talent to grow the security engineering team
- Formulate, execute and oversee plans and objectives to support the direction of software security engineering.
- Lead product security architecture, security testing, secure design review, and security engineering, and reporting.
- Integrate plans at the strategic and operational level of the supported organization and lead efforts to verify the security of our code, products, and infrastructure.
- Drive projects related to product security, threat modelling, software security automation, penetration testing/ bug bounty and the security development lifecycle.
- Maintain a collaborative working relationship with business unit leaders and engineering teams and work to champion security priorities and objectives across Affirm.
- Manage cyber security risks and threats tied to Affirms reputation, exposure and regulatory, technology and data compliance.
- Collaborate with Engineering teams to ensure the products are designed, implemented and operated to provide continuity in the face of an attack
- Manage internal and third-party penetration tests.
- Work as a complement to platform security and security operations to define and maintain a cohesive monitoring and response program for Affirm services.
- Provide continuous input to leaders within security and Product teams under technology.
- Support compliance programs - PCI, NIST CSF, SOC 2 via the development, implementation and governance of common controls for products and infrastructure.
- Focus on using security metrics and risk management to guide security programs and apply resources efficiently.
What we look for
- Several years of experience in a leadership role, particularly leading and developing managers, and driving successful cross-functional initiatives and programs.
- Consistent track record of raising the bar of the product development lifecycle to ensure that products are secure by design.
- Experience in creating frictionless paths for engineering teams to securely build and deploy applications.
- Experience tuning and growing bug bounty programs.
- Proven ability to champion the Security Engineering org internally and build a robust security engineering brand externally.
- Excellent interpersonal, organizational, leadership, communication and time-management skills.
- Ability to understand the big picture by aligning activities to business objectives and partnering with other other areas of the business to align on strategies and enterprise priorities.
At Affirm, People Come First is one of our core values, and that’s why diversity and inclusion are vital to our priorities as an equal opportunity employer. You can read about our D&I program here and our progress thus far in our 2020 DEI Report.
We also believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.