SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer

Affirm - Remote - Remote - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 204,000 - 290,000 / annual

Affirm is seeking a Staff Product Security Engineer to build and lead the company's end-to-end security review process for enterprise AI and LLM systems. This role sits within the InfoSec team, which protects Affirm's systems and data from evolving threats through risk management, vulnerability monitoring, and protective controls. You will own the design and continuous improvement of Affirm's AI security review process, evaluating architecture, data flows, permissions, and design of internal AI tools, agentic systems (MCP-based), and AI features. You'll threat model AI/LLM-based systems for risks including prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, then drive remediation efforts. Key responsibilities include reviewing source code, system prompts, agent configurations, and tool/permission manifests; helping tool owners build security-focused test cases and red-team/eval scenarios; designing and building security guardrails and tooling for permission boundaries, authentication/authorization for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC); evaluating AI capabilities of third-party SaaS vendors (Notion, Slack, Google Workspace) as part of vendor security reviews; identifying emerging AI/agentic security vulnerabilities and developing mitigations; and leading cross-functional AI security initiatives to closure while advising technical and executive stakeholders. You will serve as an internal point of expertise on AI security, staying current on the landscape (OWASP LLM Top 10, MITRE ATLAS) and translating research into practical controls. You'll also contribute to AI-specific incident response playbooks as a senior escalation point. REQUIREMENTS: - Seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls - Practical experience threat modeling and reviewing AI/LLM applications (e.g., against OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks (MCP servers/clients, tool-permission models, agent-to-tool trust boundaries) - Experience building AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluating AI capabilities within SaaS platforms (Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews - Experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira) - Ability to build security tooling, guardrails, and detections with Python or similar; deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS - Understanding of how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals - Ability to lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure; communicate effectively with technical and executive audiences - Plus: Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities

Similar roles