6 hours ago
Remote, CanadaStaff+
Responsibilities
- Lead and continuously improve the enterprise AI security review process for AI tools, agentic/MCP systems, and AI features.
- Evaluate architectures, data flows, permissions, source code, system prompts, agent configurations, and tool-permission manifests.
- Threat model AI/LLM systems for prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
- Design and build AI security guardrails and tooling for permission boundaries, authentication and authorization, data handling, logging, monitoring, and policy-as-code.
- Create security-focused test cases, red-team scenarios, and evaluation processes for AI systems before launch.
- Evaluate AI capabilities in third-party SaaS vendors and make risk-based adoption recommendations.
- Identify emerging AI and agentic security vulnerabilities and contribute to AI-specific incident-response playbooks as a senior escalation point.
- Lead cross-functional initiatives and advise technical and executive stakeholders on AI security.
- Develop AI governance artifacts, including acceptable-use policies, data-handling standards, and vendor/model risk assessments.
Requirements
- Seasoned security engineering experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems and enterprise security controls.
- Practical experience threat modeling AI/LLM applications and securing agentic systems, MCP servers and clients, tool-permission models, and agent-to-tool trust boundaries.
- Experience creating AI governance artifacts and evaluating AI capabilities in SaaS platforms such as Notion AI, Slack AI, Google Workspace AI, and GitHub Copilot.
- Experience with AI visibility and control tools such as CASB and Okta, and with corporate systems including OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.
- Ability to build security tooling, guardrails, and detections with Python or similar technologies.
- Experience deploying cloud services and policy-as-code with Infrastructure as Code such as Terraform; familiarity with Kubernetes and AWS.
- Understanding of RAG, embeddings, fine-tuning, tool use, OAuth2, SAML, service accounts, non-human identities, application architecture, and threat modeling.
- Ability to lead cross-functional initiatives and communicate with technical and executive audiences.
- Experience in regulated environments such as SOC 2 and PCI DSS, and experience applying IAM to non-human or agent identities, are preferred.
Benefits
- Remote-first work arrangement limited to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan, with occasional in-person work possible and in-person onboarding for new hires.
- 100% subsidized medical coverage for employees and dependents, plus dental and vision coverage.
- Monthly technology, health, and wellness spending stipends.
- Flexible time off and generous holiday calendars.
- Employee stock purchase plan and potential equity rewards.
- Inclusive interview process with accommodations for candidates with disabilities.
Tech Stack
Categories
About Affirm
Affirm provides buy now, pay later installment financing at online and in-store checkout, along with a consumer app and virtual card, for shoppers and merchants. It monetizes through merchant fees and interest on select loans, with no late fees. Founded in 2012 and headquartered in San Francisco, Affirm is a public company listed on NASDAQ that powers payments for thousands of ecommerce retailers.
