Staff Security Engineer, Enterprise AIActive$220K–$280K

The opportunity

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

What you'll do

  • You will lead and continuously improve Affirm's enterprise AI security review: process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.

  • You will threat model AI/LLM-based systems and their data flows for risks: such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.

  • You will review source code, system prompts, agent configurations, and: tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.

  • You will design and build security guardrails and tooling for AI systems: permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.

  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g.,: Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.

  • You will identify emerging classes of AI/agentic security vulnerabilities,: develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.

What they're looking for

  • You will lead cross-functional AI security initiatives to closure, advise: technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.