跳到主要内容
OOfficialJobs
菜单
官方来源官方来源职位

产品安全工程师 II

机器翻译
查看雇主原标题Product Security Engineer II

Affirm · Remote 加拿大 · Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidiz

职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。

为什么值得关注?

发现指数 50/100,仅依据与该职位一起存储的证据计算。

50/100 发现指数
  • 新的雇主官方职位
  • 远程职位

分数构成

  • 时效性 (随职位发布时间变化)+18
  • 雇主官方来源+15
  • 远程职位+8
  • 稀有职位+1
  • 公司来源健康度+8

该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。

这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。

职位描述

机器翻译

在Affirm,我们存在的意义在于那些重要时刻——为人们提供清晰、可预测的分期付款方式,没有隐藏费用,没有意外,在最重要的事情上无需妥协。

关于信息安全与IT团队

应用安全团队帮助Affirm构建和发布赢得客户信任、满足合规义务并降低业务风险的产品。我们与产品、工程、基础设施、风险、合规及其他团队紧密合作,尽早识别安全风险,推荐务实的缓解措施,并帮助团队找到安全的发布路径。

我们正在寻找一位早期职业阶段的应用安全工程师,要求好奇心强、善于协作,并且能够自如地处理代码。你将帮助评估应用风险,支持漏洞管理工作,与工程团队合作进行安全设计决策,并贡献轻量级工具、自动化和基于代码的分析,帮助AppSec在Affirm范围内扩展。

这个职位非常适合具有实际软件或安全经验、喜欢阅读和推理代码、正在积极发展攻击性安全技能,并希望以产品思维、基于风险的方式应用这些技能的人。

岗位职责

• 与产品和工程团队合作,识别应用安全风险,并帮助将其转化为清晰的业务风险、发布选项和建议的后续步骤。

• 阅读应用代码、配置、拉取请求、日志和文档,以了解系统如何运作以及安全风险可能存在于何处。

• 贡献小型代码更改、脚本、检测、测试、安全默认值或自动化,以改进AppSec工作流程并减少重复出现的问题。

• 在GitHub中工作,审查代码更改,理解工程背景,参与拉取请求讨论,跟踪修复工作,并与工程师协作。

• 帮助评估来自内部测试、漏洞赏金报告、安全工具、渗透测试和其他来源的漏洞;与团队合作,根据现实世界风险确定优先级并修复问题。

• 为漏洞管理工作流程做出贡献,包括分类、验证、严重性评估、修复指导、跟踪和报告。

• 将重复出现的安全发现转化为可重复的机制,如安全编码指南、检查清单、铺平路径、轻量级自动化、检测逻辑、可复用的审查模式或面向开发者的文档。

• 与工程师合作,了解系统设计、数据流、信任边界、身份验证和授权模型、代码路径以及潜在的滥用场景。

• 向技术和非技术受众清晰地传达安全问题,包括风险、权衡、建议的缓解措施和剩余风险。

• 在Affirm各团队之间建立牢固的关系,并在不依赖正式权威的情况下影响安全成果。

• 帮助将AppSec工作与客户信任、监管/合规期望、运营韧性和业务成果联系起来。

• 通过实际工作、实验室、工具、研究、认证或对内部安全项目的贡献,继续发展实际的攻击性、防御性和软件工程技能。

我们寻找什么样的人

• 4年以上应用安全、软件工程、安全工程、漏洞管理、渗透测试、安全运营或同等实践经验。

• 具备一种或多种语言的基础编程能力,如Python、JavaScript/TypeScript、Kotlin或类似语言。

• 能够自如地阅读、浏览和推理代码,即使是在不熟悉的代码库中。

• 有使用Git和GitHub或类似版本控制工作流程的经验,包括分支、提交、拉取请求、代码审查、问题或项目跟踪。

• 有一些构建、测试、破解或保护软件的实践经验。这可能包括专业经验、实习、安全实验室、CTF、漏洞赏金工作、开源贡献、个人项目、自动化脚本、内部工具或课程作业。

• 能够编写清晰、可维护的脚本或小型程序,以解决实际问题、自动化手动工作流程、分析数据、验证发现或改进安全流程。

• 对常见的Web、API、移动、云和应用安全风险有基础理解,如OWASP Top 10问题、身份验证和授权缺陷、注入、不安全设计、机密泄露、依赖风险和数据保护问题。

• 对攻击性安全有兴趣,如学习或完成安全认证、练习Web/API测试、学习漏洞利用开发基础、使用Burp Suite等工具,或参与实验室和夺旗赛环境。

• 接触过漏洞管理概念,包括分类、严重性评估、修复跟踪、误报分析、补偿控制和基于风险的优先级排序。

• 能够推理风险和权衡,而不仅仅是识别问题。你能够解释可能出什么问题、可能性有多大、可能产生什么影响,以及有哪些降低风险的选项。

• 强烈的产品和工程同理心。在推荐前进路径之前,你会寻求了解发布目标、技术约束、用户影响和业务优先级。

• 清晰的书面和口头沟通能力,包括能够以实用、可操作的方式解释安全发现。

• 具有协作心态,能够自如地在产品、工程、合规、风险、基础设施和安全团队之间工作。

• 好奇心、谦逊和成长心态。你主动寻求反馈,提出好问题,并继续建立你的技术深度。

• 安全设计判断力,包括发现模式、推荐简单控制措施,并在发布速度与有意义的风险降低之间取得平衡的能力。

福利待遇

我们的福利体现了我们对关怀、透明和灵活性的承诺。以下是一些亮点:

• 免费健康保险:我们为员工及其家属支付100%的保费。

• 支出津贴:每月津贴支持你的技术设备配置,并可选择适合你的健康和保健选项。

• 充电休假:灵活休假和慷慨的假期日历帮助你在需要时休息。

• 拥有你所构建成果的一部分:我们的员工购股计划(ESPP)让你以折扣价购买Affirm股票。

我们致力于提供包容性的面试流程,包括为残障候选人提供便利。如果你需要支持,我们很乐意提供帮助。

对于位于旧金山或洛杉矶的职位:根据法律要求,Affirm会考虑有逮捕和定罪记录的合格申请人。

点击“提交申请”,即表示你确认已阅读Affirm的全球候选人隐私声明,并同意按所述方式使用你的个人信息。

薪资

股权等级 - 5

新加入Affirm的员工通常从薪酬范围的起点开始。Affirm专注于提供简单透明的薪酬结构,该结构基于多种因素,包括地点、经验和工作相关技能。

基本工资是总薪酬方案的一部分,其中可能包括用于健康、保健和技术支出的月度津贴,以及福利(包括为你和你的家属提供100%补贴的医疗保险、牙科和视力保险)。此外,员工可能有资格获得Affirm Holdings, Inc.(母公司)提供的股权奖励。

加拿大年度基本工资范围:CAD $133,000 - $183,000

地点 - 加拿大远程 此远程职位仅面向居住在阿尔伯塔省、不列颠哥伦比亚省、曼尼托巴省、新不伦瑞克省、纽芬兰与拉布拉多省、新斯科舍省、安大略省、爱德华王子岛省或萨斯喀彻温省的候选人。

#LI-Remote

远程优先,内置灵活性 Affirm很自豪是一家远程优先的公司。大多数职位几乎可以在雇佣国家内的任何地方完成。某些职位可能偶尔需要在Affirm办公室现场工作,少数职位因工作性质而需要在办公室工作。所有新员工都将被邀请参加现场入职体验。

以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。

查看雇主原文

职位描述

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

About the InfoSec & IT Team

The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance obligations, and reduce business risk. We partner closely with product, engineering, infrastructure, risk, compliance, and other teams to identify security risks early, recommend pragmatic mitigations, and help teams find safe paths to launch.

We are looking for an early-career Application Security Engineer who is curious, collaborative, and comfortable working with code. You will help assess application risks, support vulnerability management efforts, partner with engineering teams on secure design decisions, and contribute lightweight tooling, automation, and code-informed analysis that helps AppSec scale across Affirm.

This role is a great fit for someone who has hands-on software or security experience, enjoys reading and reasoning about code, is actively developing offensive security skills, and wants to apply those skills in a product-minded, risk-based way.

岗位职责

• Partner with product and engineering teams to identify application security risks and help frame them as clear business risks, launch options, and recommended next steps.

• Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.

• Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.

• Work in GitHub to review code changes, understand engineering context, participate in pull request discussions, track remediation work, and collaborate with engineers.

• Help evaluate vulnerabilities from internal testing, bug bounty reports, security tooling, penetration tests, and other sources; partner with teams to prioritize and remediate issues based on real-world risk.

• Contribute to vulnerability management workflows, including triage, validation, severity assessment, remediation guidance, tracking, and reporting.

• Translate recurring security findings into repeatable mechanisms such as secure coding guidance, checklists, paved paths, lightweight automation, detection logic, reusable review patterns, or developer-facing documentation.

• Work with engineers to understand system designs, data flows, trust boundaries, authentication and authorization models, code paths, and potential abuse cases.

• Communicate security issues clearly to both technical and non-technical audiences, including the risk, tradeoffs, recommended mitigations, and residual risk.

• Build strong relationships across Affirm teams and influence security outcomes without relying on formal authority.

• Help connect AppSec work to customer trust, regulatory/compliance expectations, operational resilience, and business outcomes.

• Continue developing hands-on offensive, defensive, and software engineering skills through practical work, labs, tooling, research, certifications, or contributions to internal security programs.

What We Look For

• 4+ years of experience in application security, software engineering, security engineering, vulnerability management, penetration testing, security operations, or equivalent practical experience.

• Foundational programming ability in one or more languages such as Python, JavaScript/TypeScript, Kotlin, or similar.

• Comfort reading, navigating, and reasoning about code, even in unfamiliar codebases.

• Experience using Git and GitHub or similar version-control workflows, including branches, commits, pull requests, code review, issues, or project tracking.

• Some hands-on experience building, testing, breaking, or securing software. This could include professional experience, internships, security labs, CTFs, bug bounty work, open-source contributions, personal projects, automation scripts, internal tools, or coursework.

• Ability to write clear, maintainable scripts or small programs to solve practical problems, automate manual workflows, analyze data, validate findings, or improve security processes.

• Foundational understanding of common web, API, mobile, cloud, and application security risks, such as OWASP Top 10 issues, authentication and authorization flaws, injection, insecure design, secrets exposure, dependency risks, and data protection concerns.

• Interest in offensive security, such as studying for or completing security certifications, practicing web/API testing, learning exploit development fundamentals, using tools like Burp Suite, or participating in labs and capture-the-flag environments.

• Exposure to vulnerability management concepts, including triage, severity assessment, remediation tracking, false-positive analysis, compensating controls, and risk-based prioritization.

• Ability to reason about risk and tradeoffs, not just identify issues. You can explain what could go wrong, how likely it is, what impact it may have, and what options exist to reduce risk.

• Strong product and engineering empathy. You seek to understand launch goals, technical constraints, user impact, and business priorities before recommending a path forward.

• Clear written and verbal communication skills, including the ability to explain security findings in practical, actionable terms.

• A collaborative mindset and comfort working across product, engineering, compliance, risk, infrastructure, and security teams.

• Curiosity, humility, and a growth mindset. You proactively seek feedback, ask good questions, and continue building your technical depth.

• Secure-by-design judgment, including the ability to spot patterns, recommend simple controls, and balance launch velocity with meaningful risk reduction.

福利待遇

Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

• Health coverage at no cost: We cover 100% of premiums for employees and their dependents.

• Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.

• Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.

• Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.

We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.

For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.

薪资

Equity Grade - 5

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

CAN base pay range per year: CAD $133,000 - $183,000

Location - Remote Canada This remote role is open only to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.

#LI-Remote

Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Affirm 的更多职位

公司主页

资深产品安全工程师

Affirm · Information Security

官方来源
Remote US远程全职Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (includi
英文原文

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The InfoSec team p…

未出现在监控的职位板上
首次发现于昨天
已核实10小时前

资深产品安全工程师

Affirm · Information Security

官方来源
Remote 加拿大远程全职Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidiz
英文原文

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The InfoSec team p…

未出现在监控的职位板上
首次发现于昨天
已核实10小时前
Remote 加拿大远程全职Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (includi
英文原文

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The Growth Platfor…

未出现在监控的职位板上
首次发现于前天
已核实10小时前
官方来源
Remote 加拿大远程全职Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidiz
英文原文

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. About the Team…

未出现在监控的职位板上
首次发现于3天前
已核实10小时前

其他公司的相似职位

搜索这类职位
官方来源最新
Hybrid - San Francisco, New York City混合办公全职$208k – $312k
英文原文

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next…

未出现在监控的职位板上
首次发现于4小时前
已核实4小时前

Staff Software Engineer, Event logging原文

Airbnb · Software Engineering

官方来源最新
美国全职未披露薪资
英文原文

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every c…

未出现在监控的职位板上
首次发现于4小时前
已核实4小时前

Senior Staff Software Engineer, Trust原文

Airbnb · Software Engineering

官方来源最新
Remote - US远程全职未披露薪资
英文原文

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every c…

未出现在监控的职位板上
首次发现于4小时前
已核实4小时前
官方来源最新
美国全职未披露薪资
英文原文

Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every c…

未出现在监控的职位板上
首次发现于4小时前
已核实4小时前