665,413open jobs
38,949companies
99,649added this week
Browse all
Salary
$230k – $290k per year
Location
Remote (United States, Canada)
Seniority
Staff
Overview
Company
Impact
Profile match
Affirm is an American consumer lending company founded in San Francisco in 2012 that offers instalment loans at the point of sale, an approach usually described as buy now pay later. Unlike revolving credit it underwrites each purchase individually, discloses total cost up front and does not charge late fees, earning revenue from merchant fees on interest-free plans and from interest on longer-term loans. The company is listed on Nasdaq, partners with large retailers and marketplaces including Amazon and Shopify, and also issues a debit card that lets shoppers split purchases after the fact.

At Affirm, we exist for the moments that matter-giving people a clear, predictable way to pay over time, with no hidden fees, no surprises, and no tradeoffs on what matters most.

The InfoSec team protects Affirm’s systems and data from evolving threats. We manage security risk, monitor vulnerabilities, and enforce protective controls across the company. The team leads incident response, compliance, identity and access management, and employee training. Our goal is to ensure that security is built into every system and decision at Affirm. We maintain a secure, trustworthy environment so the business can operate and grow with confidence.

In this role, you'll build and run Affirm's end-to-end security review process for enterprise AI/LLM systems evaluating architecture, prioritizing AI-specific risks, and designing the controls and guardrails that let Affirm adopt AI safely, partnering across Security, Legal, Privacy, Compliance, IT, and Engineering to make it scalable and repeatable.

What you’ll do

  • You will lead and continuously improve Affirm's enterprise AI security review process  evaluating the architecture, data flows, permissions, and design of internal AI tools, agentic/MCP-based systems, and AI features - and embed security requirements into the design phase.
  • You will threat model AI/LLM-based systems and their data flows for risks such as prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure, and drive remediation.
  • You will review source code, system prompts, agent configurations, and tool/permission manifests (e.g., MCP definitions), and help tool owners build security-focused test cases and red-team/eval scenarios to verify requirements before launch.
  • You will design and build security guardrails and tooling for AI systems permission boundaries, authn/authz for agentic tools and MCP servers, data-handling controls, logging/monitoring, and policy-as-code (Python, IaC) - to enforce and automate AI security.
  • You will evaluate the AI capabilities of third-party SaaS vendors (e.g., Notion, Slack, Google Workspace) as part of vendor and SaaS security reviews and drive risk-based adoption decisions.
  • You will identify emerging classes of AI/agentic security vulnerabilities, develop mitigations before they become incidents, and contribute to AI-specific incident response playbooks as a senior escalation point.
  • You will lead cross-functional AI security initiatives to closure, advise technical and executive stakeholders as an internal point of expertise, and stay current on the AI security landscape (OWASP LLM Top 10, MITRE ATLAS) to translate new research into practical controls.

What we look for

  • You are a seasoned security engineer with hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems, plus deep expertise in enterprise security systems, processes, and controls.
  • You have practical experience threat modeling and reviewing AI/LLM applications (e.g., against the OWASP Top 10 for LLM Applications) and securing agentic systems and tool-calling frameworks - MCP servers/clients, tool-permission models, and agent-to-tool trust boundaries.
  • You have built AI governance artifacts (acceptable use policy, data-handling standards, vendor/model risk assessments) and evaluated AI capabilities within SaaS platforms (e.g., Notion AI, Slack AI, Google Workspace AI, GitHub Copilot) as part of vendor reviews.
  • You have experience with enterprise tools for AI visibility and control (e.g., CASB, IDP/Okta) and familiarity with the corporate systems where AI is adopted (OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, Jira).
  • You can build security tooling, guardrails, and detections with Python or similar, and deploy cloud services and policy-as-code using Infrastructure as Code (Terraform or similar); familiarity with Kubernetes and AWS.
  • You understand how LLMs and agentic systems are built (RAG, embeddings, fine-tuning, tool use) and authn/authz models (OAuth2, SAML, service-account/non-human identities) for agentic and machine-to-machine access, with strong application-architecture and threat-modeling fundamentals.
  • You can lead cross-functional initiatives across Security, Engineering, Legal, Privacy, and Compliance and drive them to closure, and communicate effectively with technical and executive audiences. Experience in regulated environments (SOC 2, PCI DSS) and applying IAM to non-human/agent identities is a plus.

Base Pay Grade - P

Equity Grade - 13

Employees new to Affirm typically come in at the start of the pay range.  Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA base pay range (CA, WA, NY, NJ, CT) per year: $230,000 - $290,000

USA base pay range (all other U.S. states) per year: $204,000 - $264,000

Remote-first with flexibility built in

Affirm is proud to be a remote-first company. Most roles can be done from almost anywhere within the country of employment. Some positions may occasionally require in-person work at an Affirm office, and a few are office-based due to the nature of the work. All new hires will be invited to attend an in-person onboarding experience.

Benefits designed for you

Our benefits reflect our commitment to care, transparency, and flexibility. Here are a few highlights:

  • Health coverage at no cost: We cover 100% of premiums for employees and their dependents.
  • Spending stipends: Monthly stipends support your tech setup, and the ability to choose health and wellness options that are right for you.
  • Time off to recharge: Flexible time off and generous holiday calendars help you rest when you need to.
  • Own a piece of what you build: Our employee stock purchase plan (ESPP) lets you buy Affirm stock at a discount.

We’re committed to providing an inclusive interview process, including accommodations for candidates with disabilities. If you need support, we’re happy to help.

For positions based in San Francisco or Los Angeles: Affirm considers qualified applicants with arrest and conviction records, as required by law.

By clicking "Submit Application," you acknowledge that you have read Affirm's  Global Candidate Privacy Notice and consent to the use of your personal information as described.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
665,413 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote/Hybrid • Full-Time • Brazil
Python
Java
SQL
Java
Spring Boot
AI/ML
Copilot
Windsurf
Model Context Protocol
AI Agents
RAG
Devin
DevOps
Splunk
OpenShift
Dynatrace
CI/CD
Git
Kubernetes
Apply
$99k – $245k per year (Estimated) • In office • Internship • Bachelor's Degree • Boise
Python
Verilog
C++
MATLAB
AI/ML
Copilot
Claude
AI Agents
Apply
$49k – $76k per year (Estimated) • In office • Internship • Bachelor's Degree • Longmont
Python
C++
AI/ML
Copilot
Claude
DevOps
Git
Apply
$162k – $315k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • San Jose • Folsom • Boise
Python
AI/ML
Model Context Protocol
XGBoost
Scikit-learn
AI Agents
TensorFlow
PyTorch
RAG
Knowledge Graph
LLM Guardrails
Agentic Workflows
DevOps
GCP
OpenShift
Azure
CI/CD
AWS
Docker
Kubernetes
Apply
$100k – $248k per year (Estimated) • In office • Internship • Master's Degree • Folsom
Python
Perl
AI/ML
Copilot
Claude
Chips/EDA
Cadence Innovus
Synopsys PrimeTime
Siemens Calibre
Apply
$130k – $173k per year • Equity • Remote
Python
AI/ML
Copilot
Model Context Protocol
Fine-tuning
Embeddings
Function Calling
AI Agents
LLM
RAG
OpenAI
Anthropic
LLM Guardrails
Tool Use
DevOps
Terraform
AWS
Kubernetes
GitHub
IAM
Cybersecurity
Okta
OWASP Top 10
PCI DSS
SOC 2
Threat Modeling
Management
Slack
Notion
Jira
Google Workspace
Apply
$129k – $248k per year (Estimated) • Equity • Remote • 6+ years exp • Bachelor's Degree
Python
Kotlin
Databases
Apache Kafka
DevOps
AWS
Platform Engineering
Amazon Kinesis
Analytics
A/B Testing
Apply
$73k – $109k per year • Equity • Remote
JavaScript
TypeScript
Frontend
Vue.js
React.js
Mobile
Declarative UI
Apply
$230k – $290k per year • Equity • Remote • 2+ years exp • Bachelor's Degree
Apply
$195k – $255k per year • Equity • Remote • 4+ years exp • Bachelor's Degree
Python
Kotlin
Databases
MySQL
AI/ML
Spark
DevOps
AWS
Kubernetes
Apply
See all jobs
This is one of many
665,413 more open roles from verified company boards, updated every day.