Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Product Security Engineer (Fintech): Architecting and implementing security measures across the product development lifecycle with an accent on threat modeling, secure code analysis, and cloud-based service security. Focus on driving cross-team security initiatives, automating security processes, and ensuring compliance in a regulated financial environment.
Location: Must be based in Canada
Salary: $178,000 - $228,000 CAD
Company
Affirm is a financial technology company reinventing credit by providing flexible, transparent payment solutions without hidden fees.
What you will do
- Partner with product teams to integrate security into every phase of the development lifecycle.
- Conduct threat modeling and architecture reviews for complex, distributed products.
- Analyze source code to identify vulnerabilities and provide actionable remediation recommendations.
- Develop and implement automated security solutions to address emerging threat classes.
- Advise on business security requirements and enforce security-focused test cases.
- Manage scope and drive cross-team projects toward successful closure.
Requirements
- Must be based in Canada
- Deep understanding of web application architecture and design principles.
- Experience with modern software development and delivery for cloud-based services (Python, Kotlin, Java, AWS, Azure).
- Knowledge of common security flaws (OWASP, SANS) and authentication mechanisms (SAML, OAuth2).
- Experience working in PCI or other regulated environments.
- Proven ability to conduct threat models for complex, distributed systems.
- BS degree in a related field or equivalent practical experience.
Culture & Benefits
- 100% subsidized medical, dental, and vision coverage for employees and dependents.
- Generous flexible spending wallets for technology, food, and lifestyle needs.
- Competitive vacation and holiday schedules.
- Employee stock purchase plan (ESPP) with discount.
- Remote-first work environment with occasional office collaboration.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →