Compliance Manager Jobs at Affirm with Visa Sponsorship
Affirm hires Compliance Managers to build and maintain regulatory frameworks across its financial products, including BNPL and credit services. The company has a consistent track record of supporting work visa sponsorship for this function, making it a realistic target for international candidates with compliance backgrounds in financial services.
See All Compliance Manager at Affirm JobsOverview
Showing 5 of 54+ Compliance Manager Jobs at Affirm jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 54+ Compliance Manager Jobs at Affirm
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Compliance Manager Jobs at Affirm.
Get Access To All Jobs
INTRODUCTION
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. We’re hiring a Senior Manager to lead Security Governance and the Security Third-Party Risk Management (TPRM) function. This role owns program strategy, operational maturity, and stakeholder alignment for security governance, vendor risk, and third-party integration risk. The manager will drive policy and control frameworks, remediate audit findings, deliver measurable program KPIs, and grow a high-performing team that executes vendor diligence, monitoring, and governance at scale. Our Security Governance and TPRM programs must move from tactical firefighting to predictable, measurable operations that scale with the business. This leader will set the security risk posture, tighten governance and fourth-party oversight, improve tooling and automation adoption, and ensure timely, actionable escalations so senior leadership can make the right business decisions.
ROLE AND RESPONSIBILITIES
Program strategy & governance
- Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations).
- Lead program maturity planning, roadmaps, and cross-functional governance forums (e.g., security steering committee, risk council).
- Define and enforce security risk appetite and decision criteria for third-party relationships and integrations.
Third-party risk management
- Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding.
- Ensure robust fourth-party oversight, including subprocessors, and manage remediation/QA cycles driven by Internal Audit and regulators.
- Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria.
Operational excellence & tooling
- Own program KPIs, dashboards, and reporting (Jira STPRM Ops, AuditBoard, Sigma/BI, MetricStream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity.
- Partner with Automation/TPRM Ops to operationalize threat-modeling outputs, integration inventories, pre-integration gates, and CI/CD checks; prioritize automations that reduce manual work and surface strategic escalations.
- Implement and maintain QA processes (quarterly QA), runbooks, SOPs for ticket ownership, and evidence standards.
People & stakeholder leadership
- Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.
- Act as the primary security contact for Legal, Procurement, Privacy, Product, and Engineering on vendor risk and governance matters.
- Represent Security in executive forums, audit meetings, and regulatory engagements; own remediation commitments and timelines.
Audit, compliance & risk reporting
- Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress.
- Produce regular program health reporting for senior leadership and Board-level stakeholders.
Success metrics (examples)
- Vendors reviewed per month and % critical vendors reviewed on schedule
- Average review turnaround time and backlog age distribution
- % tickets with clear owner and SLA met
- Time to remediate Internal Audit findings and completion rate
- Implementation count of automated checks/runbooks and pre-integration gates
- Team engagement / retention and time-to-productivity for new hires
BASIC QUALIFICATIONS
- 7+ years in information security, risk management, or GRC roles, with a minimum of 3 years managing teams (or equivalent leadership experience).
- Demonstrated ownership of a TPRM program or security governance program in a regulated or high-growth technology environment (fintech preferred).
- Strong knowledge of security frameworks (NIST, ISO), compliance standards (SOC2, PCI), and vendor risk processes (IRQ/DDQ/SME assessments).
- Hands-on familiarity with TPRM/GRC tooling and observability: AuditBoard (or equivalent), Jira, BI tools (Sigma/Tableau/Looker), and experience with integrations/APIs.
- Excellent stakeholder management across legal, procurement, engineering, product, and executive leadership.
- Proven experience translating audit findings into operational remediation plans and measurable outcomes.
- Strong communication skills — able to present risk to technical and non-technical audiences and to influence decisions.
- Certifications such as CISSP, CISM, CRISC, or similar.
- Practical experience with threat-modeling approaches and third-party integration security (API, SSO/OAuth/SAML, TLS).
- Experience scaling automation for GRC/TPRM programs and integrating security checks into CI/CD pipelines.
- Prior experience in fintech or highly regulated industries.
COMPENSATION
- Pay Grade - Q
- Equity Grade - 10
- Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
- Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
- USA base pay range (CA, WA, NY, NJ, CT) per year: $250,000 - $300,000
- USA base pay range (all other U.S. states) per year: $223,000 - $273,000
LOCATION
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
BENEFITS
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

INTRODUCTION
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. We’re hiring a Senior Manager to lead Security Governance and the Security Third-Party Risk Management (TPRM) function. This role owns program strategy, operational maturity, and stakeholder alignment for security governance, vendor risk, and third-party integration risk. The manager will drive policy and control frameworks, remediate audit findings, deliver measurable program KPIs, and grow a high-performing team that executes vendor diligence, monitoring, and governance at scale. Our Security Governance and TPRM programs must move from tactical firefighting to predictable, measurable operations that scale with the business. This leader will set the security risk posture, tighten governance and fourth-party oversight, improve tooling and automation adoption, and ensure timely, actionable escalations so senior leadership can make the right business decisions.
ROLE AND RESPONSIBILITIES
Program strategy & governance
- Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations).
- Lead program maturity planning, roadmaps, and cross-functional governance forums (e.g., security steering committee, risk council).
- Define and enforce security risk appetite and decision criteria for third-party relationships and integrations.
Third-party risk management
- Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding.
- Ensure robust fourth-party oversight, including subprocessors, and manage remediation/QA cycles driven by Internal Audit and regulators.
- Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria.
Operational excellence & tooling
- Own program KPIs, dashboards, and reporting (Jira STPRM Ops, AuditBoard, Sigma/BI, MetricStream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity.
- Partner with Automation/TPRM Ops to operationalize threat-modeling outputs, integration inventories, pre-integration gates, and CI/CD checks; prioritize automations that reduce manual work and surface strategic escalations.
- Implement and maintain QA processes (quarterly QA), runbooks, SOPs for ticket ownership, and evidence standards.
People & stakeholder leadership
- Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.
- Act as the primary security contact for Legal, Procurement, Privacy, Product, and Engineering on vendor risk and governance matters.
- Represent Security in executive forums, audit meetings, and regulatory engagements; own remediation commitments and timelines.
Audit, compliance & risk reporting
- Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress.
- Produce regular program health reporting for senior leadership and Board-level stakeholders.
Success metrics (examples)
- Vendors reviewed per month and % critical vendors reviewed on schedule
- Average review turnaround time and backlog age distribution
- % tickets with clear owner and SLA met
- Time to remediate Internal Audit findings and completion rate
- Implementation count of automated checks/runbooks and pre-integration gates
- Team engagement / retention and time-to-productivity for new hires
BASIC QUALIFICATIONS
- 7+ years in information security, risk management, or GRC roles, with a minimum of 3 years managing teams (or equivalent leadership experience).
- Demonstrated ownership of a TPRM program or security governance program in a regulated or high-growth technology environment (fintech preferred).
- Strong knowledge of security frameworks (NIST, ISO), compliance standards (SOC2, PCI), and vendor risk processes (IRQ/DDQ/SME assessments).
- Hands-on familiarity with TPRM/GRC tooling and observability: AuditBoard (or equivalent), Jira, BI tools (Sigma/Tableau/Looker), and experience with integrations/APIs.
- Excellent stakeholder management across legal, procurement, engineering, product, and executive leadership.
- Proven experience translating audit findings into operational remediation plans and measurable outcomes.
- Strong communication skills — able to present risk to technical and non-technical audiences and to influence decisions.
- Certifications such as CISSP, CISM, CRISC, or similar.
- Practical experience with threat-modeling approaches and third-party integration security (API, SSO/OAuth/SAML, TLS).
- Experience scaling automation for GRC/TPRM programs and integrating security checks into CI/CD pipelines.
- Prior experience in fintech or highly regulated industries.
COMPENSATION
- Pay Grade - Q
- Equity Grade - 10
- Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
- Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
- USA base pay range (CA, WA, NY, NJ, CT) per year: $250,000 - $300,000
- USA base pay range (all other U.S. states) per year: $223,000 - $273,000
LOCATION
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
BENEFITS
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
See all 54+ Compliance Manager at Affirm jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Compliance Manager at Affirm roles.
Get Access To All JobsTips for Finding Compliance Manager Jobs at Affirm Jobs
Frame your credentials around U.S. financial regulations
Affirm operates under federal and state lending laws, so translate your compliance experience into U.S.-specific frameworks like the CFPB, TILA, and ECOA before applying. Hiring managers need to see direct regulatory relevance, not just general compliance exposure.
Target roles aligned with your current visa status
If you're on F-1 OPT, prioritize Compliance Manager postings that mention BNPL or consumer lending oversight. Affirm files for TN and H-1B sponsorship for this function, so confirm the specific role supports your visa category before investing time in the application.
Use Migrate Mate to filter Affirm compliance openings
Affirm posts Compliance Manager roles across multiple teams at varying seniority levels. Use Migrate Mate to filter specifically for Affirm compliance positions that include visa sponsorship, so you're not manually sorting through listings that won't move your immigration status forward.
Clarify H-1B cap timing before accepting an offer
If you need an initial H-1B, the annual cap registration window opens in March for an October 1 start. Confirm with Affirm's recruiting team early whether your start date can align with that timeline, or whether a cap-exempt pathway applies to your situation.
Document your supervisory or program-ownership experience
Affirm's Compliance Manager roles typically involve owning compliance programs, not just executing them. Before interviews, prepare concrete examples of policies you've written, audits you've led, or cross-functional teams you've managed. This evidence directly supports the specialty occupation standard USCIS evaluates.
Understand how PERM affects your long-term sponsorship path
If Affirm sponsors you for EB-2 or EB-3, the PERM labor certification process requires them to advertise the role to the U.S. labor market first. That process typically takes six to twelve months before DOL certifies the application, so factor that into your timeline planning.
Compliance Manager at Affirm jobs are hiring across the US. Find yours.
Find Compliance Manager at Affirm JobsFrequently Asked Questions
Does Affirm sponsor H-1B visas for Compliance Managers?
Yes, Affirm sponsors H-1B visas for Compliance Manager roles. Compliance functions at Affirm qualify as specialty occupations under USCIS standards, given the degree requirements and regulatory complexity involved. If you're already on H-1B with another employer, Affirm can file an H-1B transfer, which lets you start work as soon as USCIS receives the petition.
How do I apply for Compliance Manager jobs at Affirm?
You can browse open Compliance Manager positions directly on Affirm's careers page or use Migrate Mate to filter for Affirm roles that include visa sponsorship. When applying, tailor your resume to highlight U.S. regulatory experience relevant to consumer lending and fintech compliance. Affirm's hiring process for this function typically includes a recruiter screen, technical compliance interviews, and a final round with senior leadership.
Which visa types does Affirm commonly use to sponsor Compliance Managers?
Affirm sponsors Compliance Managers on H-1B, TN (for Canadian and Mexican nationals in qualifying professional categories), F-1 OPT and CPT for candidates earlier in their careers, and employment-based Green Card pathways including EB-2 and EB-3 for longer-term sponsorship. The right visa depends on your nationality, education level, and where you are in your career.
What qualifications does Affirm expect for a sponsored Compliance Manager?
Affirm typically looks for a bachelor's degree or higher in law, finance, business, or a related field, combined with direct experience in financial services compliance. Familiarity with consumer lending regulations, CFPB oversight, or fintech-specific compliance programs strengthens your candidacy. Candidates who have managed compliance programs end-to-end rather than supporting them from an analyst role are better positioned for sponsored Compliance Manager offers.
How long does the visa sponsorship process take if Affirm extends an offer?
Timeline depends heavily on visa type. An H-1B transfer for candidates already on H-1B can move quickly once USCIS receives the petition. A new H-1B cap subject filing requires waiting for the March lottery and an October 1 start. TN status can be obtained at a port of entry on your start date. EB-2 and EB-3 Green Card sponsorship through PERM typically runs one to two years before priority date considerations.
See which Compliance Manager at Affirm employers are hiring and sponsoring visas right now.
Search Compliance Manager at Affirm Jobs