
Staff Product Security Engineer
Posted Aug 13

Posted Aug 13
This is a fully remote position, open to applicants in Canada.
• Design, develop, and manage essential CIAM backend services that facilitate customer registration, authentication, authorization, account lifecycle management, and profile management for both B2C and B2B platforms.
• Implement and enhance identity standards including OAuth 2.0, OIDC, SAML, and SCIM.
• Create backend APIs and services using Python and Kotlin for web, mobile, and partner applications.
• Connect CIAM platforms with user data repositories, messaging systems, fraud detection signals, and downstream customer platforms.
• Take ownership of secure authentication and account flows, which include MFA, step-up authentication, device binding, consent, and adaptive authentication.
• Automate CIAM infrastructure and deployments utilizing Infrastructure as Code and CI/CD pipelines.
• Monitor, troubleshoot, and optimize CIAM services to enhance performance, resilience, and abuse detection.
• Deliver significant features and system components through well-defined technical and execution plans.
• Collaborate effectively with partner engineering, product, frontend, mobile, and security teams.
• A minimum of 7 years of experience in designing, developing, and launching scalable backend systems using Python or Kotlin.
• At least 5 years of professional experience in backend software engineering.
• Extensive experience in designing and implementing CIAM systems.
• In-depth hands-on knowledge of OAuth 2.0, OIDC, SAML, and SCIM.
• Strong production experience with Python or a comparable backend programming language.
• Proficient in designing APIs, automation frameworks, and distributed systems.
• Practical experience in building and maintaining CI/CD pipelines.
• Familiarity with GitHub-based development workflows and Buildkite or similar build systems.
• Experience in cloud-native development, preferably with AWS.
• Experience in extending and integrating CIAM platforms like Okta, Auth0, Ping Identity, ForgeRock, or Azure AD B2C.
• Understanding of API design principles, data modeling, latency, error handling, and observability.
• Experience with Infrastructure as Code and automation tools such as Terraform.
• Knowledge of security fundamentals including access control, token handling, encryption, MFA, and privacy by design.
• Excellent verbal and written communication skills.
• Familiarity with Cursor and other AI-augmented development environments.
• Health care coverage - Affirm pays all premiums for all levels of coverage for you and your dependents.
• Flexible Spending Wallets - generous stipends available for Technology, Food, various Lifestyle needs, and family forming expenses.
• Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge.
• ESPP - An employee stock purchase plan that allows you to acquire shares of Affirm at a discounted rate.
• Equity rewards may be included in the overall compensation package.
• Monthly stipends for health, wellness, and technology expenditures.
• Dental and vision coverage for you and your dependents.
• Reasonable accommodations will be provided during the hiring process.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.