Director, Information Technology & Security
AffirmRemote (USA)1mo ago
Job description
About the role
Affirm is embarking on an exciting journey to establish a new Industrial Loan Company (ILC) and is in search of a visionary leader to spearhead its information security and cybersecurity initiatives. This position demands a unique combination of strategic foresight and practical technical expertise to cultivate a secure environment that adheres to regulatory requirements and safeguards sensitive information. As a figure in this endeavor, you will play a crucial role in defining the security framework of the Bank from the ground up.
Key facts
What you'll do
- Develop and execute a information security strategy that aligns with FDIC regulations and Interagency Standards.
- Formulate and implement policies, standards, and procedures that govern cybersecurity, data protection, and incident management.
- Supervise the technical development of the Bank's infrastructure with a strong emphasis on cloud security and the integration of DevOps practices.
- Create and manage capabilities for threat monitoring and detection to proactively identify potential security incidents.
- Establish multi-layered security measures, including network segmentation, data encryption, and access control protocols.
- Lead the Bank's response to security incidents and liaise with regulatory authorities as necessary.
- Evaluate and manage information security risks related to third-party service providers and affiliates.
- Ensure adherence to data privacy laws such as the Gramm-Leach-Bliley Act (GLBA) and relevant state regulations.
- Play a key role in the formulation and testing of business continuity and disaster recovery strategies.
- Document and build the Bank's technology and information security frameworks for regulatory submissions.
- Serve as the primary advocate for cybersecurity and data protection within the Bank, promoting a culture of security awareness.
- Recruit, mentor, and lead a specialized security team dedicated to safeguarding the Bank's information assets.
Requirements
- At least 10 years of experience in information technology, security, and technology risk management, showcasing a proven ability to navigate between strategic planning and hands-on technical execution.
- Demonstrated experience in crafting and implementing information security programs that meet FDIC and FFIEC standards.
- Strong grasp of third-party risk management frameworks and cybersecurity expectations specific to the financial services sector.
- Experience in leading incident response efforts, conducting penetration tests, and managing security operations in both cloud and hybrid environments.
- Proficient in articulating complex technical ideas to executive leadership, Board members, and regulatory agencies.
- Strong leadership qualities, analytical thinking, and problem-solving capabilities with a pragmatic, risk-based approach.
- In-depth knowledge of cloud infrastructure (AWS/GCP), DevOps methodologies, and software-defined security measures.
- Proven track record of contributing to technology development phases while effectively managing relationships with executive stakeholders and regulators.
Nice to have
- Familiarity with advanced threat detection and response technologies.
- Experience in regulatory compliance within the banking or financial services sectors.
- Knowledge of emerging cybersecurity trends and technologies.
Skills & tools
- Comprehensive understanding of information security principles, frameworks, and regulatory obligations.
- Ability to think strategically while ensuring effective operational execution and control.
- Strong communication and influencing skills that bridge technical and business domains.
- A collaborative leadership style that fosters accountability, awareness, and a culture of continuous improvement.
Practical notes
- The base salary range for positions in the USA Pacific region (California, Washington, New York, New Jersey, Connecticut) is between $300,000 and $360,000 annually.
- For the USA Sapphire region (all other U.S. states), the salary range is between $267,000 and $327,000 per year.
- Please note that visa sponsorship is not available for this role.
- Affirm provides 100% subsidized medical coverage, including dental and vision, for employees and their dependents.
- Employees may qualify for equity rewards from Affirm Holdings, Inc.
- Flexible spending stipends are available for health, wellness, and technology expenses.
- Affirm operates as a remote-first organization, allowing employees the flexibility to work from anywhere in the U.S.