Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, Enterprise AI

$220k - $280k

Affirm

At affirm we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

The InfoSec team protects affirm's systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence.

In this role, you'll build and run affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable.

What you'll do

  • You will lead and continuously improve affirm's enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.

What we look for

  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

Base Pay Grade - P

Equity Grade - 13

Employees new to affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.
Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA base pay range (CA, WA, NY, NJ, CT) per year: $220,000 - $280,000

USA base pay range (all other U.S. states) per year: $195,000 - $255,000

Remote-first with flexibility built in Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for you Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
#J-18808-Ljbffr

Vacancy posted 15 hours ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, Enterprise AI in Chicago, IL vacancy
  • $161k - $221k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential...  .... The Defensive Cyber Engineering organization is...  ...capabilities. The team also manages enterprise security tools and...  ...Sector roadmap by hiring a Staff Software Engineer in the DC... 
    Suggested
    Local area
    Worldwide
    Flexible hours

    Okta

    Chicago, IL
    2 days ago
  • $210k - $260k

     ...platform in the world. What you'll do: We're looking for a Staff Security Engineer, Application Security to help scale and mature our security...  ..., dependency security, and container security Leverage AI/LLMs where appropriate to improve triage, detection, and review... 
    Suggested
    Remote job
    Full time
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    NinjaTrader

    Chicago, IL
    a month ago
  • $200k - $225k

     ...our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative...  ...Head of AI Security to align Falcon's architecture with enterprise AI security standards without slowing product velocity. Product... 
    Suggested
    Full time
    Local area
    Immediate start
    Remote work

    Jones Lang LaSalle

    Chicago, IL
    19 hours ago
  •  ...Remote100% RemoteThe client is seeking a Senior Security Automation Engineer to help design, build, and scale an enterprise security automation platform that improves...  ...application security requirements and controls, and use AI technologies daily to improve engineering speed... 
    Suggested

    Mindlance

    Chicago, IL
    3 days ago
  •  ...TechnologyJob Description Summary: The Senior IT Security Engineer is responsible for planning, deploying,...  ...SSDLC, etc.).Monitoring and managing enterprise security systems, cloud environments,...  ...warehousesDemonstrable knowledge of AI workflows and threats and risks to AI... 
    Suggested
    Full time

    Breakthru Beverage Group

    Cicero, IL
    1 day ago
  • $137.2k - $205.8k

    Senior Staff Infrastructure Engineer - IEB07BEWe’re determined to make a difference...  ...mentor engineers, and apply AI as a responsible productivity...  ..., build, and operate secure, highly available Oracle database...  ....Ensure platforms meet enterprise expectations for security,... 
    Full time
    Temporary work
    Work at office
    3 days per week

    The Hartford Financial Services Group

    Chicago, IL
    1 day ago
  • $114.5k - $194.7k

     ...exceptional service. The Senior Lead, Security Engineer is an experienced individual contributor...  ...responsible for engineering and operationalizing enterprise security platforms across Northern...  ..., vulnerability & exposure management, AI guardrails, and SaaS.Apply engineering... 
    Full time
    H1b
    Remote work
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    2 days ago
  • $110k - $140k

     ...software solution to automate securities-based lending from...  ...and hands-on Senior Security Engineer to help protect Supernova’s financial...  ...financial technology platform and enterprise environment. This senior...  ...security requirements. Evaluate AI-assisted security workflows... 

    Supernova Companies LLC

    Chicago, IL
    2 days ago
  • $10 per hour

     ...environment? Come join us. All security disciplines work under the...  ...and tooling that hundreds of engineers around the world rely on...  ...similar), and keep pace as we add AI agents and MCP integrations...  ...of experience in corporate, enterprise, or IT security engineering —... 
    Work at office
    Immediate start
    Flexible hours

    Flexport

    Chicago, IL
    3 days ago
  • $121.55k - $157.3k

     ...within the context of the enterprise environment, and...  ...vulnerability‑related security tickets, providing authoritative...  ...and coaching junior staff, documenting standards...  ...a strong emphasis on engineering and operational...  ...data analysis.Advanced AI usage skills to supercharge... 
    Full time
    Work at office
    Immediate start
    Flexible hours

    Cboe Exchange

    Chicago, IL
    3 days ago
  • $130k - $190k

    Staff ML Engineer Press Ganey is the leading experience measurement, data...  ...Engineer to bridge the gap from AI Agent prototype to shipped,...  ...and modernizing our enterprise application with advanced AI...  ...remains scalable, observable, secure, and maintainable. What You'... 
    For contractors
    Local area

    Press Ganey

    Chicago, IL
    4 days ago
  • $149.8k - $262.2k

    Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious...  ...work. Today, ServiceNow is the AI control tower for business reinvention. Our...  ...Experience supporting/administering other enterprise platforms and technologies is an advantage... 
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Weekend work

    Moveworks

    Chicago, IL
    1 day ago
  •  ...Line of Business Applications, AI Platforms (Newmark Document...  ...Newmark AI Exchange), and core enterprise systems. Architect and...  ...reliability and efficiency. Set engineering standards and best practices...  ...-as-code, CI/CD, security, and observability across the... 
    Flexible hours

    Newmark ltd

    Chicago, IL
    2 days ago
  •  ...meet you.   ABOUT THE ROLE As the Security Operations Engineer at Hopscotch, you will lead and...  ...ingenuity to identify where agentic AI can accelerate evidence collection, interpret...  ...are not limited to: Manage the enterprise security program. Define systems... 
    Live in
    Work at office

    Hopscotch Primary Care

    Chicago, IL
    a month ago
  • $1,000 per month

     ...Job Description Job Description SECURITY SALES ENGINEER (for Enterprise clients) Location : Greater Chicago, IL area or Greater Atlanta, GA area...  ...with any of the following: ExtraHop, Stealthwatch, Vectra AI, Darktrace, RSA NetWitness, CoreLight, Netscout nGenius... 
    Permanent employment
    Full time
    Work from home
    Worldwide

    MRINetwork Jobs

    Chicago, IL
    a month ago
  • $110k - $140k

     ...AI Security Engineer Reporting Location: Chicago - 345 North Morgan 110,000-140,000 Workplace Type: Hybrid ABOUT US tms unites...  ...marketing technology stacks, AI‑integrated platforms, and enterprise SaaS environments. Roles and Responsibilities Evaluate... 

    Morgan Street Holdings

    Chicago, IL
    2 days ago
  • $160k - $200k

     ...forward. About JLL and Data Engineering JLL is a leading professional...  ...that power decisions across the enterprise. We move fast, think big, and...  ...grade standards for quality, security, and scalability. You bring...  ...engineering across data and AI agents, and the interpersonal... 
    Daily paid
    Local area
    Shift work

    JLL

    Chicago, IL
    4 days ago
  • $190k - $225k

     ...or GCP). Architect and lead enterprise Master Data Management (MDM),...  ...Architect and integrate agentic AI and LLM-driven workflows (...  ...analytics, and BI consumers. Set engineering standards and best practices...  ...statements, see Newmark's Securities and Exchange Commission filings... 
    Temporary work
    Local area
    Flexible hours

    Newmark ltd

    Chicago, IL
    4 days ago
  •  ...seeking a highly skilled Principal Data Engineer to join our Data & Analytics team. This individual...  ...pipelines and architectures to support enterprise analytics, reporting, and data products....  ...this job, you agree to receive calls, AI-generated calls, text messages, or emails... 
    Local area
    Remote work

    Jobot

    Chicago, IL
    4 days ago
  • $95k - $130k

     ...end-to-end software solution to automate securities-based lending from origination through the...  ...motivated and detail-oriented Security Engineer to help secure our securities-backed lending...  ...delivery. Prototype automation, explore AI/LLM‑assisted workflows to improve triage... 
    Full time
    Internship

    Supernova Technology™

    Chicago, IL
    1 day ago
  • $145k - $195k

     ...revolutionizing global financial infrastructure with stablecoins, AI-driven fraud prevention, and instant settlement. Coinflow...  ...at coinflow.cash . About The Role We're hiring for a Security Engineer to own the day-to-day defensive and offensive security posture... 
    Worldwide
    Flexible hours

    Coin Flow

    Chicago, IL
    3 days ago
  • $75 - $80 per hour

    We are seeking a Security Architect to support a growing portfolio of artificial intelligence...  ...security architecture support for AI, agentic AI, cloud, SaaS, andother...  ...security considerations.• Partner with engineering teams, enterprise architects, IAM, data protection,... 
    Contract work
    Temporary work

    TEKsystems

    Chicago, IL
    3 days ago
  • $149k - $235k

     ...data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual...  ..., BrazeAI™ allows marketers to combine and activate AI agents, models, and features at every touchpoint throughout the... 
    Work at office
    Local area
    Flexible hours

    Braze

    Chicago, IL
    4 days ago
  • $112.5k - $187.5k

     ...capabilities that strengthen Security Operations Center response and...  ...security operations, detection engineering, and supporting technology teams to build scalable, AI-driven security solutions within...  ...-teaming. Exposure to Splunk Enterprise Security, Search Processing... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Flexible hours
    2 days per week

    TransUnion

    Chicago, IL
    3 days ago
  • $226k - $339.7k

     ...Exposure Management & Cyber Engineering and ArchitectureApplyremote type...  ...a complex, multinational enterprise. This executive will drive modernization...  ..., shape long-term security architecture strategy, and lead...  ...across infrastructure, cloud, AI-enabled technologies,... 
    Work at office

    Wolters Kluwer N.V.

    Chicago, IL
    4 days ago
  •  ...Reporting to the CISO, the Security Architect will ensure that stakeholder...  ...addressed in all aspects of enterprise architecture — including...  ...collaboration with zerohash engineering teams Develop and maintain...  ...machine learning, and agentic/AI‑augmented systems Ability... 
    Work from home

    Zero Hash

    Chicago, IL
    4 days ago
  •  ...and financial services company focused on securing the future of middle‑income America....  .... The Lead IT Security Architect secures enterprise information by determining security requirements...  ...audiences.Demonstrated knowledge of AI and machine learning technologies, including... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    CNO Financial Group

    Chicago, IL
    2 days ago
  • $110k - $130k

     ...organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach...  ...Qualifications What you bring to the table 5+ years of engineering and pre-sales experience Possess strong analytical and... 
    Temporary work
    Worldwide

    Check-Point-Software-Technologies-2

    Chicago, IL
    1 day ago
  • $198k - $368k

     ..., join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International...  ...respondLead the design, evaluation and productionization of AI and agentic capabilities across detection, triage,... 
    H1b
    Local area

    KPMG

    Chicago, IL
    3 days ago
  • $10 per hour

     ...tier-1 queue here. Detection & Response engineers own their detections end to end: you write...  ...and your team is paged when they fire. The security team is spread across the globe with a...  ...record of critically evaluating and verifying AI-assisted work - testing, source-checking,... 
    Work at office
    Local area
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    Chicago, IL
    29 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, Enterprise AI. Be the first to apply!