Senior AI Security Engineer — Enterprise Guardrails & Risk

Affirm

Baltimore (MD)

On-site

USD 204,000 - 290,000

Full time

23 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health coverage 100% for you and your…
Monthly tech stipends and wellness
Flexible time off and holidays
ESPP – stock purchase plan

Job summary

Affim is seeking a seasoned security engineer to design, evaluate, and maintain security architecture for AI/LLM systems. You will lead enterprise AI security reviews, embed security into design, and collaborate across Security, Legal, Privacy, Compliance, IT, and Engineering.

The role requires threat modeling, governance artifacts, and hands-on tooling with Python, Terraform, Kubernetes, and AWS. Remote-first with flexible work arrangements and competitive pay.

Qualifications

  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

Responsibilities

  • You will lead and continuously improve Affim's enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.

Skills

Security architecture
Threat modeling
AI security
MCP servers/clients
Tool-calling frameworks
Python
IaC / Terraform
Kubernetes
AWS
OAuth2
SAML
Non-human IAM

Tools

Terraform
Kubernetes
AWS
Okta

Job description

Affim is seeking a seasoned security engineer to design, evaluate, and maintain security architecture for AI/LLM systems. You will lead enterprise AI security reviews, embed security into design, and collaborate across Security, Legal, Privacy, Compliance, IT, and Engineering.

The role requires threat modeling, governance artifacts, and hands-on tooling with Python, Terraform, Kubernetes, and AWS. Remote-first with flexible work arrangements and competitive pay.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI Security Engineer — Enterprise Guardrails
Senior AI Security Engineer — Enterprise Guardrails

Affirm • Chicago (IL)

On-site
USD 204,000 - 290,000
Health coverage for employee and their
Monthly tech stipends
Flexible time off
Senior AI Security Engineer — Enterprise & LLM
Senior AI Security Engineer — Enterprise & LLM

Affirm • Phoenix (AZ)

On-site
USD 204,000 - 264,000
Health coverage
Tech stipend
Flexible time off
+1
Senior AI Security Engineer — Enterprise AI Guardrails
Senior AI Security Engineer — Enterprise AI Guardrails

Affirm • Los Angeles (CA)

On-site
USD 204,000 - 290,000
Health coverage
Stipends for tech setup
Flexible time off
+1
Senior AI Security Engineer – Remote, Guardrails & Risk
Senior AI Security Engineer – Remote, Guardrails & Risk

Affirm • Boise (ID)

On-site
USD 204,000 - 264,000
Health coverage for dependents
Tech stipends
Flexible time off
+1
Remote-First AI Security Engineer — Enterprise Guardrails
Remote-First AI Security Engineer — Enterprise Guardrails

Affirm • Palo Alto (CA)

On-site
USD 230,000 - 290,000
Health coverage
Tech stipends
Flexible time off
+1
Staff AI Security Engineer — Enterprise & LLM Risk
Staff AI Security Engineer — Enterprise & LLM Risk

Affirm • Dallas (TX)

On-site
USD 204,000 - 290,000
Remote-first
100% health coverage for you and your?
Tech stipends
+2
Senior AI Security Engineer (Enterprise Systems)
Senior AI Security Engineer (Enterprise Systems)

Affirm • Sioux Falls (SD)

On-site
USD 204,000 - 264,000
Health coverage for you and dependents
Tech stipends
Generous time off
+1
Staff AI Security Engineer — Enterprise Guardrails
Staff AI Security Engineer — Enterprise Guardrails

Affirm • St. Louis (MO)

On-site
USD 204,000 - 264,000
Health coverage
Tech stipends
Flexible Time Off
+1
Senior AI Security Engineer - Enterprise & LLMs (Remote)
Senior AI Security Engineer - Enterprise & LLMs (Remote)

Affirm • Austin (TX)

On-site
USD 204,000 - 290,000
Health coverage for you and dependents
Tech stipends for setup
Flexible time off
+1
Staff AI Security Engineer — Enterprise LLM Safeguards
Staff AI Security Engineer — Enterprise LLM Safeguards

Affirm • Madison (WI)

Remote
USD 204,000 - 290,000
100% subsidized medical coverage
Monthly tech stipends
Flexible time off
+1