SAFER: Risk-Constrained Sample-then-Filter in Large Language Models