Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Affirm

Staff Product Security Engineer

Affirm

. Build and run Affirm's end-to-end security review process for enterprise AI/LLM systems .

Posted 9/15/2026full-timeRemote • United StatesLead💰 $204,000 - $290,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and evaluating security architecture for AI/LLM systems, with a focus on threat modeling, risk management, and compliance in enterprise environments. Proficient in building security tooling and governance artifacts while leading cross-functional initiatives and communicating effectively with stakeholders.

Highest-signal resume keywords
AI Security Architecture DesignThreat Modeling for AI/LLM SystemsSecurity Tooling Development with PythonEnterprise AI Visibility Tools (CASB, IdP/Okta)Regulatory Compliance (SOC 2, PCI DSS)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Architecture for AI/LLM SystemsThreat ModelingSecurity Tooling DevelopmentPolicy-as-Code (Terraform)IAM for Non-Human IdentitiesData Handling StandardsAI Governance ArtifactsAgentic Systems SecurityCloud Services DeploymentOWASP Top 10 for LLM Applications
Soft Skills
Cross-Functional LeadershipEffective CommunicationStakeholder Advising
Tools & Technologies
KubernetesAWSOpenAIAnthropicGitHubGoogle WorkspaceSlackNotionJira
Industry Keywords
AI SecurityLLM SystemsVendor Risk AssessmentData PoisoningSensitive Data ExposureMCP Servers/ClientsApplication ArchitectureIncident Response PlaybooksEmerging AI VulnerabilitiesCompliance Standards

Tech Stack

Tools & technologies
AWSCloudKubernetesPythonTerraform

About the role

Key responsibilities & impact
  • Build and run Affirm's end-to-end security review process for enterprise AI/LLM systems
  • Evaluate architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features
  • Embed security requirements into the AI system design phase
  • Threat model AI/LLM systems and data flows for prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure
  • Drive remediation of identified risks
  • Review source code, system prompts, agent configurations, and tool/permission manifests such as MCP definitions
  • Help tool owners create security-focused test cases and red-team/evaluation scenarios
  • Design and build AI security guardrails and tooling for permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code
  • Evaluate third-party SaaS AI capabilities during vendor and SaaS security reviews
  • Drive risk-based AI adoption decisions
  • Identify emerging AI/agentic security vulnerabilities and develop mitigations
  • Contribute to AI-specific incident response playbooks as a senior escalation point
  • Lead cross-functional AI security initiatives across Security, Legal, Privacy, Compliance, IT, and Engineering
  • Advise technical and executive stakeholders as an internal subject-matter expert
  • Monitor the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and translate research into practical controls

Requirements

What you’ll need
  • Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems
  • Deep expertise in enterprise security systems, processes, and controls
  • Practical experience threat modeling and reviewing AI/LLM applications, including OWASP Top 10 for LLM Applications
  • Experience securing agentic systems and tool-calling frameworks, including MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries
  • Experience building AI governance artifacts, including acceptable use policies, data-handling standards, and vendor/model risk assessments
  • Experience evaluating AI capabilities within SaaS platforms as part of vendor reviews
  • Experience with enterprise AI visibility and control tools such as CASB and IdP/Okta
  • Familiarity with OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira
  • Ability to build security tooling, guardrails, and detections with Python or similar
  • Experience deploying cloud services and policy-as-code with Infrastructure as Code, such as Terraform
  • Familiarity with Kubernetes and AWS
  • Understanding of LLM and agentic-system concepts including RAG, embeddings, fine-tuning, and tool use
  • Understanding of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling
  • Ability to lead cross-functional initiatives and communicate with technical and executive audiences
  • Experience in regulated environments such as SOC 2 and PCI DSS is a plus
  • Experience applying IAM to non-human/agent identities is a plus

Benefits

Comp & perks
  • Base pay may include equity rewards
  • Monthly stipends for health, wellness and tech spending
  • 100% subsidized medical coverage, dental and vision for employees and dependents
  • Health coverage at no cost: 100% of premiums covered for employees and dependents
  • Flexible time off
  • Generous holiday calendars
  • Employee stock purchase plan (ESPP) to buy Affirm stock at a discount
  • Inclusive interview process and accommodations for candidates with disabilities
  • Remote-first flexibility; most roles can be done from almost anywhere within the country of employment
  • In-person onboarding experience for all new hires