Director, Affirm Bank Information Security

Affirm
Remote USPosted 11 February 2026

Tech Stack

Job Description

<div class="content-intro"><p>Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.</p></div><p>The Chief Information Security Officer (CISO) will serve as a key member of the Bank’s Executive Management Team and will be responsible for establishing and leading Bank’s information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), the CISO will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank’s risk appetite, and protects customer and institutional data.</p> <p>The CISO will lead the development of information security governance, technical controls, and third-party risk oversight, ensuring a strong and scalable security posture from inception through growth. This leader will collaborate closely with technology, risk, and operations teams to ensure security is integrated into every aspect of the Bank’s systems and operations.</p> <p><strong><strong>What You’ll Do</strong></strong></p> <p>1. Information Security Program Development</p> <ul> <li>Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.</li> <li>Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.</li> <li>Ensure alignment with the Bank’s overall risk management and governance frameworks.</li> <li>Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.</li> </ul> <p>2. Cybersecurity and Threat Management</p> <ul> <li>Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.</li> <li>Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).</li> <li>Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.</li> <li>Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.<br> </li> </ul> <p>3. Third-Party and Affiliate Risk Oversight</p> <ul> <li>Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.</li> <li>Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.</li> <li>Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.<br> </li> </ul> <p>4. Data Governance and Privacy Protection</p> <ul> <li>Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).</li> <li>Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.</li> <li>Partner with business and technology teams to integrate privacy-by-design principles into new products and services.<br> </li> </ul> <p>5. Business Continuity and Resilience</p> <ul> <li>Lead development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) p ... (truncated, view full listing at source)
Apply Now

Direct link to company career page

Share this job