Staff Security Engineer, Enterprise AI

Affirm

Chicago (IL)

Remote

USD 195,000 - 280,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health coverage
Stipends for tech setup
Flexible time off

Job summary

Affirm seeks a seasoned security engineer to design and oversee security architecture for AI/LLM systems, ensuring secure data flows, prompts, and tool permissions from design to deployment.

You will build guardrails, threat models, and policy-as-code, collaborating with Legal, Privacy, Compliance, IT and Engineering to scale risk-aware AI adoption. Remote-first in the US with strong compensation and benefits.

Qualifications

  • Experience designing, evaluating, and maintaining security architecture for AI/LLM systems.

Responsibilities

  • Lead enterprise AI security review process evaluating architecture and data flows, and embed security requirements into design stages.
  • Threat model AI/LLM systems and data flows for risks and remediation.
  • Review source code, prompts, configurations, and tool manifests; help build security-focused test cases and eval scenarios.
  • Design and build guardrails and tooling for AI systems permission boundaries, authn/authz, data handling, logging, and policy-as-code.

Skills

Security engineer
Threat modeling
AI/LLM security
Enterprise security
Code review
Python
Terraform
Kubernetes
AWS
OAuth2
SAML

Tools

Notion AI
Slack AI
Google Workspace AI
GitHub Copilot
CASB
IDP/Okta
OpenAI
Anthropic
GitHub
Jira

Job description

At affirm we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

The InfoSec team protects affirm's systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence.

In this role, you'll build and run affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable.

What you'll do
  • You will lead and continuously improve affirm's enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.
What we look for
  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

Base Pay Grade - P

Equity Grade - 13

Employees new to affirm typically come in at the start of the pay range.Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA base pay range (CA, WA, NY, NJ, CT) per year: $220,000 - $280,000

USA base pay range (all other U.S. states) per year: $195,000 - $255,000

Remote-first with flexibility built inAffirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for youOur benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Engineer, Enterprise AI
Staff Security Engineer, Enterprise AI

Affirm • United States

Remote
USD 204,000 - 290,000
Health coverage for you and dependents
Remote-first with flexibility
Stock purchase plan
Staff Product Security Engineer
Staff Product Security Engineer

Affirm • New York (NY)

On-site
USD 230,000 - 290,000
Health coverage for employees and deps
Monthly tech and wellness stipends
Flexible time off
+1
Staff CIAM Software Engineer
Staff CIAM Software Engineer

Affirm • Austin (TX)

On-site
USD 204,000 - 264,000
Health coverage
Flexible Spending Wallets
Time off
+1
Staff CIAM Software Engineer
Staff CIAM Software Engineer

Affirm • Atlanta (GA)

On-site
USD 204,000 - 264,000
Health care coverage
ESPP - stock purchase plan
Time off
+1
Senior Software Engineer, Backend (Lake Analytics Platform)
Senior Software Engineer, Backend (Lake Analytics Platform)

Affirm • St. Louis (MO)

On-site
USD 173,000 - 233,000
Health care coverage
Flexible Spending Wallets
Time off
+1
Security Risk Management Lead
Security Risk Management Lead

Affirm • Salt Lake City (UT)

On-site
USD 146,000 - 225,000
100% subsidized medical coverage
Generous stipends for wellness and technology
Competitive vacation and holiday schedules
+1
Analyst
Analyst

Free resume • Northern (KY)

Hybrid
USD 101,000 - 165,000
Health coverage and wellness stipends
Remote-first with flexible in-persons
Security Risk Management Lead
Security Risk Management Lead

Affirm • Los Angeles (CA)

On-site
USD 165,000 - 225,000
Health care coverage
Flexible Spending Wallets
Competitive time off
+1
Security Risk Management Lead
Security Risk Management Lead

Affirm • Houston (TX)

On-site
USD 146,000 - 206,000
Health care coverage
Flexible Spending Wallets
Competitive vacation and holiday schedules
+1
Security Risk Management Lead
Security Risk Management Lead

Affirm • Portland (OR)

On-site
USD 146,000 - 225,000
Health care coverage
Flexible Spending Wallets
Time off
+1