Affirm

Staff Product Security Engineer

Affirm
Apply
6 hours ago
Remote, United StatesStaff+
H1B sponsor

Base Salary

$204k - $290k/yr

Responsibilities

  • Lead and continuously improve enterprise AI security reviews covering architecture, data flows, permissions, and design.
  • Threat model AI/LLM and agentic systems for prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure.
  • Review source code, system prompts, agent configurations, and MCP tool and permission manifests, and drive remediation.
  • Build AI security guardrails and tooling for permission boundaries, authentication and authorization, data handling, logging, monitoring, and policy-as-code.
  • Evaluate AI capabilities in third-party SaaS products and lead risk-based vendor and SaaS security decisions.
  • Identify emerging AI and agentic vulnerabilities, develop mitigations, and contribute to AI-specific incident response playbooks.
  • Lead cross-functional AI security initiatives and advise technical and executive stakeholders.

Requirements

  • Seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM systems and enterprise security controls.
  • Practical experience threat modeling and reviewing AI/LLM applications, securing agentic systems and tool-calling frameworks, and working with MCP servers, clients, and tool-permission models.
  • Experience creating AI governance artifacts such as acceptable-use policies, data-handling standards, and vendor or model risk assessments.
  • Experience evaluating AI capabilities in SaaS platforms such as Notion AI, Slack AI, Google Workspace AI, and GitHub Copilot.
  • Experience with AI visibility and control tools such as CASB and Okta, and familiarity with OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.
  • Ability to build security tooling, guardrails, and detections with Python or similar technologies and deploy cloud services and policy-as-code with Terraform or similar IaC tools.
  • Familiarity with Kubernetes and AWS, and understanding of RAG, embeddings, fine-tuning, tool use, OAuth2, SAML, service accounts, non-human identities, and machine-to-machine access.
  • Strong application-architecture and threat-modeling fundamentals, cross-functional leadership, and communication with technical and executive audiences.
  • Experience in regulated environments such as SOC 2 and PCI DSS and applying IAM to non-human or agent identities is a plus.

Benefits

  • Remote-first work arrangement with flexibility to work from almost anywhere within the country of employment, occasional office work for some positions, and in-person onboarding for new hires.
  • 100% subsidized medical coverage for employees and dependents, plus dental and vision coverage.
  • Monthly technology, health, and wellness stipends.
  • Flexible time off and generous holiday calendars.
  • Employee stock purchase plan with a discount.
  • Inclusive interview process with disability accommodations.
Affirm

About Affirm

1,001-5,000 employees

Affirm provides buy now, pay later installment financing at online and in-store checkout, along with a consumer app and virtual card, for shoppers and merchants. It monetizes through merchant fees and interest on select loans, with no late fees. Founded in 2012 and headquartered in San Francisco, Affirm is a public company listed on NASDAQ that powers payments for thousands of ecommerce retailers.

Contact me