Staff Product Security Engineer building AI/LLM security reviews, guardrails, and threat models at Affirm, a buy-now-pay-later company. Leading cross-functional security initiatives across enterprise systems.
Responsibilities
Lead and continuously improve Affirm’s enterprise AI security review process
Evaluate architectures, data flows, permissions, and designs of internal AI tools, agentic/MCP-based systems, and AI features
Embed security requirements into the design phase
Threat model AI/LLM systems and data flows for prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure
Drive remediation of identified risks
Review source code, system prompts, agent configurations, and tool/permission manifests
Help tool owners develop security-focused test cases and red-team/evaluation scenarios
Design and build security guardrails and tooling for AI systems, permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code
Evaluate third-party SaaS AI capabilities during vendor and SaaS security reviews
Identify emerging AI/agentic security vulnerabilities and develop mitigations
Contribute to AI-specific incident response playbooks as a senior escalation point
Lead cross-functional AI security initiatives to closure
Advise technical and executive stakeholders as an internal point of expertise
Monitor the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and translate research into practical controls
Requirements
Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems
Deep expertise in enterprise security systems, processes, and controls
Practical experience threat modeling and reviewing AI/LLM applications
Experience securing agentic systems and tool-calling frameworks, including MCP servers/clients and tool-permission models
Experience building AI governance artifacts and evaluating AI capabilities within SaaS platforms
Experience with enterprise tools for AI visibility and control, such as CASB and Okta
Experience with corporate systems including OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira
Ability to build security tooling, guardrails, and detections with Python or similar
Experience deploying cloud services and policy-as-code using Terraform or similar Infrastructure as Code
Familiarity with Kubernetes and AWS
Understanding of LLM and agentic-system concepts including RAG, embeddings, fine-tuning, and tool use
Understanding of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling
Ability to lead cross-functional initiatives and communicate with technical and executive audiences
Experience in regulated environments such as SOC 2 and PCI DSS is a plus
Experience applying IAM to non-human/agent identities is a plus
Must reside in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan
Benefits
Monthly stipends for health, wellness and tech spending
100% subsidized medical coverage for employees and dependents
Dental and vision coverage for employees and dependents
Flexible time off
Generous holiday calendars
Employee stock purchase plan (ESPP) with discounted Affirm stock
Remote-first flexibility
In-person onboarding experience
Inclusive interview process and accommodations for candidates with disabilities
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.