SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Affirm is reinventing credit to make it more honest and friendly, giving consumers flexibility to buy now and pay later without hidden fees or compounding interest. The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance obligations, and reduce business risk.
You will be an early-career Application Security Engineer who partners closely with product, engineering, infrastructure, risk, and compliance teams to identify security risks early, recommend pragmatic mitigations, and help teams find safe paths to launch.
Key responsibilities include:
- Partner with product and engineering teams to identify application security risks and frame them as clear business risks with launch options and recommended next steps
- Read application code, configuration, pull requests, logs, and documentation to understand systems and identify security risks
- Contribute code changes, scripts, detections, tests, secure defaults, and automation that improve AppSec workflows
- Work in GitHub to review code changes, participate in pull request discussions, and collaborate with engineers
- Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests; prioritize and remediate based on real-world risk
- Contribute to vulnerability management workflows including triage, validation, severity assessment, remediation guidance, and reporting
- Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, automation, and developer-facing documentation
- Work with engineers to understand system designs, data flows, trust boundaries, authentication/authorization models, and potential abuse cases
- Communicate security issues clearly to technical and non-technical audiences
- Build strong relationships across Affirm teams and influence security outcomes without formal authority
- Connect AppSec work to customer trust, regulatory expectations, operational resilience, and business outcomes
- Continue developing hands-on offensive, defensive, and software engineering skills
You should have 0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or equivalent practical experience. You need foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar languages, comfort reading and reasoning about code in unfamiliar codebases, and experience with Git/GitHub workflows. Hands-on experience building, testing, breaking, or securing software through professional work, internships, security labs, CTFs, bug bounty work, open-source contributions, or personal projects is important. You should be able to write clear, maintainable scripts or small programs to solve practical problems and automate workflows. Foundational understanding of common web, API, mobile, cloud, and application security risks (OWASP Top 10, authentication/authorization flaws, injection, insecure design, secrets exposure, dependency risks, data protection) is expected. Interest in offensive security through certifications, web/API testing, exploit development, Burp Suite, or capture-the-flag environments is valued.