Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Product Security Engineer

$204k - $290k
Full-time

Affirm

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

The InfoSec team protects Affirm’s systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at Affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence.

In this role, you'll build and run Affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let Affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable.

What you’ll do

  • You will lead and continuously improve Affirm's enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.

What we look for

  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

Base Pay Grade - P

Equity Grade - 13

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA base pay range (CA, WA, NY, NJ, CT) per year: $230,000 - $290,000
USA base pay range (all other U.S. states) per year: $204,000 - $264,000

#LI-Remote

Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for you Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
  • Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.

We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.

For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Product Security Engineer in Remote vacancy
  • $106k - $209k

    The MongoDB Product Security organization is a diverse collection of individuals working together to scale MongoDB's security, both security...  ...MongoDB Product Security organization works with software engineers to design, implement, and operate systems in a manner that... 
    Suggested
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    MongoDB

    Seattle, WA
    1 day ago
  • $208k - $312k

     ...team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now...  ...is manual penetration testing. A software engineer with a strong desire to move into security, or... 
    Suggested
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    Vercel

    San Francisco, CA
    4 days ago
  • $192k - $230k

    Snyk is the leader in secure AI software development, helping millions of developers...  ...innovate securely in the AI era — boosting productivity while reducing business risk. We’re not...  ...team works consultatively with the engineering teams that build and run our cloud platform... 
    Suggested
    Full time
    Work at office
    Work from home
    Flexible hours
    Early shift

    Snyk

    Boston, MA
    4 days ago
  • $122.8k - $184.2k

     ...locally and globally. Come make an impact every day at Zebra.What We're Looking For:The Advanced Engineer Security, as an integral part of the Advanced Data Capture (ADC) product security team, is responsible to ensure that a Secure Development Lifecycle (SDLC) is defined,... 
    Suggested
    Full time
    Summer work
    Work at office
    Local area
    Flexible hours

    Zebra Technologies Corporation

    Holtsville, NY
    5 days ago
  • $144.8k - $261.45k

    The Opportunity Are you passionate about securing global systems and mitigating risks in a fast-paced environment? Adobe Security...  ...its Vulnerability Operation Center (VOC). As a VOC Senior Product Security Engineer, you will analyze and triage incoming identified... 
    Suggested
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe Systems

    Lehi, UT
    3 days ago
  • $100k - $125k

    Aras is a leader in product lifecycle management (PLM) and digital thread solutions. As one of the fastest growing PLM companies,...  ...aerospace and defense, and high-tech electronics. As a Product Security Engineer specializing in our Security Operations Center (SOC) for... 
    Temporary work
    Flexible hours

    Aras

    Andover, MA
    4 days ago
  • Join Hologic's mission to drive a Secure by Design culture within our Breast & Skeletal Health Connected Health products. As a Senior Product Security Engineer, you will play a pivotal role in ensuring the security and integrity of our innovative healthcare solutions. If... 
    Remote work

    Hologic

    Santa Clara, CA
    4 days ago
  • $68.9k - $131.1k

     ...authorized to access information under this program/contract. Security Clearance Type: None/Not Required Security Clearance...  ...protection. We are seeking a driven System Security Engineer to join our Embedded Product Cybersecurity Engineering team and defend mission-... 
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    Raytheon

    Cedar Rapids, IA
    2 days ago
  • $165k - $200k

    Atlanta (Remote Friendly)Security /Full Time /RemoteGreenlight is the leading family fintech company on a mission to help parents...  ...on it.We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. This individual will be... 
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    Greenlight Financial Technology

    Atlanta, GA
    2 days ago
  •  ...The Opportunity Are you passionate about securing global systems and mitigating risks in a fast-paced environment? Adobe...  ...its Vulnerability Operation Center (VOC). As a VOC Senior Product Security Engineer, you will analyze and triage incoming identified vulnerabilities... 

    Adobe

    McLean, VA
    4 days ago
  • $108.24k - $151.48k

     ...your work location, balancing what your work requires. What's in it for you: The Residential HVAC team is adding a Product Security Engineering position to focus on embedded systems, services, applications and the associated product development processes used in... 
    Hourly pay
    Local area
    Work from home

    Trane Technologies

    Tyler, TX
    2 days ago
  • $135k - $175k

     ...Product Security Engineer Boston; New York, New York, United States KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following... 
    Work at office
    Local area
    Remote work

    KKR

    Boston, MA
    2 days ago
  • $160k - $276k

     ...Product Security Engineer We are looking for a highly motivated engineer specializing in product security to work on Model S, X, 3, Y, Cyber Truck and future R&D projects. At Tesla, we make the future of "connected cars" a reality. We regularly send over-the-air software... 
    Hourly pay
    Full time
    Temporary work
    Remote work
    Flexible hours

    Tesla

    Palo Alto, CA
    5 days ago
  •  ...Senior Product Security Engineer Germany Remote About Staffbase We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our... 
    Remote work
    Flexible hours

    Staffbase

    United States
    5 days ago
  •  ...future of AI on LanceDB, from frontier and world models to robots and autonomous vehicles. About the Role Our first product security-focused engineer Takes high-level direction (e.g., "identify top five security-related gaps for AX") and drives to results... 
    Remote work

    LanceDB

    United States
    5 days ago
  • $217k - $303.9k

     ...of the internet’s largest sources of information. For more information, visit redditinc.com . Reddit is hiring a Staff Product Security Engineer to make the secure path the easiest path for engineers and AI agents. You'll lead the design and delivery of secure frameworks... 
    For contractors
    Work experience placement
    Remote work

    GrabJobs

    Joliet, IL
    3 days ago
  •  ...Tempo Product Security Engineer Tempo is a layer-1 blockchain purpose-built for stablecoins and real-world payments, born from Stripe's experience in global payments and Paradigm's expertise in crypto tech. Tempo's payment-first design provides a scalable, low-cost... 
    Remote work

    Tempo LLC

    United States
    3 days ago
  •  ...experiences; and dramatic increases in productivity. Leading organizations including American...  ..., Stryker, The United States Social Security Administration, The United States...  ...documents. As a Senior Product Security Engineer, you will be the cornerstone of our product... 
    Remote work
    Work from home
    Flexible hours

    HYPERLABS

    United States
    2 days ago
  •  ...Senior Engineer - Cyber Security Founded in 2018, we've already grown to be a 300+ team distributed across the globe, united by a singular...  ...agentic systems across clinical operations and patient-facing products, and running a lean security function that scales through... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Numan

    United States
    1 day ago
  • $500 per month

     ...Security Practitioner The Security Team is responsible for providing key security capabilities covering application, cloud...  ...security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and... 
    Local area
    Remote work
    Home office
    Flexible hours

    ClickHouse

    United States
    3 days ago
  •  ...Product Security Engineer We are seeking a Product Security Engineer to join our team and lead the implementation of enterprise security strategies across our orthopedic medical device portfolio. This position plays a key role in both pre-market and post-market product... 
    Remote work

    Kasmo Global

    United States
    2 days ago
  • $180k - $240k

     ...better, brighter future for the next generation depends on it. We are seeking a seasoned and highly accomplished Senior Staff Product Security Engineer to join our security leadership team. This is a senior individual contributor role that carries significant... 
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    GrabJobs

    Antioch, CA
    3 days ago
  •  ...Senior Product Security Engineer As a Senior Product Security Engineer at Hyperscience, you will play a crucial role in safeguarding our machine-learning-powered platform. In this position, you will work closely with the engineering team to design, implement, and automate... 
    Remote work

    Aidoos

    United States
    3 days ago
  •  ...Senior Product Security Engineer We're hiring a Senior Product Security Engineer to work hand-in-hand with developers to secure the product across its entire lifecycle. You'll be the person who makes our platform defensible — through design reviews, threat modeling,... 
    Remote work
    Worldwide

    Tessera Labs

    United States
    4 days ago
  •  ...Product Security Engineer Our client, a leading Medical Device Manufacturing Company is looking for a Product Security Engineer for an initial duration of 06 Months Contract – Remote. Job Title: Product Security Engineer Duration: 06 Months Contract Position... 
    Hourly pay
    Contract work
    Remote work

    Sunrise Systems

    United States
    3 days ago
  •  ...Job Description Job Description Job title: Product Security PKI and Cloud Environment Architect \tLeads the development, implementation...  ...environment architect \t5+ years of experience \tAny Engineering or computer science BS or BS information systems degree... 
    Contract work
    For contractors
    Work experience placement
    Immediate start
    Remote work

    Systemart LLC

    Washington DC
    21 days ago
  •  ...Senior Product Security Engineer (Black Duck & Application Security) Location: Philadelphia. Hybrid (3 days in-person,2 days remote) Role Summary We are seeking a highly experienced Senior Product Security Engineer with strong expertise in Black Duck, software... 
    Remote work

    TekCommands Inc

    Pennsylvania
    3 days ago
  •  ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on...  ...and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform... 
    Full time
    Local area
    Remote work
    Worldwide
    Flexible hours

    DataRobot

    San Francisco, CA
    5 days ago
  • $161k - $247k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building...  ...building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen... 
    Full time
    Local area
    Remote work
    Worldwide
    Flexible hours

    Okta

    San Francisco, CA
    2 days ago
  •  ...while learning, having fun, and making a profound difference for the dreamers and builders in the world. We’re looking for a Product Security Engineer who is passionate about partnering with engineers to assess the security risk of new products and features. As a member of... 
    Full time

    DigitalOcean

    Remote
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!