Primary record

Product Security Engineer II

Affirm Indexed employerRemote Canada · Remote US
Source-hosted applyChecked 10m agoInternship
Apply at Affirm

Affirm receives this application through Greenhouse. Babu Careers does not claim delivery.

Workplace

remote

Employment

Internship

Published

Aug 11, 2026

Closes

No date supplied

The role

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

About the InfoSec & IT Team

The Application Security team helps Affirm build and launch products that earn customer trust, meet compliance obligations, and reduce business risk. We partner closely with product, engineering, infrastructure, risk, compliance, and other teams to identify security risks early, recommend pragmatic mitigations, and help teams find safe paths to launch.

We are looking for an early-career Application Security Engineer who is curious, collaborative, and comfortable working with code. You will help assess application risks, support vulnerability management efforts, partner with engineering teams on secure design decisions, and contribute lightweight tooling, automation, and code-informed analysis that helps AppSec scale across Affirm.

This role is a great fit for someone who has hands-on software or security experience, enjoys reading and reasoning about code, is actively developing offensive security skills, and wants to apply those skills in a product-minded, risk-based way.

What You'll Do

Partner with product and engineering teams to identify application security risks and help frame them as clear business risks, launch options, and recommended next steps.

Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.

Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.

Work in GitHub to review code changes, understand engineering context, participate in pull request discussions, track remediation work, and colla

Requirements

Department: Information Security