About the Role
We're hiring a Product Security Engineer to build Collective's application security program, centered around AI agents. This role involves designing and operating an agentic appsec pipeline for automated security testing and AI-driven triage, driving vulnerability remediation, and making targeted code changes to eliminate vulnerability classes. You will work closely with product engineers on a platform handling sensitive financial and tax data.
Responsibilities
- Build and operate an agentic application security program, including SAST, DAST, SCA, CI/CD integration, LLM-based triage, and automated security review of pull requests.
- Drive vulnerability remediation end to end, including triaging findings, routing fixes, tracking closure against SLAs, and verifying fixes.
- Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes.
- Lead threat modeling and security review for new features and platform changes, automating the practice over time.
- Tune and evolve the program's signal quality by developing new rules, improving prompts, and reducing false positives.
- Stay current on the vulnerability landscape relevant to a fintech platform and translate findings into concrete program changes.
Requirements
- 4+ years of security engineering experience with deep application security knowledge.
- Hands-on experience with SAST, DAST, and SCA tooling and CI/CD integration (e.g., Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite).
- Genuine enthusiasm for building with LLMs and AI agents, including automating security work and evaluating prompts/workflows.
- Sufficient software engineering skill to make confident code changes in a production codebase (Python/Django on AWS).
- Experience driving remediation through teams without direct management.
- Product empathy, optimizing for fixed vulnerabilities and shaping feedback for engineers.
Skills
- Application Security
- SAST
- DAST
- SCA
- CI/CD Integration
- LLM Prompting
- AI Agent Automation
- Vulnerability Remediation
- Threat Modeling
- Python
- Django
- AWS
Location
- San Francisco
Work Type
- Hybrid
Experience Level
- 4+ years
Benefits
- Hybrid Work Model
- Fresh Lunch on in-office days
- $150 monthly commuter reimbursement
- $200 quarterly health & wellness reimbursement
- Flexible PTO
- 14 company holidays
- 100% medical, dental, and vision coverage for employees
- 75% coverage for dependents' medical, dental, and vision
- 16 weeks fully paid parental leave
- 401k plan
- Equity package
- Quarterly virtual team events
- Annual in-person summit
About the Company
- Collective is redefining the way businesses-of-one work by providing an integrated platform for business incorporation, accounting, bookkeeping, tax services, and community.
- Our mission is to empower self-employed people to achieve financial independence and enjoy tax savings.
- Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more.
- Backed by investors including General Catalyst, Sound Ventures, QED Investors, and Google’s Gradient Ventures.
