Product Security Engineer II
Affirm
$146,000–$225,000from the description
Jul 26, 2026
—
Jul 27, 2026
What this job asks for AI summary
An early-career role on Affirm's Application Security team, focused on assessing application and API risks, supporting vulnerability management, and contributing scripts or lightweight tooling to scale security practices. The work involves reading code and system designs, collaborating with engineering teams on secure-by-design decisions, and translating recurring findings into reusable guidance. A good fit for someone with foundational programming ability and growing offensive security skills.
Junior level · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 41,400 people nationally plausibly meet what this posting asks for (information security analysts). range 17,400–62,000
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (5)
The role sits at the intersection of application security analysis and software engineering — it requires writing code, automation, and tooling (pointing toward 15-1252) but the primary mission is security risk assessment, vulnerability management, and AppSec review (pointing toward 15-1212). 15-1212 was chosen as the primary SOC given the security-analysis framing, with 15-1252 as a close runner-up.
The posting explicitly targets 0–2+ years of experience and is described as 'early-career,' supporting a Junior seniority classification despite the title carrying no explicit level word.
Programming language requirement is framed as 'one or more languages such as Python, JavaScript/TypeScript, Kotlin, or similar' — Python is listed as the primary with the others captured as alternatives on the same skill entry.
Burp Suite is mentioned only in the context of interest/exposure to offensive security tools, not as a hard gate, so it is marked preferred.
Two compensation bands are given: $165,000–$225,000 for CA/WA/NY/NJ/CT and $146,000–$206,000 for all other US states. The lower floor and upper ceiling across both bands are reported.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.