Staff Security Engineer (Enterprise AI)

Affirm

New York (NY)

Remote

USD 150,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote-first
Spending wallets
Supportive communities
Remote workforce
Generous time off
Health benefits
Mental health
Parental leave
Away days
Learning & development

Job summary

Affirm is seeking a security engineer to build and run the enterprise AI/LLM security review process. You will evaluate architecture, data flows, permissions, and guardrails to enable safe AI adoption across Security, Legal, Privacy, Compliance, IT, and Engineering.

You will threat model AI/LLM systems, review code and prompts, and design robust security controls. You will lead cross-functional initiatives and stay current on AI security trends to translate research into practical safeguards.

Qualifications

  • Experience threat modeling and reviewing AI/LLM apps against OWASP Top 10 for LLMs.
  • Ability to design and maintain security architecture for AI/LLM systems.
  • Experience in regulated environments (SOC 2, PCI DSS) and IAM for non-human identities is a plus.

Responsibilities

  • Build and run Affirm’s end-to-end security review process for enterprise AI/LLM systems.
  • Threat model data flows, architecture, and tool-permission boundaries; design controls and guardrails.
  • Review source code, prompts, agent configs, and tool manifests; build security-focused test cases and red-team scenarios.

Skills

Threat modeling AI/LLM
Security architecture
Cross-functional leadership
Incident response planning

Tools

Python
Terraform
Kubernetes
AWS
OAuth2
SAML

Job description

  • In this role, you’ll build and run Affirm’s end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let Affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable
  • You will lead and continuously improve Affirm’s enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls
Benefits
  • Compensation: We have a simple, flexible, and transparent remote-first compensation structure so you can make the best decisions for yourself and your family
  • Spending Wallets: Access tech, food, lifestyle, and family planning wallets for your expenses
  • Supportive Communities: Get involved with our employee resource groups and community groups
  • Remote-first Workforce: If your role is remote, you can set up shop anywhere in your home country
  • Generous Time Off: Take the time you need when life happens
  • Health Benefits: Get a plan that fits your needs
  • Mental Healthcare: Take care of your mind with great mental health programs
  • Parental Leave: Birth and non-birth parents get 18 weeks’ paid leave. Plus, a 4-week return-to-work transition program, at full base pay
  • Away Days: We offer 20 company-wide paid days off—which help our teams collectively pause to recharge
  • Learning & Development: Engage in exciting learning programs to level up your growth
You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentalsYou have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundariesYou can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plusYou have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviewsYou can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWSYou are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controlsYou have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security AI DevSecOps Engineer
Security AI DevSecOps Engineer

Regional Management Corp • Plano (TX)

Hybrid
USD 140,000 - 170,000
Gen AI Security Architect
Gen AI Security Architect

Envision Technology Solutions • United States

On-site
USD 120,000 - 170,000
AI Security Engineer
AI Security Engineer

TBG | The Bachrach Group • New York (NY)

Hybrid
USD 150,000 - 230,000
AI Information Security Engineer
AI Information Security Engineer

Tenable • Boston (MA)

Hybrid
USD 150,000 - 230,000
Health insurance
Hybrid or remote opportunities
Professional development and tuition
Senior AI Security Engineer - LLM/Agentic - Remote
Senior AI Security Engineer - LLM/Agentic - Remote

Affirm • Boston (MA)

On-site
USD 204,000 - 264,000
100% subsidized medical coverage
Tech stipends
Flexible time off
+1
Senior AI Security Engineer — Enterprise & LLM
Senior AI Security Engineer — Enterprise & LLM

Affirm • Phoenix (AZ)

On-site
USD 204,000 - 264,000
Health coverage
Tech stipend
Flexible time off
+1
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Atlanta (GA)

On-site
USD 140,000 - 210,000
Application & AI Security Engineer
Application & AI Security Engineer

Hydrogen Group • United States

On-site
USD 140,000 - 190,000
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

On-site
USD 120,000 - 150,000
Staff AI Security Engineer — Enterprise LLM Safeguards
Staff AI Security Engineer — Enterprise LLM Safeguards

Affirm • Madison (WI)

Remote
USD 204,000 - 290,000
100% subsidized medical coverage
Monthly tech stipends
Flexible time off
+1