Product Security Engineer at Collective | San Francisco | Rezi

Product Security Engineer at Collective

Product Security Engineer

Collective · San Francisco

1 weeks ago

Product Security Engineer

Collective · San Francisco

12 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

We're hiring a Product Security Engineer to build Collective's application security program, centered around AI agents. This role involves designing and operating an agentic appsec pipeline for automated security testing and AI-driven triage, driving vulnerability remediation, and making targeted code changes to eliminate vulnerability classes. You will work closely with product engineers on a platform handling sensitive financial and tax data.

Responsibilities

  • Build and operate an agentic application security program, including SAST, DAST, SCA, CI/CD integration, LLM-based triage, and automated security review of pull requests.
  • Drive vulnerability remediation end to end, including triaging findings, routing fixes, tracking closure against SLAs, and verifying fixes.
  • Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes.
  • Lead threat modeling and security review for new features and platform changes, automating the practice over time.
  • Tune and evolve the program's signal quality by developing new rules, improving prompts, and reducing false positives.
  • Stay current on the vulnerability landscape relevant to a fintech platform and translate findings into concrete program changes.

Requirements

  • 4+ years of security engineering experience with deep application security knowledge.
  • Hands-on experience with SAST, DAST, and SCA tooling and CI/CD integration (e.g., Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite).
  • Genuine enthusiasm for building with LLMs and AI agents, including automating security work and evaluating prompts/workflows.
  • Sufficient software engineering skill to make confident code changes in a production codebase (Python/Django on AWS).
  • Experience driving remediation through teams without direct management.
  • Product empathy, optimizing for fixed vulnerabilities and shaping feedback for engineers.

Skills

  • Application Security
  • SAST
  • DAST
  • SCA
  • CI/CD Integration
  • LLM Prompting
  • AI Agent Automation
  • Vulnerability Remediation
  • Threat Modeling
  • Python
  • Django
  • AWS

Location

  • San Francisco

Work Type

  • Hybrid

Experience Level

  • 4+ years

Benefits

  • Hybrid Work Model
  • Fresh Lunch on in-office days
  • $150 monthly commuter reimbursement
  • $200 quarterly health & wellness reimbursement
  • Flexible PTO
  • 14 company holidays
  • 100% medical, dental, and vision coverage for employees
  • 75% coverage for dependents' medical, dental, and vision
  • 16 weeks fully paid parental leave
  • 401k plan
  • Equity package
  • Quarterly virtual team events
  • Annual in-person summit

About the Company

  • Collective is redefining the way businesses-of-one work by providing an integrated platform for business incorporation, accounting, bookkeeping, tax services, and community.
  • Our mission is to empower self-employed people to achieve financial independence and enjoy tax savings.
  • Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more.
  • Backed by investors including General Catalyst, Sound Ventures, QED Investors, and Google’s Gradient Ventures.