Staff Red Team Engineer
Remote US
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
As a Staff Red Team Engineer, you will be part of Affirm's Security Team, joining a group of passionate and highly skilled individuals who enjoy solving security challenges and learning new skills. The team operates with a team-first mindset and is focused on redefining security in the fintech space.
You will collaborate with cross-functional teams across Affirm and lead key Security projects to bolster the security posture of Affirm. You will need a strong ability to analyze, parse, and correlate information against data from multiple sources and engineer solutions when needed.
What you’ll do
- Identify vulnerabilities and gaps in Affirm's products via penetration tests.
- Plan and execute adversarial red teaming engagements -- emulating real-world scenarios.
- Review historical vulnerability data to identify areas of weakness and attempt to exploit systems.
- Research critical CVEs/zero days and determine potential impact to Affirm.
- Continuously review environments to determine risks and facilitate remediations.
- Decompose large, cross-team projects into individual tasks -- managing scope across teams and driving project closure.
- Provide support to partner teams during security events.
- Enhance Affirm's brand by showcasing innovative techniques through publications and participation in industry events.
What we look for
- Strong familiarity with MacOS exploitation and malware development.
- Experience exploiting vulnerabilities in cloud-native environments
- A curious mind who likes to tinker with systems to see what breaks.
- Ability to organize datasets into actionable intelligence.
- Proven track record of discovering security vulnerabilities.
- A passion to stay on top of the latest web technology trends and security developments.
- Python & Kotlin experience a plus.
- Industry certifications like Offensive Security Certified Professional preferred.
Base Pay Grade - P
Equity Grade - 13
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA base pay range (CA, WA, NY, NJ, CT) per year: $225,000 - $275,000
USA base pay range (all other U.S. states) per year: $200,000 - $250,000
Location: Remote - US
#LI-Remote
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
ApplyJob Profile
Limited number of roles remain office-based Limited office-based roles Occasional office work required Remote US
Benefits/Perks100% subsidized medical 100% subsidized medical coverage Competitive benefits Competitive vacation Competitive vacation and holiday schedules Dental Dental and vision Dental and vision coverage Employee stock purchase plan Equity Equity rewards ESPP Flexible Spending Flexible Spending Wallets Generous stipends Health care coverage Inclusive interview experience Inclusive interview experience for all Monthly stipends Monthly stipends for health Remote-first company Subsidized medical coverage Tech spending Time off Transparent pay structure Vision Wellness Wellness and tech spending
Tasks- Identify vulnerabilities
- Manage cross-team projects
- Managing
- Plan and execute red teaming
- Research critical CVEs
- Review historical vulnerability data
- Showcase techniques in publications
- Support during security events
Benefits Cloud native environments Compensation Data analysis Fintech Kotlin MacOS exploitation Malware development Python Research REST Security Technology Web
Experience5 years
Education CertificationsOffensive Security Certified Professional
TimezonesAmerica/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9