
Staff Product Security Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Canada.
• Oversee and enhance Affirm’s enterprise AI security review procedures.
• Assess architectures, data flows, permissions, and designs associated with internal AI tools, agentic/MCP-based systems, and AI functionalities.
• Integrate security requirements into the design phase effectively.
• Conduct threat modeling for AI/LLM systems and data flows, focusing on risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive data exposure.
• Lead the remediation efforts for identified risks.
• Examine source code, system prompts, agent configurations, and tool/permission manifests.
• Assist tool owners in developing security-centric test cases and red-team/evaluation scenarios.
• Create and implement security guardrails and tools for AI systems, including permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code.
• Assess third-party SaaS AI capabilities during vendor and SaaS security evaluations.
• Identify new AI/agentic security vulnerabilities and formulate mitigations.
• Contribute to AI-specific incident response playbooks as a senior escalation resource.
• Drive cross-functional AI security initiatives to completion.
• Provide guidance to technical and executive stakeholders as a trusted internal expert.
• Keep abreast of the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and convert research findings into actionable controls.
• Practical experience in designing, assessing, and maintaining security architecture for AI/LLM-based systems.
• Profound knowledge of enterprise security systems, processes, and controls.
• Hands-on experience with threat modeling and reviewing AI/LLM applications.
• Familiarity with securing agentic systems and tool-calling frameworks, including MCP servers/clients and tool-permission models.
• Experience in creating AI governance artifacts and assessing AI capabilities within SaaS platforms.
• Proficiency with enterprise tools for AI visibility and control, such as CASB and Okta.
• Experience with corporate systems like OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.
• Capability to develop security tools, guardrails, and detections using Python or similar programming languages.
• Experience in deploying cloud services and policy-as-code with Terraform or similar Infrastructure as Code solutions.
• Familiarity with Kubernetes and AWS environments.
• Understanding of LLM and agentic-system concepts, including RAG, embeddings, fine-tuning, and tool usage.
• Knowledge of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling.
• Aptitude for leading cross-functional initiatives and effectively communicating with both technical and executive audiences.
• Experience in regulated environments such as SOC 2 and PCI DSS is an advantage.
• Experience applying IAM to non-human/agent identities is also a plus.
• Candidates must reside in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.
• Monthly stipends for health, wellness, and technology expenses.
• Comprehensive medical coverage for employees and their dependents at no cost.
• Dental and vision insurance for employees and their dependents.
• Flexible time off policies.
• Generous holiday schedules.
• Employee stock purchase plan (ESPP) with discounted Affirm stock options.
• Remote-first work flexibility.
• In-person onboarding experience.
• Inclusive interview process with accommodations for candidates with disabilities.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.