Affirm is a consumer credit fintech processing $37 billion in annual payments for nearly 26 million users across the U.S., Canada, and the U.K. The company provides point-of-sale installment financing at checkout - online, in-store, and via digital wallets - built on machine-learning-driven underwriting and real-time integration with merchant systems. The attack surface is wide and high-stakes: transaction-level financial data at massive scale, API integrations across retail partners, fraud vectors inherent to credit origination, and the regulatory pressure that comes with operating as a lending platform across multiple jurisdictions.
The threat model is the standard fintech gauntlet - account takeover, synthetic identity fraud, API abuse, data exfiltration of PII and financial records, plus the compliance surface that spans PCI-DSS, SOC 2, and consumer lending regulations in three countries. Affirm's security teams operate at the intersection of fraud detection, infrastructure hardening, and application security, with the added complexity of protecting ML underwriting models from adversarial manipulation. Engineering domains include financial technology, underwriting systems, and point-of-sale integration stacks.
Founded in 2012, Affirm positions itself as an alternative to predatory credit products - no hidden fees, no compounding interest, transparent terms. Whether that mission translates into internal security culture or is just brand positioning is the kind of question worth asking in an interview. What's concrete is the scale: millions of active consumers, billions in annualized transaction volume, and a multi-country regulatory footprint that demands serious security engineering discipline.





