
Staff Product Security Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Develop and manage Affirm's comprehensive security review process for enterprise AI/LLM systems.
• Assess architecture, data flows, permissions, and designs of internal AI tools, agentic/MCP-based systems, and AI features.
• Integrate security requirements during the design phase of AI systems.
• Conduct threat modeling for AI/LLM systems and data flows, focusing on prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure.
• Lead the remediation of detected risks.
• Analyze source code, system prompts, agent configurations, and tool/permission manifests such as MCP definitions.
• Assist tool owners in developing security-oriented test cases and red-team evaluation scenarios.
• Design and implement AI security guardrails and tooling for permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code.
• Evaluate third-party SaaS AI capabilities during vendor and SaaS security assessments.
• Propel risk-based decisions regarding AI adoption.
• Identify and address emerging security vulnerabilities related to AI/agentic systems.
• Contribute to AI-specific incident response playbooks as a senior escalation resource.
• Lead cross-functional AI security initiatives collaborating with Security, Legal, Privacy, Compliance, IT, and Engineering teams.
• Serve as an internal subject-matter expert to provide guidance to technical and executive stakeholders.
• Keep abreast of the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and translate research findings into actionable controls.
• Practical experience in designing, evaluating, and maintaining security architecture for AI/LLM-based systems.
• Extensive expertise in enterprise security systems, processes, and controls.
• Hands-on experience in threat modeling and reviewing AI/LLM applications, including OWASP Top 10 for LLM Applications.
• Knowledge in securing agentic systems and tool-calling frameworks, including MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
• Experience in creating AI governance documentation, such as acceptable use policies, data-handling standards, and vendor/model risk assessments.
• Familiarity with evaluating AI capabilities within SaaS platforms as part of vendor assessments.
• Proficiency with enterprise AI visibility and control tools like CASB and IdP/Okta.
• Familiarity with tools such as OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.
• Capability to develop security tooling, guardrails, and detections using Python or similar languages.
• Experience deploying cloud services and policy-as-code utilizing Infrastructure as Code methodologies, such as Terraform.
• Knowledge of Kubernetes and AWS.
• Understanding of LLM and agentic-system concepts, including RAG, embeddings, fine-tuning, and tool usage.
• Comprehension of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling.
• Ability to lead cross-functional initiatives and effectively communicate with both technical and executive audiences.
• Experience in regulated environments, such as SOC 2 and PCI DSS, is advantageous.
• Familiarity with applying IAM to non-human/agent identities is a plus.
• Base pay may include equity rewards.
• Monthly stipends for health, wellness, and technology expenses.
• 100% subsidized medical coverage, including dental and vision for employees and their dependents.
• Health coverage at no cost: 100% of premiums covered for employees and dependents.
• Flexible time off policy.
• Generous holiday calendar.
• Employee stock purchase plan (ESPP) allowing purchase of Affirm stock at a discounted rate.
• Inclusive interview process with accommodations for candidates with disabilities.
• Remote-first flexibility; most roles can be performed from virtually anywhere within the country of employment.
• In-person onboarding experience for all new hires.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.