Product Security Engineer IINew$165K–$225K

The opportunity

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

What you'll do

  • Partner with product and engineering teams to identify application security: risks and help frame them as clear business risks, launch options, and recommended next steps.

  • Read application code, configuration, pull requests, logs, and documentation: to understand how systems work and where security risks may exist.

  • Contribute small code changes, scripts, detections, tests, secure defaults,: or automation that improve AppSec workflows and reduce recurring issues.

  • Work in GitHub to review code changes, understand engineering context,: participate in pull request discussions, track remediation work, and collaborate with engineers.

  • Help evaluate vulnerabilities from internal testing, bug bounty reports,: security tooling, penetration tests, and other sources; partner with teams to prioritize and remediate issues based on real-world risk.

  • Contribute to vulnerability management workflows, including triage,: validation, severity assessment, remediation guidance, tracking, and reporting.

What they're looking for

  • Translate recurring security findings into repeatable mechanisms such as: secure coding guidance, checklists, paved paths, lightweight automation, detection logic, reusable review patterns, or developer-facing documentation.
  • Work with engineers to understand system designs, data flows, trust: boundaries, authentication and authorization models, code paths, and potential abuse cases.
  • Communicate security issues clearly to both technical and non-technical: audiences, including the risk, tradeoffs, recommended mitigations, and residual risk.
  • Build strong relationships across Affirm teams and influence security: outcomes without relying on formal authority.