Staff Product Security Engineer

Posted Sep 15

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop and manage Affirm's comprehensive security review process for enterprise AI/LLM systems.

• Assess architecture, data flows, permissions, and designs of internal AI tools, agentic/MCP-based systems, and AI features.

• Integrate security requirements during the design phase of AI systems.

• Conduct threat modeling for AI/LLM systems and data flows, focusing on prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure.

• Lead the remediation of detected risks.

• Analyze source code, system prompts, agent configurations, and tool/permission manifests such as MCP definitions.

• Assist tool owners in developing security-oriented test cases and red-team evaluation scenarios.

• Design and implement AI security guardrails and tooling for permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code.

• Evaluate third-party SaaS AI capabilities during vendor and SaaS security assessments.

• Propel risk-based decisions regarding AI adoption.

• Identify and address emerging security vulnerabilities related to AI/agentic systems.

• Contribute to AI-specific incident response playbooks as a senior escalation resource.

• Lead cross-functional AI security initiatives collaborating with Security, Legal, Privacy, Compliance, IT, and Engineering teams.

• Serve as an internal subject-matter expert to provide guidance to technical and executive stakeholders.

• Keep abreast of the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and translate research findings into actionable controls.


⛳️ Requirements

• Practical experience in designing, evaluating, and maintaining security architecture for AI/LLM-based systems.

• Extensive expertise in enterprise security systems, processes, and controls.

• Hands-on experience in threat modeling and reviewing AI/LLM applications, including OWASP Top 10 for LLM Applications.

• Knowledge in securing agentic systems and tool-calling frameworks, including MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.

• Experience in creating AI governance documentation, such as acceptable use policies, data-handling standards, and vendor/model risk assessments.

• Familiarity with evaluating AI capabilities within SaaS platforms as part of vendor assessments.

• Proficiency with enterprise AI visibility and control tools like CASB and IdP/Okta.

• Familiarity with tools such as OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.

• Capability to develop security tooling, guardrails, and detections using Python or similar languages.

• Experience deploying cloud services and policy-as-code utilizing Infrastructure as Code methodologies, such as Terraform.

• Knowledge of Kubernetes and AWS.

• Understanding of LLM and agentic-system concepts, including RAG, embeddings, fine-tuning, and tool usage.

• Comprehension of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling.

• Ability to lead cross-functional initiatives and effectively communicate with both technical and executive audiences.

• Experience in regulated environments, such as SOC 2 and PCI DSS, is advantageous.

• Familiarity with applying IAM to non-human/agent identities is a plus.


🏝️ Benefits

• Base pay may include equity rewards.

• Monthly stipends for health, wellness, and technology expenses.

• 100% subsidized medical coverage, including dental and vision for employees and their dependents.

• Health coverage at no cost: 100% of premiums covered for employees and dependents.

• Flexible time off policy.

• Generous holiday calendar.

• Employee stock purchase plan (ESPP) allowing purchase of Affirm stock at a discounted rate.

• Inclusive interview process with accommodations for candidates with disabilities.

• Remote-first flexibility; most roles can be performed from virtually anywhere within the country of employment.

• In-person onboarding experience for all new hires.

People also viewed

Alcoa12 hours ago

Senior Cybersecurity Specialist

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
McKesson12 hours ago

Senior Product Security Engineer – AI, DevSecOps

US flagKansas, +2 more statesFull-timeCybersecurity / Security Engineer$140.3k – $233.8k/year
ApplyView job
Zillow12 hours ago

Director, Application Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$220.2k – $351.8k/year
ApplyView job
Truelogic Software12 hours ago

AI Security Engineer – Offensive Security Engineer

DO flagDominican Republic OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Truelogic Software12 hours ago

AI Security Engineer – Offensive Security Engineer

Latin AmericaFull-timeCybersecurity / Security Engineer
ApplyView job
Truelogic Software12 hours ago

AI Security Engineer / Offensive Security Engineer – Technology

CO flagColombia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers