
1001 - 5000 employees
Founded 2012
💳 Fintech
👥 B2C
🛍️ eCommerce
💰 Post-IPO Equity on 2021-01
Fintech • B2C • eCommerce
Affirm is a financial technology company that offers a 'Buy Now, Pay Later' service, allowing consumers to make purchases and pay for them over time with flexible payment plans. Affirm eliminates hidden fees and compound interest, providing clear terms and conditions for its users. The company also offers the Affirm Card, a debit card that allows users to request to pay over time for larger purchases or pay in full for smaller ones. Affirm partners with various retailers across multiple categories, including electronics, apparel, and travel, providing customers with the convenience of paying over time at checkout both online and in physical stores. Affirm's services are integrated with Apple Pay, enabling customers to make payments seamlessly from their iPhone or iPad.
🔥 18 hours ago
🇨🇦 Canada – Remote
💵 $181k - $241k / year
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 1%
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
Founded 2012
💳 Fintech
👥 B2C
🛍️ eCommerce
💰 Post-IPO Equity on 2021-01
Fintech • B2C • eCommerce
Affirm is a financial technology company that offers a 'Buy Now, Pay Later' service, allowing consumers to make purchases and pay for them over time with flexible payment plans. Affirm eliminates hidden fees and compound interest, providing clear terms and conditions for its users. The company also offers the Affirm Card, a debit card that allows users to request to pay over time for larger purchases or pay in full for smaller ones. Affirm partners with various retailers across multiple categories, including electronics, apparel, and travel, providing customers with the convenience of paying over time at checkout both online and in physical stores. Affirm's services are integrated with Apple Pay, enabling customers to make payments seamlessly from their iPhone or iPad.
• Lead and continuously improve Affirm’s enterprise AI security review process • Evaluate architectures, data flows, permissions, and designs of internal AI tools, agentic/MCP-based systems, and AI features • Embed security requirements into the design phase • Threat model AI/LLM systems and data flows for prompt injection, insecure output handling, excessive agency, tool-permission abuse, data poisoning, and sensitive-data exposure • Drive remediation of identified risks • Review source code, system prompts, agent configurations, and tool/permission manifests • Help tool owners develop security-focused test cases and red-team/evaluation scenarios • Design and build security guardrails and tooling for AI systems, permission boundaries, authentication/authorization, data handling, logging/monitoring, and policy-as-code • Evaluate third-party SaaS AI capabilities during vendor and SaaS security reviews • Identify emerging AI/agentic security vulnerabilities and develop mitigations • Contribute to AI-specific incident response playbooks as a senior escalation point • Lead cross-functional AI security initiatives to closure • Advise technical and executive stakeholders as an internal point of expertise • Monitor the AI security landscape, including OWASP LLM Top 10 and MITRE ATLAS, and translate research into practical controls
• Hands-on experience designing, evaluating, and maintaining security architecture for AI/LLM-based systems • Deep expertise in enterprise security systems, processes, and controls • Practical experience threat modeling and reviewing AI/LLM applications • Experience securing agentic systems and tool-calling frameworks, including MCP servers/clients and tool-permission models • Experience building AI governance artifacts and evaluating AI capabilities within SaaS platforms • Experience with enterprise tools for AI visibility and control, such as CASB and Okta • Experience with corporate systems including OpenAI, Anthropic, GitHub, Google Workspace, Slack, Notion, and Jira • Ability to build security tooling, guardrails, and detections with Python or similar • Experience deploying cloud services and policy-as-code using Terraform or similar Infrastructure as Code • Familiarity with Kubernetes and AWS • Understanding of LLM and agentic-system concepts including RAG, embeddings, fine-tuning, and tool use • Understanding of OAuth2, SAML, service-account/non-human identities, application architecture, and threat modeling • Ability to lead cross-functional initiatives and communicate with technical and executive audiences • Experience in regulated environments such as SOC 2 and PCI DSS is a plus • Experience applying IAM to non-human/agent identities is a plus • Must reside in Alberta, British Columbia, Manitoba, New Brunswick, Newfoundland and Labrador, Nova Scotia, Ontario, Prince Edward Island, or Saskatchewan
• Monthly stipends for health, wellness and tech spending • 100% subsidized medical coverage for employees and dependents • Dental and vision coverage for employees and dependents • Flexible time off • Generous holiday calendars • Employee stock purchase plan (ESPP) with discounted Affirm stock • Remote-first flexibility • In-person onboarding experience • Inclusive interview process and accommodations for candidates with disabilities
Apply Now🕒 September 8
Staff Cyber Security Engineer securing NBCUniversal’s media, streaming, and entertainment technology. Conducting threat analysis and guiding network, application, cloud, and enterprise security controls.
🕒 September 3
Principal Cloud Security Engineer securing LastPass’s browser-based access platform. Defining cloud security architecture and reducing risk across AWS and Kubernetes workloads.
🕒 August 27
Staff Product Security Engineer defining security architecture for FirstPrinciples’ AI scientific-discovery platform. Securing agents, code execution, cloud infrastructure, models, data, and SaaS systems.
🕒 August 14
Technical Counselor advising CIOs, CISOs, and technology executives across Canada. Shaping cybersecurity, AI, governance, and IT strategy through executive advisory services and research.
🕒 August 11
Staff Security Engineer advancing Mozilla’s Information Security Management System and ISO 27001/SOC 2 compliance. Supporting audits, policies, remediation, and certification readiness for an open-source technology company.