Product Security Engineer II
Affirm- Total compensation
- $133k–$183k Published total compensation range
- Location
- Remote - Canada (AB, BC, MB, NB, NL, NS, ON, PE, SK) Remote eligibility
- Employment
- Full-time Mid-level
About the job
About Affirm
Affirm is a fintech company that provides transparent, predictable payment solutions over time, with no hidden fees. The company uses advanced technology and analytics to serve a broad population.
About the Team
The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance obligations, and reduce business risk. The team partners with product, engineering, infrastructure, risk, and compliance teams to identify security risks early and recommend mitigations.
Role Overview
We are looking for an early-career Application Security Engineer who is curious, collaborative, and comfortable working with code. You will help assess application risks, support vulnerability management, partner with engineering teams on secure design decisions, and contribute lightweight tooling and automation to help AppSec scale.
What You'll Do
- Partner with product and engineering teams to identify application security risks and frame them as business risks with recommended next steps.
- Read application code, configuration, pull requests, logs, and documentation to understand systems and identify security risks.
- Contribute small code changes, scripts, detections, tests, secure defaults, or automation to improve AppSec workflows.
- Work in GitHub to review code changes, participate in pull request discussions, and track remediation work.
- Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests; partner to prioritize and remediate based on risk.
- Contribute to vulnerability management workflows including triage, validation, severity assessment, and reporting.
- Translate recurring findings into repeatable mechanisms like secure coding guidance, checklists, paved paths, and automation.
- Communicate security issues clearly to technical and non-technical audiences.
What We Look For
- 4+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or equivalent.
- Foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar.
- Comfort reading and reasoning about code in unfamiliar codebases.
- Experience with Git and GitHub workflows.
- Hands-on experience building, testing, breaking, or securing software.
- Ability to write clear, maintainable scripts or small programs.
- Foundational understanding of web, API, mobile, cloud, and application security risks (e.g., OWASP Top 10).
- Interest in offensive security, including tools like Burp Suite and CTF environments.
- Exposure to vulnerability management concepts.
- Strong risk reasoning, product empathy, and communication skills.
Compensation & Benefits
Base pay range: CAD $133,000 - $183,000 per year. Total compensation may include monthly stipends for health, wellness, and tech spending, and benefits including 100% subsidized medical, dental, and vision coverage for employees and dependents. Employees may be eligible for equity rewards. Benefits also include flexible time off, generous holiday calendars, and an employee stock purchase plan (ESPP).
Location
Remote Canada, open only to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.