Product Security Engineer II
New
A
AffirmFinTech
Remote CanadaFull-TimeMiddle
SalaryCAN base pay range per year: CAD $133,000 - $183,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 0–2+ years
- Required Skills
- PythonGitJavascriptKotlinTypeScriptGitHub
Requirements
- 0–2+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, security operations, or equivalent practical experience.
- Foundational programming ability in one or more languages such as Python, JavaScript/TypeScript, Kotlin, or similar.
- Comfort reading, navigating, and reasoning about code, even in unfamiliar codebases.
- Experience using Git and GitHub or similar version-control workflows.
- Some hands-on experience building, testing, breaking, or securing software (e.g., internships, security labs, CTFs, bug bounty, open-source).
- Ability to write clear, maintainable scripts or small programs to automate manual workflows or analyze data.
- Foundational understanding of common web, API, mobile, cloud, and application security risks (e.g., OWASP Top 10).
- Exposure to vulnerability management concepts, including triage, severity assessment, and risk-based prioritization.
- Ability to reason about risk and tradeoffs in a product-minded, engineering-empathetic way.
- Clear written and verbal communication skills.
Responsibilities
- Partner with product and engineering teams to identify application security risks and help frame them as clear business risks, launch options, and recommended next steps.
- Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
- Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.
- Work in GitHub to review code changes, understand engineering context, participate in pull request discussions, track remediation work, and collaborate with engineers.
- Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, penetration tests, and other sources; partner with teams to prioritize and remediate issues based on real-world risk.
- Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, paved paths, or lightweight automation.
- Communicate security issues clearly to both technical and non-technical audiences, including the risk, tradeoffs, recommended mitigations, and residual risk.
View Full Description & ApplyYou'll be redirected to the employer's site