Staff Product Security Engineer

Affirm

Confirmed live today High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$230,000–$290,000 / yr
Posted
9 days ago
Freshness
Confirmed live today

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $184k
This role $260k
$113k most similar roles pay here $309k

This role pays more than 96% of similar roles. Most pay $151,475–$216,000 — the shaded band above. At the midpoint, this role pays about $260k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About Affirm

Affirm is a buy-now, pay-later (BNPL) financial technology company that offers point-of-sale installment loans to consumers, allowing them to split purchases into fixed monthly payments with transparent terms. Industry: Financial Technology & Consumer Lending

Affirm currently has 56 open roles on FindRole.

Listed pay typically runs $195,000–$255,000 across 56 roles with salary data.

Most-posted roles

View all roles at Affirm

At a glance

TL;DR · Staff Product Security Engineer

Staff Product Security Engineer joins the InfoSec team to build and manage the end-to-end security review process for enterprise AI and LLM systems. This role involves evaluating architectures, data flows, and permissions while designing guardrails and policy-as-code to ensure safe adoption of agentic systems and tool-calling frameworks. You will perform threat modeling against risks like prompt injection and data poisoning, conduct source code reviews, and evaluate third-party SaaS vendors such as Notion and Slack. Key technical requirements include proficiency in Python, Infrastructure as Code tools like Terraform, and familiarity with Kubernetes and AWS. The role requires expertise in RAG, fine-tuning, and authentication models like OAuth2 and SAML to secure non-human identities. You will collaborate across Engineering, Legal, and Privacy teams to mitigate vulnerabilities within a regulated environment involving SOC 2 and PCI DSS standards.

What you'll do

  • Manage the end-to-end security review process for enterprise AI/LLM systems, including architecture, data flows, and permissions.
  • Threat model AI-based systems against risks like prompt injection, data poisoning, and unauthorized tool usage.
  • Review source code, system prompts, and agent configurations to ensure security requirements are met before launch.
  • Build security guardrails and automated tools using Python and Infrastructure as Code (IaC) for AI permission boundaries.
  • Evaluate the security of third-party SaaS vendors and their integrated AI capabilities during risk assessments.
  • Identify emerging AI vulnerabilities and develop specific incident response playbooks for high-level escalations.
  • Lead cross-functional initiatives with Legal, Privacy, and Engineering to establish scalable AI governance and controls.

What we're looking for

  • You are a seasoned security engineer with experience designing and maintaining security architecture for AI/LLM-based systems.
  • You have practical experience threat modeling and reviewing AI/LLM applications against standards like OWASP Top 10 for LLM Applications.
  • You have experience securing agentic systems, tool-calling frameworks, and managing non-human or machine-to-machine identities.
  • You can build security tooling and guardrails using Python and deploy policy-as-code via Infrastructure as Code (Terraform).
  • You are familiar with cloud services like AWS, Kubernetes, and enterprise tools such as Okta and CASB.
  • You have experience building AI governance artifacts and evaluating AI capabilities within third-party SaaS platforms.
  • You can lead cross-functional initiatives and communicate effectively with both technical and executive stakeholders.
  • Experience in regulated environments (SOC 2, PCI DSS) is preferred.

More like this

Similar roles

Staff Enterprise Security Engineer, AI Security

Twilio

Remote 29 days ago $155,520–$194,400
Security Engineering Cloud Security Kubernetes Python Go Java AWS GCP Container Security Threat Modeling Data Protection AI Security Automation
7+ yrs exp Remote

Staff CIAM Software Engineer

Affirm

Remote 43 days ago $230,000–$290,000
Python Kotlin AWS Kubernetes MySQL Spark OAuth 2.0 OIDC SAML SCIM Terraform CI/CD Infrastructure as Code Okta Auth0 Ping Identity ForgeRock Azure AD B2C Buildkite GitHub
5+ yrs exp Remote

AI Security Engineer

Cisco

NC 6 days ago $128,600–$184,900
Generative AI LLM RAG Python Go Kubernetes Microservices APIs Cloud Security Application Security Threat Modeling Automation Data Protection
3+ yrs exp

Enterprise Security Engineer

Opendoor

Miami, FL 92 days ago
Okta Jamf CrowdStrike Falcon Python Go TypeScript Terraform SAML OIDC SCIM EDR Microsoft Intune Google Workspace Cloudflare Datadog GitHub OpenAI Anthropic
5+ yrs exp Hybrid

Enterprise Security Engineer

Opendoor

Toronto, Ontario, Canada 92 days ago
Okta Jamf CrowdStrike Falcon Python Go TypeScript Terraform SAML OIDC SCIM EDR Microsoft Intune Google Workspace Cloudflare Datadog GitHub OpenAI Anthropic
5+ yrs exp Hybrid