Staff Product Security Engineer

Affirm
Canada
Workplace: RemoteFull timeCAD 181,000 - 241,000 annuallyFunction: CybersecuritySkills: ["Cross-functional leadership","Effective communication","Stakeholder advisory"]

Build and run an enterprise AI security review process for AI/LLM systems, evaluating architecture, data flows, permissions, and design for internal AI tools and agentic/MCP-based systems. Threat model AI risks (e.g., prompt injection, tool-permission abuse, data poisoning), review code and configurations, and drive remediation. Design guardrails and policy-as-code with Python and Infrastructure as Code, support vendor SaaS security reviews, and serve as a senior escalation point for AI security incidents.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Affirm
Affirm
16 hours ago

Staff Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live
Reposted: similar role first listed 5 months ago

Job Summary

Build and run an enterprise AI security review process for AI/LLM systems, evaluating architecture, data flows, permissions, and design for internal AI tools and agentic/MCP-based systems. Threat model AI risks (e.g., prompt injection, tool-permission abuse, data poisoning), review code and configurations, and drive remediation. Design guardrails and policy-as-code with Python and Infrastructure as Code, support vendor SaaS security reviews, and serve as a senior escalation point for AI security incidents.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Lead and continuously improve an enterprise AI security review process for internal AI tools and agentic/MCP-based systems, embedding security requirements into the design phase.
  • •Threat model AI/LLM systems and data flows, identifying risks like prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • •Review source code, system prompts, agent configurations, and tool/permission manifests, and help tool owners build security test cases and red-team/eval scenarios for verification before launch.
  • •Design and build AI security guardrails and tooling for permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code enforcement.
  • •Evaluate third-party SaaS AI capabilities in vendor security reviews, identify emerging AI/agentic vulnerabilities, contribute to AI incident response playbooks, and lead cross-functional initiatives to closure.

Pay and Benefits

Salary: CAD 181,000 - 241,000 annually
Equity and Bonus:Equity
Perks:Medical CoverageDentalVisionTech StipendsEspp

Key Requirements

  • •Seasoned security engineer experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems.
  • •Hands-on threat modeling and reviewing AI/LLM applications, including applying concepts like OWASP LLM Top 10, and securing agentic systems and tool-calling frameworks.
  • •Experience building AI governance artifacts such as acceptable use policies, data-handling standards, and vendor/model risk assessments.
  • •Experience with enterprise security tooling and identity/access systems (e.g., CASB, IDP/Okta) and familiarity with platforms where AI is adopted.
  • •Ability to build security tooling and guardrails using Python or similar, and deploy cloud services and policy-as-code via Infrastructure as Code (e.g., Terraform), with familiarity with Kubernetes and AWS.
Skills:Cross-functional leadershipEffective communicationStakeholder advisory
Languages:English
Tech Stack:PythonIaCTerraformKubernetesAWSOAuth2SAMLOAuthRAGEmbeddingsFine-tuningPolicy-as-codeOWASP LLM Top 10MITRE ATLASCASBOktaOpenAIAnthropicGitHubGoogle Workspace

Company Brief

Affirm
Provides point-of-sale lending and buy-now-pay-later (BNPL) solutions for consumers and merchants, enabling installment payments, consumer financing, and embedded financial services through APIs and partnerships with retailers and platforms.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn