```html
Affirm is seeking a Product Security Engineer II to join its Application Security team in a remote Canada–based role. You will work alongside product, engineering, infrastructure, and compliance teams to identify and mitigate security risks, support vulnerability management, and build lightweight tooling and automation that help AppSec scale across the organization. This role suits candidates with hands-on software or security experience who enjoy code review, are developing offensive security skills, and want to apply them in a product-focused, risk-driven environment.
Responsibilities
- Partner with product and engineering teams to identify application security risks and frame them as business risks with clear launch options and recommended mitigation steps.
- Review application code, configuration, pull requests, logs, and documentation to understand systems and detect security risks.
- Contribute code changes, scripts, detections, tests, secure defaults, and automation to improve AppSec workflows and reduce recurring security issues.
- Work in GitHub to review code changes, participate in pull request discussions, track remediation efforts, and collaborate with engineering teams.
- Evaluate vulnerabilities from internal testing, bug bounty submissions, security tooling, penetration tests, and other sources; partner with teams to prioritize and remediate based on real-world risk.
- Contribute to vulnerability management workflows, including triage, validation, severity assessment, remediation guidance, tracking, and reporting.
- Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, paved paths, automation, detection logic, review patterns, and developer documentation.
- Work with engineers to understand system designs, data flows, trust boundaries, authentication and authorization models, code execution paths, and potential abuse scenarios.
- Communicate security issues clearly to both technical and non-technical audiences, including risk assessment, tradeoffs, and recommended mitigation paths.
Requirements
- Hands-on software development or security engineering experience.
- Demonstrated ability to read, analyze, and reason about code.
- Experience with or active development of offensive security skills (e.g., vulnerability identification, exploit techniques, security testing).
- Familiarity with GitHub workflows and code review processes.
- Experience with vulnerability assessment, triage, and remediation tracking.
Benefits
- Remote work based in Canada.
```