Product Security Engineer

CollectiveSan Francisco, CA
Hybrid

About The Position

Collective is seeking a Product Security Engineer to establish and lead the company's application security program, with a strong emphasis on AI agents from the outset. This role moves beyond traditional security tasks, focusing on designing and managing an agentic appsec pipeline. This pipeline will integrate automated security testing (SAST, DAST, dependency scanning) with AI-driven triage and automated security reviews of code changes, providing rapid, high-signal feedback to engineering teams. The engineer will also be responsible for driving vulnerability remediation across the platform, from identification to verified fix, and implementing targeted code changes to eliminate entire classes of vulnerabilities. This position requires close collaboration with product engineers on a platform handling sensitive financial and tax data, where security is paramount.

Requirements

  • 4+ years of security engineering experience with deep expertise in application security.
  • Thorough understanding of major vulnerability classes, including their introduction, exploitation, and durable fixes.
  • Proven experience improving the security posture of a production platform.
  • Hands-on experience with SAST, DAST, and SCA tooling and CI/CD integration (e.g., Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite).
  • Judgment to identify and prioritize critical security findings.
  • Genuine enthusiasm for building with LLMs and AI agents, including experience automating security work with them.
  • Ability to write and evaluate prompts and workflows for reliable agentic tooling.
  • Sufficient software engineering skill to make confident, well-scoped changes in a production codebase (Python/Django on AWS experience is a plus).
  • Experience driving remediation through teams without direct management authority.
  • Product empathy, optimizing for fixed vulnerabilities and providing security feedback that engineers can act on.

Nice To Haves

  • Experience building large systems from scratch is not the focus; landing precise changes in existing code is.
  • Ability to read unfamiliar code.
  • Experience shipping a paved-path library.
  • Experience fixing vulnerability patterns across a service.

Responsibilities

  • Build and operate an agentic application security program, including the full testing stack (SAST, DAST, SCA) integrated into CI/CD.
  • Implement LLM-based triage to differentiate real security findings from noise.
  • Develop automated security reviews for pull requests to ensure security feedback is delivered within minutes.
  • Drive vulnerability remediation end-to-end, including triaging and rating findings, routing fixes, tracking closure against SLAs, and verifying fixes.
  • Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes.
  • Lead threat modeling and security reviews for new features and platform changes, engaging with product engineers early in the design process.
  • Automate threat modeling practices over time, enabling agents to draft and update threat models as the system evolves.
  • Tune and evolve the program's signal quality by developing new rules, improving prompts, and reducing false positives.
  • Stay current on the vulnerability landscape relevant to fintech platforms handling sensitive data and translate this knowledge into concrete program changes.

Benefits

  • Hybrid Work Model (balance of in-office and remote flexibility in San Francisco)
  • Fresh Lunch provided on in-office days
  • $150 monthly commuter reimbursement
  • $200 quarterly health & wellness reimbursement
  • Flexible PTO
  • 14 company holidays
  • 100% medical, dental, and vision coverage for employees
  • 75% coverage for dependents
  • 16 weeks fully paid parental leave
  • 401k plan
  • Equity package
  • Quarterly virtual team events
  • Annual in-person summit
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service