远程工作雷达

资深产品安全工程师

Staff Product Security Engineer

开发工程限定地区(需当地身份)
公司Affirm
薪资未公开
工作地点Remote Canada
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间今天
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote Canada 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

在Affirm,我们为那些重要的时刻而存在——让人们能够以清晰、可预测的方式分期付款,没有隐藏费用、没有意外,也不会在最重要的事情上做出妥协。

信息安全部门保护Affirm的系统和数据免受不断演变的威胁。我们管理安全风险,监控漏洞,并在公司范围内实施防护控制。该团队负责事件响应、合规性、身份与访问管理以及员工培训。我们的目标是确保安全融入Affirm的每个系统和决策中。我们维护一个安全、值得信赖的环境,使业务能够自信地运营和增长。

在这个职位中,你将构建并运行Affirm针对企业AI/大语言模型系统的端到端安全评审流程,评估架构,优先处理AI特有的风险,并设计让Affirm安全采用AI的控制措施和保障机制,与安全、法律、隐私、合规、IT和工程团队合作,使其可扩展且可重复。

你将负责

  • 领导并持续改进Affirm的企业AI安全评审流程,评估内部AI工具、代理/MCP系统和AI功能的架构、数据流、权限和设计,并在设计阶段嵌入安全需求。
  • 对基于AI/大语言模型的系统及其数据流进行威胁建模,识别如提示注入、不安全的输出处理、过度自主性、工具权限滥用、数据污染和敏感数据泄露等风险,并推动修复。
  • 审查源代码、系统提示、代理配置和工具/权限清单(例如MCP定义),帮助工具负责人构建以安全为重点的测试用例和红队/评估场景,以在发布前验证需求。
  • 设计并构建AI系统的权限边界安全保障和工具,代理工具和MCP服务器的身份验证/授权,数据处理控制,日志/监控,以及政策即代码(Python、IaC)——以实现和自动化AI安全。
  • 在供应商和SaaS安全评审过程中评估第三方SaaS供应商(例如Notion、Slack、Google Workspace)的AI能力,并推动基于风险的采用决策。
  • 识别新兴的AI/代理安全漏洞类别,在它们成为事件之前开发缓解措施,并作为高级上报点,为AI特定的事件响应预案做出贡献。
  • 领导跨职能的AI安全计划
查看英文原文

At Affirm, we exist for the moments that matter—giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

The InfoSec team protects Affirm’s systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at Affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence.

In this role, you'll build and run Affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let Affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable.

What you’ll do

  • You will lead and continuously improve Affirm's enterprise AI security review process  evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features — and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) — to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.

What we look for

  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks — MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

This posting is for an existing vacancy

This remote role is open only to candidates residing in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan.

Base Pay Grade - P

Equity Grade - 7

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company).

CAN base pay range per year: $181,000 - $241,000 CAD.

#Li-Remote

Remote-first with flexibility built in
Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for you
Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
  • Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.

We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.

For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.

By clicking "Submit Application," you acknowledge that you have read Affirm's Global Candidate Privacy Notice and consent to the use of your personal information as described.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

软件工程师 I,前端

AffirmCanada101,000 - 151,000/年 CADpermanent4 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

← 返回全部职位