SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Affirm is reinventing credit to make it more honest and friendly, giving consumers flexibility to buy now and pay later without hidden fees or compounding interest. The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance obligations, and reduce business risk.
As a Product Security Engineer II, you will be an early-career application security professional who partners closely with product, engineering, infrastructure, risk, and compliance teams to identify security risks early, recommend pragmatic mitigations, and help teams find safe paths to launch.
Key responsibilities include:
- Partner with product and engineering teams to identify application security risks and frame them as clear business risks with launch options and recommended next steps
- Read application code, configuration, pull requests, logs, and documentation to understand systems and identify security risks
- Contribute code changes, scripts, detections, tests, secure defaults, and automation that improve AppSec workflows and reduce recurring issues
- Work in GitHub to review code changes, understand engineering context, participate in pull request discussions, and collaborate with engineers
- Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests; prioritize and remediate based on real-world risk
- Contribute to vulnerability management workflows including triage, validation, severity assessment, remediation guidance, and reporting
- Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, automation, and developer-facing documentation
- Work with engineers to understand system designs, data flows, trust boundaries, authentication/authorization models, and potential abuse cases
- Communicate security issues clearly to both technical and non-technical audiences
- Build strong relationships across Affirm teams and influence security outcomes without formal authority
- Connect AppSec work to customer trust, regulatory expectations, operational resilience, and business outcomes
- Continue developing hands-on offensive, defensive, and software engineering skills through practical work, labs, tooling, and research
You should have 0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or equivalent practical experience. Required skills include foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar; comfort reading and reasoning about code; experience with Git and GitHub workflows; hands-on experience building, testing, breaking, or securing software; ability to write clear, maintainable scripts and small programs; foundational understanding of common web, API, mobile, cloud, and application security risks (OWASP Top 10, authentication/authorization flaws, injection, insecure design, secrets exposure, dependency risks); and interest in offensive security such as security certifications, web/API testing, exploit development, or capture-the-flag environments.