
Product Security Engineer II
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Canada.
• Collaborate with product and engineering teams to pinpoint application security risks and articulate them as clear business risks, launch options, and suggested next steps.
• Analyze application code, configurations, pull requests, logs, and documentation to gain insights into system functionality and identify potential security vulnerabilities.
• Make minor code modifications, develop scripts, create detection mechanisms, conduct tests, establish secure defaults, or automate processes to enhance AppSec workflows and minimize recurring problems.
• Utilize GitHub to review code alterations, comprehend engineering contexts, engage in pull request discussions, monitor remediation efforts, and work alongside engineers.
• Assess vulnerabilities identified through internal testing, bug bounty submissions, security tools, penetration tests, and other sources; collaborate with teams to prioritize and address issues based on real-world risks.
• Participate in vulnerability management processes, including triage, validation, severity assessment, remediation advice, tracking, and reporting.
• Convert recurring security findings into repeatable mechanisms such as secure coding guidelines, checklists, paved paths, lightweight automation, detection logic, reusable review patterns, or developer-facing documentation.
• Collaborate with engineers to comprehend system architectures, data flows, trust boundaries, authentication and authorization frameworks, code pathways, and potential misuse scenarios.
• Clearly communicate security concerns to both technical and non-technical stakeholders, covering aspects such as risk, trade-offs, recommended mitigations, and residual risks.
• Foster strong relationships across Affirm teams and influence security outcomes without relying on formal authority.
• Link AppSec initiatives to customer trust, regulatory compliance, operational resilience, and business results.
• Continue to enhance practical offensive, defensive, and software engineering skills through hands-on work, labs, tooling, research, certifications, or contributions to internal security initiatives.
• 0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, security operations, or equivalent hands-on experience.
• Basic programming skills in one or more languages such as Python, JavaScript/TypeScript, Kotlin, or similar.
• Proficient in reading, navigating, and reasoning about code, even within unfamiliar codebases.
• Experience with Git and GitHub or similar version-control workflows, including branches, commits, pull requests, code review, issues, or project tracking.
• Some practical experience in building, testing, breaking, or securing software, which could include professional experience, internships, security labs, CTFs, bug bounty work, open-source contributions, personal projects, automation scripts, internal tools, or coursework.
• Capability to write clear, maintainable scripts or small programs to address practical challenges, automate manual tasks, analyze data, validate findings, or enhance security processes.
• Fundamental understanding of common web, API, mobile, cloud, and application security threats, including OWASP Top 10 issues, authentication and authorization flaws, injection vulnerabilities, insecure design, secrets exposure, dependency risks, and data protection concerns.
• Interest in offensive security, such as pursuing or completing security certifications, practicing web/API testing, learning exploit development basics, using tools like Burp Suite, or engaging in labs and capture-the-flag environments.
• Familiarity with vulnerability management concepts, including triage, severity assessment, remediation tracking, false-positive analysis, compensating controls, and risk-based prioritization.
• Ability to evaluate risk and trade-offs, articulating potential issues, likelihood, impact, and options for risk mitigation.
• Strong empathy for product and engineering teams, seeking to understand launch objectives, technical limitations, user impact, and business priorities before recommending a course of action.
• Excellent written and verbal communication skills, capable of presenting security findings in practical, actionable language.
• A collaborative approach and ease of working with product, engineering, compliance, risk, infrastructure, and security teams.
• Curiosity, humility, and a growth mindset, actively seeking feedback, asking insightful questions, and continuing to deepen technical expertise.
• Secure-by-design judgment, capable of identifying patterns, suggesting simple controls, and balancing launch speed with meaningful risk reduction.
• Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents.
• Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses.
• Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge.
• ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.