Staff Product Security Engineer

Affirm Payments

Canada
Base: $178,000 - $228,000 cad; bonus/equity: not s...
Remote
Product development lifecycle security
Threat modeling and architecture reviews
Source code vulnerability analysis
Affirm Payments is seeking a Staff Product Security Engineer to enhance information security across its product development lifecycle. The ideal candidate will collaborate with product and engineering teams to improve security measures while having a strong foundation in web application architecture and modern software development practices

Job Summary

  • Affirm values information security as a critical part of the company’s continued success, aiming to make it programmatic and cultural.
  • The Staff Product Security Engineer will partner with product teams to ensure security is integrated into every phase of the product development lifecycle.
  • The role involves conducting threat modeling, architecture reviews, and source code analysis to identify and mitigate security vulnerabilities.

Matching Summary

Match Score: 85

Affirm Payments is seeking a Staff Product Security Engineer to enhance information security across its product development lifecycle. The ideal candidate will collaborate with product and engineering teams to improve security measures while having a strong foundation in web application architecture and modern software development practices.

Salary

Base: $178,000 - $228,000 CAD; Bonus/Equity: Not specified; Benefits: Health, wellness, tech stipends, 100% subsidized medical, dental, vision, ESPP

Skills & Requirements

Must-have

  • Product development lifecycle security
  • Threat modeling and architecture reviews
  • Source code vulnerability analysis
  • Automate security processes
  • Develop solutions for emerging vulnerabilities
  • Security focused test cases

Nice-to-have

  • Programmatic and cultural information security
  • Honest and friendly financial products
  • Enable secure access to information

Key Requirements

  • Web application architecture and design principles
  • Modern software development and delivery techniques
  • Cloud-based services experience
  • OWASP, SANS common security flaws knowledge
  • PCI or other regulated environments experience
  • Threat models for complex, distributed products
  • Standard authentication mechanisms (SAML, OAuth2)
  • Continuous integration / continuous deployment processes
  • BS degree in related field or equivalent experience

Work Rights

Not specified

Tailored Resume

Cover Letter