SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Product Security Engineer

Affirm - Remote - Remote - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 181,000 - 241,000 / annual

Affirm is seeking a Staff Product Security Engineer to lead and build the company's end-to-end security review process for enterprise AI and LLM systems. This is a high-impact role focused on securing AI adoption across the organization. You will own Affirm's AI security architecture and governance, including threat modeling AI/LLM-based systems for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure. You'll review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), helping tool owners build security-focused test cases and red-team/eval scenarios before launch. Key responsibilities include: - Leading and continuously improving the enterprise AI security review process, evaluating architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features - Threat modeling AI/LLM systems and driving remediation of identified risks - Designing and building security guardrails and tooling for AI systems, including permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) - Evaluating AI capabilities of third-party SaaS vendors (Notion, Slack, Google Workspace) as part of vendor security reviews - Identifying emerging AI/agentic security vulnerabilities and developing mitigations before they become incidents - Leading cross-functional AI security initiatives across Security, Legal, Privacy, Compliance, IT, and Engineering - Serving as an internal point of expertise on AI security landscape (OWASP LLM Top 10, MITRE ATLAS) You'll work closely with Security, Engineering, Legal, Privacy, and Compliance teams to make AI security scalable and repeatable across the organization. REQUIREMENTS: - Seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems - Deep expertise in enterprise security systems, processes, and controls - Practical experience threat modeling and reviewing AI/LLM applications (e.g., against OWASP Top 10 for LLM Applications) - Experience securing agentic systems and tool-calling frameworks (MCP servers/clients, tool-permission models, agent-to-tool trust boundaries) - Experience building AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) - Experience evaluating AI capabilities within SaaS platforms (Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews - Experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) - Familiarity with corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira) - Ability to build security tooling, guardrails, and detections with Python or similar - Experience deploying cloud services and policy-as-code using Infrastructure as Code (Terraform or similar) - Familiarity with Kubernetes and AWS - Understanding of how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) - Strong knowledge of authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access - Strong application-architecture and threat-modeling fundamentals - Ability to lead cross-functional initiatives and drive them to closure - Effective communication with technical and executive audiences - Plus: Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities

Similar roles