Staff Product Security Engineer
Affirm
At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most. The InfoSec team protects Affirm’s systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at Affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence. In this role, you'll build and run Affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let Affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable. What you’ll do - You will lead and continuously improve Affirm's enterprise AI security review process evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase. - You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation. - You will review source code, system prompts, agent configurations, and tool/permission manifests (e. g. , MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch. - You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security. - You will evaluate the AI capabilities of third-party SaaS vendors (e. g.
, Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions. - You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point. - You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls. What we look for - You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls. - You have practical experience threat modeling and reviewing AI/LLM applications (e. g. , against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries. - You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e. g. , Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews. - You have experience with enterprise tools for AI visibility and control (e. g. , CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira). - You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
- ...suite of everyday financial products - including the Shakepay Card... ...something truly special. About the security team Security at Shakepay is... .... We work closely with Engineering, Platform, Risk, Compliance,... ...work and increase our impact. Staff Security Engineer We’re looking...SuggestedLong term contractFull time
- ...New Staff Product Security Architect Remote, Canada; Remote, Israel; Remote, Poland; Remote, United Kingdom; Remote, United States Apply GitLab... ...gates. In this role, you will collaborate closely with product engineering organizations, spearhead architectural strategy for critical...SuggestedFull timeRemote work
$160.32k - $200.4k per year
...See yourself at Twilio Join the team as Twilio’s next Staff Engineer, Security Engineering Partners. About the job We are actively recruiting... ...to foster cooperative partnerships across key Twilio products and platforms. Partner with product and engineering teams...SuggestedFull timeLocal areaRemote workWorldwide- ...applications and next steps. Our partner is looking for a Staff Engineer, AI Productivity based in Canada. This is a hands-on technical leadership role... ...updates with AI assistance. - Act as the internal product owner for AI agent capabilities, identifying emerging technologies...SuggestedFull time
$155k - $185k per year
...privacy-respecting communication and productivity tools that help people manage their... ...model choices. We’re looking for a Staff Full-Stack Product Engineer: a full-stack engineer who ships... ...keeping strong judgment about quality, security, and maintainability. What you...SuggestedLong term contractPermanent employmentFull timeFor contractorsInternshipLocal areaRemote work- ...privacy-respecting communication and productivity tools that help people manage their... ...model choices. We’re looking for a Staff Full-Stack Product Engineer: a full-stack engineer who ships production... ...while keeping strong judgment about quality, security, and maintainability....Long term contractFull time
- ...surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role We're hiring a Senior Product Security Engineer to build and operate the modern security tooling pipeline that underpins everything our Product Security team does. You'll...Full time
- ...Back to jobs New Senior Product Security Engineer Remote - Canada Apply About AlphaSense: The world’s most sophisticated companies rely on AlphaSense... ...Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products across AlphaSense's AI-...Full timeRemote work
- ...GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital... ...services of GitLab. An overview of this role As a Staff Backend Engineer on GitLab's Security Factory: Code Scanning...Full timeLive In
- ...Description About the company & products TuxCare offers a comprehensive portfolio of security solutions for Linux and open-source software designed for enterprise... .... Learn more at: We are currently hiring Staff Engineers for two TuxCare products: KernelCare and...Full time
- ...people around the world using our products each month, we’re shaping the... ...including AI, social media, security and more. And we’re doing this... ...seeking experienced browser engineers to join a small team exploring... ...We are looking for a browser engine specialist who enjoys turning...Full time
- ...organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and... ...we are hiring for a foundational engineering role. That means you bring technical... ...ability to influence as a Staff owning product or platform systems...Full time
- ...are looking for an experienced Product Manager to own the future of... .... You’ll join a fully staffed engineering team ready to execute, and together... ...you can have here. As a Staff Product Manager for MCP & AI Ecosystem... ...conversations with engineers, security teams, and partner CTOs. - A...Full time
- ...all applications and next steps. Our partner is looking for a Staff Product Designer based in Canada. As a Staff Product Designer on the AI... ...the future evolution of the platform. Working across Product, Engineering, Research, Revenue, Client Services, and Leadership, you’ll...Full timeRemote work
$154k per year
...surges. ” learn more about working at Coinbase . As an Offensive Security Engineer on the Application Security team within Security, you'll... ...offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security...Full timeLocal areaShift work- ...GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital... ...services of GitLab. An overview of this role As a Staff Engineer, you'll be the technical anchor for GitLab's...Full timeRemote work
$186.37k - $223.64k per year
...zones (EST + CST only at this time). Staff Backend Engineer - Application Core Services, Stacks... ...a team working at the intersection of product, platform, and business operations. The... ...workflow (your choice of tools, within security guidelines), backed by a company-funded...Long term contractFull timeContract workInternshipLocal areaImmediate startRemote workFlexible hours- ...the SaaS space? Join epilot! We are looking for product minded engineers not only coders. We're seeking builders who bridge... ...environment Basic understanding of application and cloud security principles, and how to build secure, reliable software. Tech Stack: React, Svelte,...Full timeRemote workFlexible hoursDay shift
$186.37k - $223.64k per year
...truly career-defining opportunity. Staff Backend Engineer - Adaptive Telemetry, Databases This... ...vision, prioritize work that unlocks major product or platform improvements, and influence... ...workflow (your choice of tools, within security guidelines), backed by a company-funded...Long term contractFull timeLocal areaRemote work- ...enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation... .... An overview of the role We are seeking a Staff Security Research Engineer to join our Application Security Team to...Full timeWorldwide
$109.4k - $191.5k per year
...Responsibilities Become a subject-matter expert in production database troubleshooting, ServiceNow instance performance, and Linux performance... ...mission-critical software. Mentor and collaborate with engineers across operations, support, and development. Lead individual...Remote workFlexible hours- ...growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even... ...and Ireland. Come join us! About the Role We are seeking a Staff Software Engineer to join Reference and Entity Data Systems (REDS) and own the...Full time
- ...across ingestion, matching, entity generation, and downstream delivery. Respond to production incidents and improve observability and reliability through iterative hardening. Set engineering standards, mentor engineers, and partner with product and downstream consumers on...Full time
- ...next steps. Our partner is looking for a Staff Engineer / AI Builder based in Canada. This is a... ...role focused on designing and delivering production-grade AI and ML systems at enterprise... ...integration-heavy projects where reliability, security, scalability, and measurable outcomes...Full time
- ...teammates to prioritize and deliver the product roadmap. Design, build, and own complex... ...code for production systems. Establish engineering practices that support a high-performing... ...functional teams on strategy and delivery. Staff-level technical leadership skills,...Full timeRemote workVisa sponsorship
- ...Description Sprout Social is seeking an experienced Product Manager to own the strategy, delivery, and scaling of our Listening product... ...broader R&D organization, our team collaborates closely with Engineering, Product Design, and Go-to-Market (GTM) teams to create impactful...Long term contractFull timeWorldwide
- ...Job Responsibility: Staff Site Reliability Engineer About vArmour At vArmour, we're disrupting traditional security and IT players through the understanding of relationships -... ...drives the company-in our technology and product design, as well as how the company engages...Full timeRemote workFlexible hours
- ...next steps. Our partner is looking for a Staff Software Engineer, IDSM based in Canada. We are looking... ...that help organizations operationalize AI securely, efficiently, and reliably.... ...Collaboration: Partner with engineering, product, and customer-facing teams to translate...Full time
- ...all faiths. Description Sprout Social is seeking an experienced Product Manager to own the strategy, delivery, and scaling of our... ...toward a scalable, platform-based integration model that reduces engineering lift per partner while expanding the ecosystem of systems that...Long term contractFull timeWorldwideShift work
- .... Our partner is looking for a Senior/Staff Platform Engineer based in Canada. The Senior/Staff Platform... ..., operate, and evolve large-scale production infrastructure with a strong focus on... ...workload isolation, resource management, security, upgrades, scaling, and reliability. -...Full timeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!
- project engineer assistant project manager Remote
- assistant electrical engineer Remote
- software design engineer Remote
- physical design engineer Remote
- transformer design engineer Remote
- design verification engineer Remote
- product security engineer Remote
- mechanical product design / development engineer Remote
- product design engineer Remote
- physical security engineer Remote
