Product Security Engineer

CollectiveSan Francisco, CA
$170,000 - $200,000Hybrid

About The Position

Collective is seeking a Product Security Engineer to establish and lead the company's application security program, with a strong emphasis on AI agents from the outset. This role moves beyond traditional security tasks, focusing on designing and managing an agentic application security pipeline. This pipeline will integrate automated security testing (static analysis, dynamic testing, dependency scanning) with AI-driven triage and automated code review for pull requests, providing rapid, high-signal feedback to engineering teams. The engineer will also be responsible for driving vulnerability remediation across the platform, from identification to verified fix, and implementing targeted code changes to eliminate entire classes of vulnerabilities. This position requires close collaboration with product engineers on a platform handling sensitive financial and tax data, where security is paramount.

Requirements

  • 4+ years of security engineering experience with deep expertise in application security, including a thorough understanding of major vulnerability classes, their introduction, exploitation, and remediation.
  • Proven experience improving the security posture of a production platform.
  • Hands-on experience with SAST, DAST, and SCA tooling and CI/CD integration (e.g., Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite).
  • Ability to discern the significance of security findings.
  • Genuine enthusiasm for building with LLMs and AI agents, including experience automating security work with them.
  • Proficiency in writing and evaluating prompts and workflows for reliable agentic tooling.
  • Sufficient software engineering skill to make confident, well-scoped changes in a production codebase (Python/Django on AWS).
  • Experience driving remediation through cross-functional teams.
  • Clear communication skills for writing vulnerability reports and defending severity calls.
  • Persistence in ensuring fixes are implemented without damaging relationships.
  • Product empathy, optimizing for fixed vulnerabilities over filed tickets.

Nice To Haves

  • Experience building large systems from scratch.
  • Experience landing precise changes in existing codebases.

Responsibilities

  • Build and operate an agentic application security program, including SAST, DAST, and software composition analysis (SCA) integrated into CI/CD, LLM-based triage, and automated security review of pull requests.
  • Drive vulnerability remediation end-to-end, including triaging and rating findings, routing fixes, tracking them to closure against SLAs, and verifying fixes.
  • Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes.
  • Lead threat modeling and security review for new features and platform changes, engaging with product engineers early in the design process and automating the practice over time.
  • Tune and evolve the program's signal quality by developing new rules, improving prompts, and reducing false positives.
  • Stay current on the vulnerability landscape relevant to a fintech platform and translate this knowledge into concrete program changes.

Benefits

  • Hybrid Work Model (balance of in-office and remote flexibility)
  • Fresh Lunch provided on in-office days
  • $150 monthly reimbursement for transit expenses
  • $200 quarterly reimbursement for health and wellness
  • Flexible PTO
  • 14 company holidays
  • 100% medical, dental, and vision coverage for employees
  • 75% coverage for dependents on medical, dental, and vision
  • 16 weeks fully paid parental leave
  • 401k plan
  • Equity package
  • Quarterly virtual team events
  • Annual in-person summit
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service