Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Product Security Engineer (AI): Building and operating enterprise security reviews, guardrails, and controls for AI/LLM systems with an accent on threat modeling, agentic systems, and AI governance. Focus on designing permission boundaries, securing MCP and tool-calling architectures, automating policy enforcement with Python and IaC, and driving cross-functional remediation.
Location: Remote within the United States; occasional in-person work at an Affirm office and in-person onboarding may be required.
Base pay: $230,000–$290,000 per year in CA, WA, NY, NJ, and CT; $204,000–$264,000 per year in other U.S. states.
Company
Affirm provides transparent consumer payment solutions that allow people to pay over time without hidden fees.
What you will do
- Lead and improve the enterprise AI security review process for internal AI tools, agentic systems, MCP-based systems, and AI features.
- Threat model AI/LLM applications and data flows, identify risks such as prompt injection and excessive agency, and drive remediation.
- Review source code, system prompts, agent configurations, and tool-permission manifests; help develop security tests and red-team scenarios.
- Design and build AI security guardrails for permissions, authentication, authorization, data handling, logging, monitoring, and policy-as-code.
- Evaluate AI capabilities in third-party SaaS platforms and support risk-based vendor adoption decisions.
- Lead cross-functional AI security initiatives and contribute to AI-specific incident response playbooks.
Requirements
- Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems.
- Experience threat modeling AI applications and securing agentic systems, MCP servers and clients, and tool-calling frameworks.
- Experience creating AI governance artifacts and evaluating AI capabilities in SaaS platforms.
- Ability to build security tooling and guardrails with Python or similar and deploy cloud services using Terraform or comparable Infrastructure as Code.
- Understanding of RAG, embeddings, fine-tuning, tool use, OAuth2, SAML, service accounts, and non-human identities.
- Ability to lead initiatives across Security, Engineering, Legal, Privacy, and Compliance and communicate with technical and executive stakeholders.
Nice to have
- Familiarity with Kubernetes and AWS.
- Experience in regulated environments such as SOC 2 or PCI DSS.
- Experience applying IAM to non-human and agent identities.
Culture & Benefits
- Remote-first work model with flexibility within the country of employment.
- 100% subsidized medical, dental, and vision coverage for employees and dependents.
- Monthly technology, health, and wellness stipends.
- Flexible time off and generous holiday calendars.
- Employee stock purchase plan with discounted Affirm shares.
Hiring process
- Inclusive interview process with accommodations available for candidates with disabilities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Application Security Engineer (AI)
111 000 - 144 400$
Cohere
8 дней назад
Senior Product Security Engineer (AI)
260 000 - 385 000CAD
10 дней назад
Security Engineer (AI)
150 000 - 180 000$
9 дней назад
Senior Cloud Security Engineer (Fintech)
170 000 - 225 000$
10 дней назад
Product Security Engineer (AI)
145 300 - 244 850$
Contentsquare
7 дней назад