Назад
8 дней назад

Staff Product Security Engineer (AI)

181 000 - 241 000CAD
Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer (AI): Building and operating enterprise AI/LLM security reviews, threat models, and automated guardrails for internal AI tools, agentic systems, and third-party SaaS with an accent on architecture, data flows, permissions, and AI-specific vulnerabilities. Focus on designing policy-as-code controls, securing MCP and agent-to-tool boundaries, creating red-team evaluations, and driving cross-functional remediation.

Location: Remote within Canada, limited to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan

Base pay: 181,000–241,000 CAD per year, plus potential equity, stipends, and benefits.

Company

Affirm provides transparent buy-now-pay-later payment solutions and operates a fintech platform.

What you will do

  • Lead and continuously improve the enterprise AI security review process for internal AI tools, agentic systems, MCP-based systems, and AI features.
  • Threat model AI/LLM systems and data flows, identify risks such as prompt injection, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • Review source code, system prompts, agent configurations, and tool-permission manifests, and help create security tests, red-team scenarios, and evaluations.
  • Design and build AI security guardrails and tooling for permission boundaries, authentication and authorization, data handling, logging, monitoring, and policy-as-code.
  • Evaluate AI capabilities in third-party SaaS platforms and support risk-based vendor adoption decisions.
  • Lead cross-functional AI security initiatives, advise technical and executive stakeholders, and contribute to AI-specific incident response playbooks.

Requirements

  • Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems and enterprise security controls.
  • Practical experience threat modeling AI applications and securing agentic systems, MCP servers and clients, tool-permission models, and agent-to-tool trust boundaries.
  • Experience building AI governance artifacts and evaluating AI capabilities in SaaS platforms such as Notion, Slack, Google Workspace, or GitHub Copilot.
  • Ability to build security tooling with Python or similar and deploy cloud services and policy-as-code with Terraform or comparable Infrastructure as Code.
  • Understanding of RAG, embeddings, fine-tuning, tool use, OAuth2, SAML, service accounts, non-human identities, and machine-to-machine access.
  • Must reside in one of the eligible Canadian provinces listed above.

Nice to have

  • Familiarity with Kubernetes, AWS, CASB, Okta, OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira.
  • Experience in regulated environments such as SOC 2 or PCI DSS.
  • Experience applying IAM to non-human or agent identities.

Culture & Benefits

  • Remote-first work with flexibility within the country of employment.
  • Occasional in-person work or onboarding may be required.
  • 100% subsidized medical, dental, and vision coverage for employees and dependents.
  • Monthly technology, health, and wellness spending stipends.
  • Flexible time off, generous holiday calendars, and an employee stock purchase plan.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →