Affirm

Sr. Security Operations Engineer, Incident Response

Affirm$150K — $200K *
US-AnywhereRemote in Canada
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in Security Operations or Detection & Response, particularly in cloud environments (AWS, EKS preferred)
  • Proven track record of leading security incidents, including response and remediation
  • Strong investigative and analytical skills, synthesizing data from multiple sources
  • Experience with security tools like SIEM and EDR platforms (e.g., Splunk, Elastic)
  • Solid understanding of cloud security concepts in practical scenarios
  • Excellent communication skills for diverse audiences
  • Experience in improving automation for incident response workflows (scripting in Python is a plus)

Responsibilities

  • Lead and execute incident response efforts covering all phases from detection to resolution
  • Act as incident commander during high-pressure security situations
  • Conduct hands-on investigations in cloud and endpoint environments
  • Collaborate with Observability & Automation to enhance detection and build automated response playbooks
  • Refine incident response playbooks and documentation for consistency
  • Work with Security, Infrastructure, and Product teams to identify gaps in the incident response lifecycle
  • Provide clear updates during incidents to both technical and non-technical stakeholders

Benefits

  • 100% subsidized medical, dental, and vision coverage for employees and dependents
  • Generous stipends for Technology, Food, Lifestyle needs, and family forming expenses
  • Competitive vacation and holiday schedules
  • Employee stock purchase plan (ESPP) with discounts on Affirm shares
Full Job Description
We9re seeking a Senior Security Operations Engineer to join the Incident Response function within the broader Security Operations & Resilience org. In this role, you9ll be a hands-on practitioner and technical contributor who drives incident response efforts from triage through resolution - with the depth, ownership, and composure to lead when it matters most.

This is a highly technical, execution-focused role where you9ll lead hands-on investigations and drive incident response from detection through remediation. You9ll collaborate across engineering, product, and infrastructure teams, and partner with Observability & Automation to improve detections, build automated playbooks, and strengthen our security posture. You will have the opportunity to help solve complex security challenges and build capabilities that protect millions of customers, merchants, and partners.

What you9ll do

You will lead and execute incident response efforts to protect Affirm9s systems, customers, and data.
  • Lead security incidents end-to-end, from detection and triage through containment, remediation, and post-incident review.
  • Act as incident commander, driving clear decisions and alignment across teams during high-pressure situations.
  • Conduct hands-on investigations across cloud and endpoint environments to determine root cause and impact.
  • Partner with Observability & Automation to improve detections, reduce noise, and build automated response playbooks.
  • Contribute to and refine incident response playbooks, runbooks, and documentation to improve readiness and consistency.
  • Collaborate with Security, Infrastructure, and Product teams to identify gaps and strengthen the incident response lifecycle.
  • Communicate effectively during incidents, providing clear updates to both technical and non-technical stakeholders.

What we look for

We9re looking for a hands-on security engineer who can lead through ambiguity and drive effective incident response outcomes.
  • 5+ years of experience in Security Operations or Detection & Response, with strong hands-on incident response in cloud environments (AWS and EKS experience strongly preferred).
  • Proven ability to lead security incidents, including containment and remediation, in fast-moving environments.
  • Strong investigative and analytical skills, with the ability to synthesize signals from multiple data sources.
  • Experience with security tooling such as SIEM and EDR platforms (e.g., Splunk, Elastic, SentinelOne, CrowdStrike, or similar).
  • Solid understanding of cloud security concepts and their application in real-world scenarios.
  • Strong communication skills, with the ability to clearly convey information across technical and non-technical audiences.
  • Experience building or improving automation for incident response workflows (e.g., scripting in Python; infrastructure-as-code is a plus).


Location - Remote CAN

Pay Grade - N
Equity Grade - 6

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. For sales roles, the range provided is the role9s On Target Earnings (4OTE4) range, which includes the annual base pay and the sales incentive target.

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

Base pay range per year: $150,000 - $200,000 CAD

#LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We9re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

About Affirm

Affirm is a publicly traded financial technology company headquartered in San Francisco, United States. Founded in 2012, the company operates as a financial lender of installment loans for consumers to use at the point of sale to finance a purchase. Affirm was founded in 2012 by Max Levchin, Nathan Gettings, Jeffrey Kaditz, and Alex Rampell as part of the initial portfolio of startup studio HVF. Levchin, who co-founded PayPal, became CEO of Affirm in 2014. In October 2017, the company launched a consumer app that allowed loans for purchases at any retailer. The company announced a partnership with Walmart in February 2019. Under the partnership, Affirm is available to customers in-store and on the Walmart website. Affirm has partnered with e-commerce platforms including Shopify, BigCommerce, and Zen-Cart. On November 18, 2020, Affirm filed with the Securities and Exchange Commission in preparation for an initial public offering. On December 12, 2020, it was reported that Affirm had postponed its IPO. On January 13, 2021, Affirm became listed on NASDAQ with symbol AFRM, raising about $1.2 billion in its IPO. By the next day, the price of shares had doubled, making Levchin's stake worth about $2.5 billion. In May 2021, Affirm acquired Returnly, a financial technology service company, for $300 million.
Learn more about Affirm
Size
1,300 employees
Market Cap
$2.5 billion
Industry
Net Income
-$97.6 million
Founded
2012
Revenue
$617.1 million
NASDAQ

Similar Jobs

More Jobs at Affirm

More Information Technology Jobs

Find similar Sr. Security Operations Engineer, Incident Response jobs: