Affirm's Application Security team is hiring an early-career Application Security Engineer who is curious, collaborative, and comfortable working with code, to help assess application risks, support vulnerability management, and partner with engineering teams on secure design decisions.
Responsibilities
- ▹Partner with product and engineering teams to identify application security risks and frame them as clear business risks and options
- ▹Read application code, configuration, pull requests, logs, and documentation to understand systems and security risks
- ▹Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows
- ▹Work in GitHub to review code changes, participate in pull request discussions, and track remediation work
- ▹Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests; help prioritize and remediate by real-world risk
- ▹Contribute to vulnerability management workflows: triage, validation, severity assessment, remediation guidance, tracking, reporting
- ▹Translate recurring findings into repeatable mechanisms: secure coding guidance, checklists, automation, detection logic, developer documentation
- ▹Work with engineers to understand system designs, data flows, trust boundaries, auth models, and abuse cases
- ▹Communicate security issues clearly to technical and non-technical audiences
- ▹Build relationships across Affirm teams and influence security outcomes without formal authority
- ▹Continue developing offensive, defensive, and software engineering skills through practical work, labs, tooling, and certifications
Requirements
- ▹0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or equivalent practical experience
- ▹Foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar
- ▹Comfort reading and reasoning about code, even in unfamiliar codebases
- ▹Experience with Git and GitHub or similar version-control workflows
- ▹Hands-on experience building, testing, breaking, or securing software (professional, internship, labs, CTFs, bug bounty, open source, personal projects, coursework)
- ▹Ability to write clear, maintainable scripts to automate workflows, analyze data, or validate findings
- ▹Foundational understanding of common web, API, mobile, cloud, and application security risks (OWASP Top 10, auth flaws, injection, insecure design, secrets exposure, dependency risk)
- ▹Interest in offensive security (certifications, web/API testing practice, exploit development fundamentals, Burp Suite, CTFs)
- ▹Exposure to vulnerability management concepts: triage, severity assessment, remediation tracking, false-positive analysis, risk-based prioritization
- ▹Ability to reason about risk and tradeoffs, not just identify issues
- ▹Strong product and engineering empathy
- ▹Clear written and verbal communication skills
- ▹Collaborative mindset across product, engineering, compliance, risk, and security teams
- ▹Curiosity, humility, and a growth mindset
Soft skills
Curiosity, humility, and continuous learningClear communication with technical and non-technical audiencesCross-team collaboration without formal authorityRisk-based reasoning and judgment
What we offer
- ▹100% employer-subsidized medical coverage for employees and dependents
- ▹Flexible spending wallets for technology, food, and lifestyle needs
- ▹Employee Stock Purchase Plan (ESPP) offering discounted Affirm shares
About the company
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest.
Ähnliche Stellen

Stelle
Product Security Engineer II
Affirm
+1
114 988–158 216 €/Jahr
brutto
🌍 Remote
🗣️ EN

Stelle
Application Security Engineer II
Abnormal Security
AI/MLLlm
+3
112 480–161 674 €/Jahr
brutto
🌍 Remote
🗣️ EN

Stelle
Cybersecurity Detection Engineering Specialist
Ubisoft
Powershell
💰 Gehalt: keine Angabe
🏢 Vor Ort
Montreal
🗣️ EN

Stelle
Infrastructure Security Engineer, Public Sector
Scale AI
Cloudformation
+5
171 530–295 682 €/Jahr
brutto
🏢 Vor Ort
St. Louis
🗣️ EN

Stelle
Product Security Engineer, Public Sector
Scale AI
+1
171 530–295 682 €/Jahr
brutto
🏢 Vor Ort
St. Louis
🗣️ EN

Stelle
Security engineer, application security
Writer
AI/MLLlm
+1
113 950–222 799 €/Jahr
brutto
🔀 Hybrid
New York City
🗣️ EN