Affirm27 days ago

Product Security Engineer II

Salary not specified
MARKET
15,000median for this role
CISO · 13 jobs with disclosed pay
7,333half of the offers: 9,600–17,69433,750
The employer didn't disclose pay — compare with the market yourself.
Remote Canada

Responsibilities

  • 01Partner with product and engineering teams to identify application security risks and help frame them as clear business risks
  • 02Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist
  • 03Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows
  • 04Work in GitHub to review code changes, understand engineering context, participate in pull request discussions, track remediation work
  • 05Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, penetration tests, and other sources
  • 06Contribute to vulnerability management workflows including triage, validation, severity assessment, remediation guidance, tracking, and reporting
  • 07Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, paved paths, lightweight automation
  • 08Work with engineers to understand system designs, data flows, trust boundaries, authentication and authorization models, code paths, and potential abuse cases
  • 09Communicate security issues clearly to both technical and non-technical audiences
  • 10Build strong relationships across Affirm teams and influence security outcomes without relying on formal authority
  • 11Help connect AppSec work to customer trust, regulatory/compliance expectations, operational resilience, and business outcomes

Requirements

  • 010–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, security operations, or equivalent practical experience
  • 02Foundational programming ability in one or more languages such as Python, JavaScript/TypeScript, Kotlin, or similar
  • 03Comfort reading, navigating, and reasoning about code, even in unfamiliar codebases
  • 04Experience using Git and GitHub or similar version-control workflows
  • 05Some hands-on experience building, testing, breaking, or securing software
  • 06Ability to write clear, maintainable scripts or small programs to solve practical problems
  • 07Foundational understanding of common web, API, mobile, cloud, and application security risks
  • 08Interest in offensive security such as studying for security certifications, practicing web/API testing, learning exploit development fundamentals
  • 09Exposure to vulnerability management concepts including triage, severity assessment, remediation tracking, false-positive analysis
  • 10Ability to reason about risk and tradeoffs, not just identify issues
  • 11Strong product and engineering empathy
  • 12Clear written and verbal communication skills
  • 13Collaborative mindset and comfort working across product, engineering, compliance, risk, infrastructure, and security teams
  • 14Curiosity, humility, and a growth mindset
  • 15Secure-by-design judgment including the ability to spot patterns and recommend simple controls

What we offer

  • 01Base Pay Grade - L
  • 02Equity Grade - 5
  • 03Employees new to Affirm typically come in at the start of the pay range