Product Security Engineer II
RemoteSummary
Affirm seeks an early-career Application Security Engineer to partner with product and engineering teams identifying application security risks, reviewing code for vulnerabilities, and building lightweight tooling and automation to scale AppSec workflows. The role involves assessing vulnerabilities from multiple sources, contributing to vulnerability management workflows, translating security findings into repeatable mechanisms like secure coding guidance and detection logic, and communicating security issues to technical and non-technical audiences. The ideal candidate has 0–2+ years of hands-on security or software engineering experience, foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar languages, comfort reading and reasoning about unfamiliar code, and Git/GitHub proficiency. Success requires a blend of offensive and defensive security skills, ability to work collaboratively without formal authority, and commitment to developing technical security expertise through practical work and labs.