Jobs / United States / Affirm INC
Director, Information Technology & Security
Affirm INC · 🇺🇸 Remote US · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 59 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 40 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Affirm INC paid sponsored hires in similar roles1 certified filing for “Senior Product Security Engineer” (Information Security Analysts) in CA: $190k–$190k, median $190k. Most were filed at wage level III (100%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Affirm INC
The US Department of Labor certified 59 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 40 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Affirm INC →
About the role
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. Remote US The Director, Information Technology & Security will serve as a key member of the Bank's Management Team, serving as the Chief Information Security Officer, and will be responsible for establishing and leading the Bank's information security and cybersecurity programs. As the Bank prepares to launch as a de novo Industrial Loan Company (ILC), this leader will design and implement an enterprise-wide security framework that meets FDIC and state regulatory expectations, supports the Bank's risk appetite, and protects customer and institutional data. This is a blended leadership role requiring both high-level strategic influence and deep technical execution. You will lead the development of information security governance, technical controls, and oversight of infrastructure and engineering, ensuring a strong and scalable security posture from inception. This leader must be a practitioner at heart—willing to "roll up their sleeves" to lead the technical build phase, collaborate closely with engineering on architecture, and ensure security is integrated into every aspect of the Bank's systems and operations. What You’ll Do • Oversee infrastructure design and IT Engineering • Information Security Program Development • Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards. • Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response. • Ensure alignment with the Bank’s overall risk management and governance frameworks. • Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts. • Lead the technical build phase of the Bank's infrastructure, providing direct oversight and hands-on guidance for cloud security and DevOps integration. • Partner deeply with Engineering to define and implement secure technical architectures, including network segmentation, encryption standards, and identity governance. • Cybersecurity and Threat Management • Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks. • Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management). • Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required. • Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats. • Third-Party and Affiliate Risk Oversight • Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance. • Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services. • Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated. • Manage the technical lifecycle of security-critical third-party service providers, ensuring rigorous operational oversight of vendors handling sensitive financial data. • Data Governance and Privacy Protection • Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws). • Implement processes to safeguard customer information