Affirm's Application Security team is hiring an early-career security engineer to help assess application risks and support vulnerability management. The role works closely with product and engineering teams, from secure design decisions to building lightweight tooling and automation. It suits someone with hands-on software or security experience who wants to apply offensive security skills in a risk-based, product-minded way.
Responsibilities
- ▹Partner with product and engineering teams to identify application security risks and frame them as business risks
- ▹Read application code, configuration, pull requests, logs, and documentation to understand systems and where risks may exist
- ▹Contribute small code changes, scripts, detections, tests, and automation to improve AppSec workflows
- ▹Work in GitHub reviewing code changes, participating in pull request discussions, and tracking remediation work
- ▹Evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, and penetration tests, and help prioritize remediation based on real-world risk
- ▹Contribute to vulnerability management workflows: triage, validation, severity assessment, remediation guidance, tracking, and reporting
- ▹Translate recurring security findings into secure coding guidance, checklists, automation, and developer-facing documentation
- ▹Work with engineers to understand system designs, data flows, trust boundaries, authentication/authorization models, and abuse cases
- ▹Communicate security issues clearly to both technical and non-technical audiences
Requirements
- ▹0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, or security operations, or equivalent practical experience
- ▹Foundational programming ability in one or more languages such as Python, JavaScript/TypeScript, or Kotlin
- ▹Comfort reading, navigating, and reasoning about code, even in unfamiliar codebases
- ▹Experience using Git and GitHub or similar version-control workflows, including branches, commits, pull requests, and code review
- ▹Hands-on experience building, testing, breaking, or securing software (professional experience, internships, CTFs, bug bounty work, open-source contributions, personal projects)
- ▹Ability to write clear, maintainable scripts or small programs to automate workflows, analyze data, or validate findings
- ▹Foundational understanding of common web, API, mobile, cloud, and application security risks (OWASP Top 10, auth flaws, injection, insecure design, secrets exposure, dependency risks)
- ▹Clear written and verbal communication skills
Nice to have
- ▹Interest in offensive security: certifications, web/API testing practice, exploit development fundamentals, Burp Suite, CTFs
- ▹Exposure to vulnerability management concepts: triage, severity assessment, remediation tracking, false-positive analysis, compensating controls, risk-based prioritization
- ▹Ability to reason about risk and tradeoffs, not just identify issues
- ▹Strong product and engineering empathy
- ▹Curiosity, humility, and a growth mindset
- ▹Secure-by-design judgment, balancing launch velocity with meaningful risk reduction
Soft skills
Curiosity and a collaborative mindsetBuilding relationships and influencing outcomes without formal authorityClear communication to both technical and business audiencesHumility and openness to feedbackRisk- and tradeoff-based thinking
What we offer
- ▹Monthly stipends for health, wellness, and tech spending
- ▹100% subsidized medical, dental, and vision coverage for employee and dependents
- ▹Eligible for equity rewards from Affirm Holdings, Inc.
- ▹Fully remote role (within designated Canadian provinces)
- ▹CAD $133,000–$183,000 base pay range per year
About the company
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees or compounding interest. The company is proud to be remote-first, with most roles performed remotely within the country of employment.
Similar jobs

Job
Cybersecurity Detection Engineering Specialist
Ubisoft
Powershell
💰 Salary: not specified
🏢 On-site
Montreal
🗣️ EN

Job
Product Security Engineer II
Affirm
+1
$165,000–$225,000/yr
gross
🌍 Remote
🗣️ EN

Job
Application Security Engineer
Starburst
+5
💰 Salary: not specified
🏢 On-site
Warsaw
🗣️ EN

Job
Application Security Engineer II
Abnormal Security
AI/MLLlm
+3
$130,100–$187,000/yr
gross
🌍 Remote
🗣️ EN

Job
Application Security Engineer
Pepperstone
+6
💰 Salary: not specified
🏢 On-site
Limassol
🗣️ EN

Job
Application Security Engineer
Pepperstone
+6
💰 Salary: not specified
🏢 On-site
Budapest