Назад
4 дня назад

Staff Product Security Engineer (AI)

204 000 - 264 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer (AI): Building and operating enterprise security reviews, guardrails, and controls for AI/LLM systems with an accent on threat modeling, agentic systems, and AI governance. Focus on designing permission boundaries, securing MCP and tool-calling architectures, automating policy enforcement with Python and IaC, and driving cross-functional remediation.

Location: Remote within the United States; occasional in-person work at an Affirm office and in-person onboarding may be required.

Base pay: $230,000–$290,000 per year in CA, WA, NY, NJ, and CT; $204,000–$264,000 per year in other U.S. states.

Company

Affirm provides transparent consumer payment solutions that allow people to pay over time without hidden fees.

What you will do

  • Lead and improve the enterprise AI security review process for internal AI tools, agentic systems, MCP-based systems, and AI features.
  • Threat model AI/LLM applications and data flows, identify risks such as prompt injection and excessive agency, and drive remediation.
  • Review source code, system prompts, agent configurations, and tool-permission manifests; help develop security tests and red-team scenarios.
  • Design and build AI security guardrails for permissions, authentication, authorization, data handling, logging, monitoring, and policy-as-code.
  • Evaluate AI capabilities in third-party SaaS platforms and support risk-based vendor adoption decisions.
  • Lead cross-functional AI security initiatives and contribute to AI-specific incident response playbooks.

Requirements

  • Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems.
  • Experience threat modeling AI applications and securing agentic systems, MCP servers and clients, and tool-calling frameworks.
  • Experience creating AI governance artifacts and evaluating AI capabilities in SaaS platforms.
  • Ability to build security tooling and guardrails with Python or similar and deploy cloud services using Terraform or comparable Infrastructure as Code.
  • Understanding of RAG, embeddings, fine-tuning, tool use, OAuth2, SAML, service accounts, and non-human identities.
  • Ability to lead initiatives across Security, Engineering, Legal, Privacy, and Compliance and communicate with technical and executive stakeholders.

Nice to have

  • Familiarity with Kubernetes and AWS.
  • Experience in regulated environments such as SOC 2 or PCI DSS.
  • Experience applying IAM to non-human and agent identities.

Culture & Benefits

  • Remote-first work model with flexibility within the country of employment.
  • 100% subsidized medical, dental, and vision coverage for employees and dependents.
  • Monthly technology, health, and wellness stipends.
  • Flexible time off and generous holiday calendars.
  • Employee stock purchase plan with discounted Affirm shares.

Hiring process

  • Inclusive interview process with accommodations available for candidates with disabilities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →