Senior Product Security Engineer (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Product Security Engineer (Fintech): Building and architecting secure software for a credit platform with an accent on threat modeling, architecture reviews, and source code analysis. Focus on identifying emerging vulnerability classes, automating security processes, and ensuring compliance in regulated environments.
Location: Remote Canada
Salary: $153,000 - $213,000 per year
Company
Affirm is a fintech company reinventing credit to make it more honest and friendly by providing flexible buy now and pay later solutions without hidden fees.
What you will do
- Partner with product teams to integrate security into every phase of the product development lifecycle.
- Conduct threat modeling and architecture reviews to document and mitigate risks.
- Analyze product source code to identify vulnerabilities and provide secure implementation recommendations.
- Automate security processes and develop solutions for emerging vulnerability classes.
- Assist teams in developing security-focused test cases to enforce requirements.
- Manage scope and drive closure for large, cross-team security projects.
Requirements
- Must be based in Canada.
- Deep understanding of web application architecture and design principles.
- Experience with cloud-based services, preferably using Python, Kotlin, Java, AWS, and Azure.
- Knowledge of common security flaws (OWASP, SANS) and experience with PCI or other regulated environments.
- Proven experience conducting threat models for complex distributed products.
- Proficiency with standard authentication mechanisms including SAML and OAuth2.
Culture & Benefits
- 100% subsidized medical, dental, and vision coverage for employees and dependents.
- Generous flexible spending wallets for technology, food, and lifestyle needs.
- Competitive vacation and holiday schedules to ensure work-life balance.
- Employee Stock Purchase Plan (ESPP) to buy company shares at a discount.
- Remote-first culture with flexibility to work from anywhere within the country of employment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →