1h ago

Staff Product Security Engineer

Remote US
full-timesenior RemoteFinancial Services

Tech Stack

Description

As a Staff Product Security Engineer at Affirm, you will partner with product teams to embed security into every phase of the product development lifecycle. You'll conduct threat modeling, architecture reviews, and code analysis to identify and mitigate vulnerabilities, while automating security processes and guiding teams on security requirements.

Requirements

  • Deep understanding of web application architecture and design principles
  • Experience developing cloud-based services using modern techniques (Python, Kotlin, Java, AWS, Azure preferred)
  • Knowledge of common security flaws (OWASP, SANS) and resolution
  • Experience with threat modeling for complex distributed products
  • Familiarity with authentication mechanisms (SAML, OAuth2) and CI/CD processes

Responsibilities

  • Partner with product teams to embed security in the product development lifecycle
  • Conduct threat modeling and architecture reviews to document and mitigate threats
  • Review and analyze product source code to identify vulnerabilities and recommend secure implementation
  • Develop security-focused test cases and advise on business security requirements early in development
  • Decompose large projects into individual tasks, manage scope, and drive project closure
0 views 0 saves 0 applications