Open Role
Affirm

Remote opportunity at

Affirm

Staff Security Engineer, Enterprise AI

Affirm is a financial services organization that offers transparent payment alternatives over time with absence of hidden costs or surprises. The Information Security division aims to…

View Company

Role Snapshot

Hiring Now

Remote from

Remote

Salary

Undisclosed

Department

General

Employment

Full-time

Experience

Not specified

Published16d ago
Listing Views18
Applications0
Apply BeforeNo deadline

Career Tools

About This Role

Affirm is a financial services organization that offers transparent payment alternatives over time with absence of hidden costs or surprises. The Information Security division aims to safeguard company systems against emerging threats, managing risk, handling vulnerability tracking, enforcing safeguards, and steering compliance and identity management. Within this setting, the organization seeks a Staff Security Engineer, Enterprise AI to spearhead the end-to-end security review process for artificial intelligence and large language…

Job Description

Affirm is a financial services organization that offers transparent payment alternatives over time with absence of hidden costs or surprises. The Information Security division aims to safeguard company systems against emerging threats, managing risk, handling vulnerability tracking, enforcing safeguards, and steering compliance and identity management. Within this setting, the organization seeks a Staff Security Engineer, Enterprise AI to spearhead the end-to-end security review process for artificial intelligence and large language model systems. This remote position suits an experienced security professional capable of assessing architectural designs, prioritizing AI-specific threats, and establishing protective controls that enable safe adoption.

The person in this function will evaluate internal tools, agent-based frameworks, and AI features to embed security protocols into the design phase. Daily duties include threat modeling against potential risks like prompt injection, excessive agency, and sensitive data exposure, alongside reviewing source code, agent setups, and tool configurations. Additionally, the engineer will create automated guardrails using Python and infrastructure as code, appraise third-party SaaS vendor capabilities, and collaborate across multidisciplinary groups including Legal, Privacy, Compliance, IT, and Engineering. The role is open to applicants residing in specific Canadian provinces including Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.

Responsibilities

  • Manage and continuously enhance the end-to-end security review process for corporate artificial intelligence systems.
  • Evaluate architecture, permissions, and data flows of internal AI tools and agentic frameworks during the design phase.
  • Perform threat modeling on large language models to address prompt injection, excessive agency, data poisoning, and sensitive data exposure.
  • Inspect source code, system prompts, agent setups, and tool definitions to assist owners in building security test scenarios.
  • Create and deploy security guardrails, access controls, logging, and policy-as-code using Python and Infrastructure as Code.
  • Assess artificial intelligence capabilities of third-party software vendors to guide adoption decisions.
  • Contribute to incident response playbooks and resolve emerging security vulnerabilities as a senior escalation point.

Requirements

  • Extensive background in designing, assessing, and maintaining security architecture for artificial intelligence and large language model systems.
  • Practical expertise in threat modeling and reviewing applications against established guidelines such as the OWASP Top 10 for LLM Applications.
  • Familiarity with securing agentic systems, Model Context Protocol servers, tool-permission structures, and trust boundaries.
  • Experience building corporate governance artifacts including acceptable use policies and risk assessments.
  • Proficiency in developing security tooling and detections using Python or similar languages.
  • Ability to deploy cloud services and policy-as-code using Terraform alongside familiarity with Kubernetes and AWS.

Qualifications

  • Background working in regulated environments maintaining standards such as SOC 2 or PCI DSS.
  • Experience applying identity and access management principles to non-human or machine identities.

Core Skills

Benefits

  • 100 percent subsidized medical, dental, and vision coverage for employees and their dependents.
  • Monthly stipends supporting technology setups, health, and wellness choices.
  • Flexible time off combined with generous holiday schedules.
  • Access to an employee stock purchase plan allowing discounted stock acquisition.

Frequently Asked Questions

Is this position remote?

Yes, this is a remote-first role, but it is restricted exclusively to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.

What is the employment type?

The posting specifies that this is a full-time position.

What is the salary range for this role?

The Canadian base pay range per year is between $173,000 and $233,000, determined by location, experience, and job-related skills.

What benefits are included?

Benefits include fully subsidized medical, dental, and vision coverage, monthly stipends for technology and wellness, flexible time off, and an employee stock purchase plan.

Sample Interview Questions

AI-generated questions tailored to this specific role — a preview of the full practice set.

Search similar jobs

Related Jobs

Affirm
AffirmPosted 16h ago
Full-timeRemoteUSD 164,000 - 245,000/yr
Affirm
AffirmPosted 2d ago
Affirm
AffirmPosted 2d ago
San FranciscoFull-timeRemote
Advertisement
320 × 50

Posted by Affirm

Source: Affirm

Affirm

Affirm

153Open Jobs
—No reviews yet
View Company Profile