Staff Product Security Engineer
Core
Lead and improve Affirm's end-to-end security review process for enterprise AI/LLM systems, including threat modeling, guardrail design, and vendor evaluation.
Role type
Staff Product Security Engineer (AI/LLM Security)
Builds
Security guardrails, tooling, and policy-as-code for AI/LLM systems; incident response playbooks.
Domain
Artificial Intelligence / Large Language Models (LLM) / Enterprise Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
AI/LLM security architecture design, threat modeling for agentic systems, security review of AI tools and SaaS vendors, Python development, Infrastructure as Code (Terraform), Kubernetes, AWS, OAuth2/SAML, RAG/embeddings/fine-tuning understanding, cross-functional leadership.
Preferred skills
Experience in regulated environments (SOC 2, PCI DSS), IAM for non-human/agent identities.
Technologies
Python, Terraform, Kubernetes, AWS, MCP servers, OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira, CASB, Okta, OWASP LLM Top 10, MITRE ATLAS.
Responsibilities
Lead enterprise AI security review process; threat model AI/LLM systems for risks like prompt injection and data poisoning; review source code and agent configurations; design security guardrails and policy-as-code; evaluate third-party SaaS vendor AI capabilities; identify emerging AI vulnerabilities; lead cross-functional AI security initiatives.
Seniority
Staff, hands-on IC with strategic leadership