```html
Affirm is seeking a Product Security Engineer II to join its Application Security team in a remote US role. You'll work across product, engineering, infrastructure, and compliance teams to identify application security risks early, recommend practical mitigations, and help teams launch safely. This position is designed for someone with hands-on software or security experience who enjoys reading code, is developing offensive security skills, and wants to apply those capabilities in a product-focused, risk-based environment.
Responsibilities
- Partner with product and engineering teams to identify application security risks and frame them as business risks with launch options and remediation recommendations
- Review application code, configuration, pull requests, logs, and documentation to understand systems and identify security risks
- Write code changes, scripts, detections, tests, secure defaults, and automation to improve AppSec workflows and reduce recurring issues
- Use GitHub to review code changes, engage in pull request discussions, track remediation work, and collaborate with engineers
- Evaluate vulnerabilities from internal testing, bug bounty reports, security tools, penetration tests, and other sources; partner with teams to prioritize and remediate based on actual risk
- Contribute to vulnerability management workflows including triage, validation, severity assessment, remediation guidance, tracking, and reporting
- Translate recurring security findings into secure coding guidance, checklists, paved paths, automation, detection logic, code review patterns, and developer documentation
- Work with engineers to understand system designs, data flows, trust boundaries, authentication and authorization models, code paths, and potential abuse scenarios
- Communicate security issues clearly to technical and non-technical audiences, explaining risk and tradeoffs
Requirements
- Hands-on software development or security engineering experience
- Demonstrated ability to read and reason about application code
- Experience with or active development of offensive security skills
- Proficiency working in GitHub for code review and collaboration
- Understanding of application security concepts including authentication, authorization, common vulnerabilities, and secure design patterns
```