Affirm's Application Security team is hiring an early-career Application Security Engineer who is curious, collaborative, and comfortable working with code, to help assess application risks, support vulnerability management, and partner with engineering teams on secure design decisions.
Responsibilities
- ▹Partner with product and engineering teams to identify application security risks and frame them as clear business risks and options
- ▹Read application code, configuration, pull requests, logs, and documentation to understand systems and security risks
- ▹Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows
- ▹Work in GitHub to review code changes, participate in pull request discussions, and track remediation work
- ▹Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests; help prioritize and remediate by real-world risk
- ▹Contribute to vulnerability management workflows: triage, validation, severity assessment, remediation guidance, tracking, reporting
- ▹Translate recurring findings into repeatable mechanisms: secure coding guidance, checklists, automation, detection logic, developer documentation
- ▹Work with engineers to understand system designs, data flows, trust boundaries, auth models, and abuse cases
- ▹Communicate security issues clearly to technical and non-technical audiences
- ▹Build relationships across Affirm teams and influence security outcomes without formal authority
- ▹Continue developing offensive, defensive, and software engineering skills through practical work, labs, tooling, and certifications
Requirements
- ▹0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or equivalent practical experience
- ▹Foundational programming ability in Python, JavaScript/TypeScript, Kotlin, or similar
- ▹Comfort reading and reasoning about code, even in unfamiliar codebases
- ▹Experience with Git and GitHub or similar version-control workflows
- ▹Hands-on experience building, testing, breaking, or securing software (professional, internship, labs, CTFs, bug bounty, open source, personal projects, coursework)
- ▹Ability to write clear, maintainable scripts to automate workflows, analyze data, or validate findings
- ▹Foundational understanding of common web, API, mobile, cloud, and application security risks (OWASP Top 10, auth flaws, injection, insecure design, secrets exposure, dependency risk)
- ▹Interest in offensive security (certifications, web/API testing practice, exploit development fundamentals, Burp Suite, CTFs)
- ▹Exposure to vulnerability management concepts: triage, severity assessment, remediation tracking, false-positive analysis, risk-based prioritization
- ▹Ability to reason about risk and tradeoffs, not just identify issues
- ▹Strong product and engineering empathy
- ▹Clear written and verbal communication skills
- ▹Collaborative mindset across product, engineering, compliance, risk, and security teams
- ▹Curiosity, humility, and a growth mindset
Soft skills
Curiosity, humility, and continuous learningClear communication with technical and non-technical audiencesCross-team collaboration without formal authorityRisk-based reasoning and judgment
What we offer
- ▹100% employer-subsidized medical coverage for employees and dependents
- ▹Flexible spending wallets for technology, food, and lifestyle needs
- ▹Employee Stock Purchase Plan (ESPP) offering discounted Affirm shares
About the company
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest.
Similar jobs

Job
Product Security Engineer II
Affirm
+1
$133,000–$183,000/yr
gross
🌍 Remote
🗣️ EN

Job
Application Security Engineer II
Abnormal Security
AI/MLLlm
+3
$130,100–$187,000/yr
gross
🌍 Remote
🗣️ EN

Job
Cybersecurity Detection Engineering Specialist
Ubisoft
Powershell
💰 Salary: not specified
🏢 On-site
Montreal
🗣️ EN

Job
Infrastructure Security Engineer, Public Sector
Scale AI
Cloudformation
+5
$198,400–$342,000/yr
gross
🏢 On-site
St. Louis
🗣️ EN

Job
Product Security Engineer, Public Sector
Scale AI
+1
$198,400–$342,000/yr
gross
🏢 On-site
St. Louis
🗣️ EN

Job
Security engineer, application security
Writer
AI/MLLlm
+1
$131,800–$257,700/yr
gross
🔀 Hybrid
New York City
🗣️ EN