Staff Product Security Engineer
A
AffirmFinancial Technology
Remote USFull-TimeStaff
SalaryUSA base pay range (CA, WA, NY, NJ, CT) per year: $230,000 - $290,000; USA base pay range (all other U.S. states) per year: $204,000 - $264,000
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSPythonKubernetesOAuthTerraform
Requirements
- Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems.
- Deep expertise in enterprise security systems, processes, and controls.
- Practical experience threat modeling and reviewing AI/LLM applications against OWASP Top 10 for LLM Applications.
- Experience securing agentic systems, tool-calling frameworks, and agent-to-tool trust boundaries.
- Background building AI governance artifacts and evaluating AI capabilities within SaaS platforms.
- Proficiency with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta).
- Ability to build security tooling, guardrails, and detections using Python.
- Experience deploying cloud services and policy-as-code using Infrastructure as Code (Terraform).
- Familiarity with Kubernetes and AWS.
- Strong understanding of RAG, embeddings, fine-tuning, and authn/authz models like OAuth2 and SAML.
- Excellent communication skills for both technical and executive audiences.
Responsibilities
- Lead and continuously improve the enterprise AI security review process including architecture, data flows, and design of internal AI tools and features.
- Threat model AI/LLM-based systems for risks such as prompt injection, insecure output handling, tool-permission abuse, and data poisoning.
- Review source code, system prompts, agent configurations, and tool/permission manifests to build security-focused test cases.
- Design and build security guardrails and tooling for permission boundaries, authn/authz, logging, and policy-as-code to automate AI security.
- Evaluate AI capabilities of third-party SaaS vendors and drive risk-based adoption decisions.
- Identify emerging classes of AI vulnerabilities, develop mitigations, and contribute to AI-specific incident response playbooks.
- Lead cross-functional AI security initiatives and advise technical and executive stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site