Affirm is a financial services company that is on a mission to provide its customers with “honest financial products that improve lives.” As an employer, Affirm maintains a rem
Senior Product Security Engineer
Location
Canada
Posted
64 days ago
Salary
$150K - $200K / year
Seniority
Senior
Job Description
Senior Product Security Engineer
Affirm
• Partner with Affirm product teams to ensure that security is included in every phase of the product development lifecycle. • Conduct threat modeling and architecture reviews to ensure threats are understood, documented, and mitigated. • Review and analyze product source code to identify security vulnerabilities and provide recommendations for secure implementation. • Seek out opportunities to automate processes when appropriate. • Identify emerging classes of vulnerabilities and developing solutions for them before they’re a problem. • Assist product teams in the development of security focused test cases to enforce security requirements. • Advise product teams on business security requirements early in the product development lifecycle. • Decompose large, cross-team projects into individual tasks. Manage scope across teams and drive toward project closure.
Job Requirements
- Deep understanding of web application architecture and design principles
- Experience using modern software development and delivery techniques to develop cloud-based services. Python, Kotlin, Java, AWS, and Azure experience preferred.
- Knowledge of common security flaws and resolution as published by OWASP, SANS, etc.
- Experience with PCI or other regulated environments.
- Experience conducting threat models for complex, distributed products using standard threat modeling techniques and methodologies.
- Experience with standard authentication mechanisms, including SAML and OAuth2.
- Understanding of continuous integration / continuous deployment processes and tools.
- BS degree in related field or equivalent experience. MS degree in a related field or equivalent experience is a plus.
Benefits
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Design, build, and maintain SAP roles, profiles, and authorizations across SAP landscapes (ECC, S/4HANA, BW, etc.) • Administer user access, including provisioning, deprovisioning, and role assignments in accordance with least privilege principles • Perform Segregation of Duties (SoD) analysis and remediation using tools such as GRC Access Control (or equivalent) • Support SAP security audits, compliance reviews, and Authority to Operate (ATO) activities • Implement and maintain security controls aligned with DoD RMF and STIG requirements • Monitor and respond to security incidents, vulnerabilities, and access-related issues • Collaborate with Basis and infrastructure teams to secure SAP systems in AWS or hybrid cloud environments • Develop and maintain security documentation, policies, and standard operating procedures • Support integration security across SAP modules and external interfaces
• You will help design, build, and tune security tooling that improves security of code and CI/CD pipelines while maintaining code deployment velocity. • You will help design, implement, and maintain scalable security controls for our cloud environments without impacting deployment speeds and platform stability. • You will help define, implement, and enforce our AI security policies and procedures. • You will aid our Product Managers in developing secure and resilient product designs by addressing risks you’ve identified through threat modeling. • You will help maintain our vulnerability management, bug bounty, and penetration testing programs. • Most importantly, you’ll develop close, collaborative relationships with other technical experts in our Product, Platform Engineering, Software Engineering, IT, and Detection & Response functions.
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we’re all a part of something bigger than ourselves. Are you ready to change the way the world moves? Enterprise Technology is looking for a Security Engineer within Enterprise Platform Engineering and Operations group to engineer solutions within our Cybersecurity platforms in support of our Cyber Defense Organization. Enterprise Technology plays a critical part in shaping the future of mobility. If you’re looking for the chance to leverage advanced technology to redefine the transportation landscape, enhance the customer experience, and improve people’s lives, this is the opportunity for you. Join us and challenge your IT expertise and analytical skills to help create vehicles that are as smart as you are. This position drives the software architecture and engineering of our SIEM/SOAR and unified risk management ecosystems. With a primary focus on cloud based SIEM/SOAR & security management platforms, you will apply software engineering principles to build scalable, API-driven security solutions. The ideal candidate brings a hybrid background in coding and security, capable of programmatically managing infrastructure, developing custom data pipelines, and engineering automation workflows to empower a mature SOC. You will collaborate with cross-functional teams to code and deploy enhancements that strengthen our security posture and automate compliance standards. - Architect and engineer scalable, cloud-native SIEM solutions, utilizing Infrastructure-as-Code principles to manage log ingestion pipelines and storage. - Develop and maintain robust data pipelines to ingest, transform, and normalize security logs from diverse endpoints (APIs, cloud platforms, firewalls) into the SIEM, ensuring high data fidelity and low latency. - Write and optimize custom parsers using Regex and scripting languages to map raw log data to standardized security models, ensuring consistent data structures for analysis. - Program custom integrations connecting third-party tools and streaming data sources to the SIEM via REST APIs and webhooks. - Collaborate with DevOps and Application teams to define logging standards and embed security telemetry requirements early in the software development lifecycle (SDLC). - Manage the full lifecycle of the SIEM platform, including health monitoring, troubleshooting ingestion failures, and debugging parsing errors to ensure 24/7 availability. - Proactively analyze ingestion volume against capacity limits to identify optimization opportunities, implementing granular log tuning and exclusion rules that minimize licensing costs and maximize the signal-to-noise ratio - Engineer automated provisioning workflows using Infrastructure as Code (IaC) to programmatically manage both the underlying infrastructure and complex IAM policies supporting the security platforms. You’ll have: - Bachelor’s degree in Computer Science, Cyber Security, Information Systems or related field. - 6+ years of overall software engineering experience - 2+ technical experience designing and maintaining scalable security data architectures. - Skilled in configuring cloud-native security & SIEM/SOAR platforms. - Experience with security logging, data sources, log parsing & tuning and industry best practices for log ingestion - Experience administering cloud-native security platforms, with a specific focus on maintaining platform health, troubleshooting configuration issues, and managing complex IAM roles to ensure granular access control. - 2+ years hands-on development experience on cloud native platforms, preferably Google Cloud Platform. Even better, you may have... - Proficiency in scripting languages like Python, Go, Java, or Bash for automation, data manipulation, and integration tasks. - Hands-on experience setting up CI/CD pipelines. OpenShift Tekton, or GitHub Actions or similar. - Knowledge of secure coding practices - Experience setting up serverless functions using GCP Cloud Run or Cloud functions, and configuring the respective service for scaling - Robust knowledge of system design principles including reliability, availability, and scalability - Experience setting up logging and monitoring services (Dynatrace, GCP Ops Suites) - Strong understanding of network security, log analysis, threat detection, and incident response. - Knowledge of RESTful APIs, data integration techniques, and infrastructure-as-code tools (e.g., Terraform, Ansible). - Analytical and Problem-Solving Skills: - Ability to analyze complex data systems, identify improvement opportunities, and translate business requirements into detailed technical designs. - Excellent analytical skills and attention to detail for solving complex problems with many variables. - Communication and Collaboration: - Strong verbal and written communication skills to articulate technical issues, collaborate with stakeholders, and create comprehensive documentation. - Ability to work effectively in a team environment and interact with various internal and external teams. - Comfortable supporting multiple client environments and balancing delivery with operations. - Security & Cloud skills: - Familiarity with security concepts, cybersecurity frameworks such as NIST, MITRE ATT&CK threat hunting, and cyber threat intelligence. - Strong technical experience working in multi-cloud platforms, particularly Google Cloud. You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply! As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder…or all of the above? No matter what you choose, we offer a work life that works for you, including: - Immediate medical, dental, and prescription drug coverage - Flexible family care, parental leave, new parent ramp-up programs, subsidized back-up child care and more - Vehicle discount program for employees and family members, and management leases - Tuition assistance - Established and active employee resource groups - Paid time off for individual and team community service - A generous schedule of paid holidays, including the week between Christmas and New Year’s Day - Paid time off and the option to purchase additional vacation time. For a detailed look at our benefits, click here: Benefit Summary This position is a salary grade 7- 8. This position is a salary grade 7-8 and ranges from $97,140-190,500. *Visa Sponsorship is not provided for this role* Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, If you need a reasonable accommodation for the online application process due to a disability, please call 1-888-336-0660. #LI-Remote #LI-GH2
Principal Security Engineer, Infrastructure Security
OpenAICreating safe AGI that benefits all of humanity.
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture. About the Role OpenAI is seeking a Principal Software Engineer to join the Infrastructure Security (InfraSec) team. InfraSec safeguards the core of OpenAI’s research and production environments: GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data. As a Principal Software Engineer, you will set technical direction and drive execution of critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s customer and supercomputing environment and must remain robust under intense scale and adversarial pressure. In this role, you will: - Own the architecture and roadmap for one or more core security services (e.g., authN/Z, policy enforcement, secure proxies, key management), taking them from design to rollout to long-term operation. - Design and implement planet-scale security systems that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD: balancing security, reliability, latency, and developer ergonomics. - Lead cross-functional launches with infrastructure and research engineering teams, shaping interfaces, migration plans, and safe rollout strategies across large fleets and critical workflows. - Build or evolve security primitives (identity, attestation, authorization, encryption key lifecycle, access mediation) that become platform building blocks for OpenAI. - Leverage frontier models and agents to develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments. - Lead design reviews and threat models for major initiatives, and drive closure on systemic issues. - Mentor engineers across InfraSec and partner teams, raising the bar on engineering quality, operational readiness, and secure-by-default practices. You will thrive in this role if you have: - Strong software engineering skills with a track record of shipping and operating reliable distributed systems in production. - Experience building or operating critical infrastructure, especially security infrastructure, at planet scale (e.g., auth services, service-to-service proxies, certificate or key-management systems). - Deep understanding of security principles, best practices, and common vulnerabilities. - Demonstrated ability to lead cross-team technical initiatives: setting direction, aligning stakeholders, driving execution, and delivering measurable outcomes. - Expertise and curiosity about using frontier models and agents to effectively solve security challenges. - Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design. - A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling. - Strong analytical and problem-solving skills, with an ability to think critically and objectively assess risks. - Excellent communication skills, with the ability to convey complex security concepts to executive, technical, and non-technical stakeholders. About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement. Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link. OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.




