1h ago
Staff Product Security Engineer
Remote US
full-timesenior RemoteFinancial Services
Tech Stack
Description
As a Staff Product Security Engineer at Affirm, you will partner with product teams to embed security into every phase of the product development lifecycle. You'll conduct threat modeling, architecture reviews, and code analysis to identify and mitigate vulnerabilities, while automating security processes and guiding teams on security requirements.
Requirements
- Deep understanding of web application architecture and design principles
- Experience developing cloud-based services using modern techniques (Python, Kotlin, Java, AWS, Azure preferred)
- Knowledge of common security flaws (OWASP, SANS) and resolution
- Experience with threat modeling for complex distributed products
- Familiarity with authentication mechanisms (SAML, OAuth2) and CI/CD processes
Responsibilities
- Partner with product teams to embed security in the product development lifecycle
- Conduct threat modeling and architecture reviews to document and mitigate threats
- Review and analyze product source code to identify vulnerabilities and recommend secure implementation
- Develop security-focused test cases and advise on business security requirements early in development
- Decompose large projects into individual tasks, manage scope, and drive project closure
0 views 0 saves 0 applications