Senior Product Security Engineer
CollibraRemote (USA)2w ago
SecurityEngineeringremotecurated-jd
Job description
Senior Product Security Engineer at Collibra
About the role
Collibra seeks a Senior Product Security Engineer to join its Product Security team. This role is crucial for finding security weaknesses and guiding development teams on how to fix them. You will provide technical direction to ensure Collibra's products remain secure for customers.
Key facts
What you'll do
- Conduct penetration tests on web applications, APIs, and thick clients.
- Perform network penetration tests for both internal and external systems.
- Test cloud services on AWS, Azure, and GCP.
- Analyze source code for security flaws.
- Develop threat models for new and existing features.
- Create clear and timely reports on security findings.
- Work with engineering teams to integrate security into their development processes.
- Help engineering teams fix identified vulnerabilities.
- Use AI and MCP to build automated security guidance for developers.
- Assist in reviewing security findings from SAST, SCA, IAST, and DAST tools.
Requirements
- A minimum of 5 years of experience in penetration testing, product security, or application security.
- At least 2 years of experience securing web applications built with Java, Python, or JavaScript.
- Experience with advanced security tools for simulating attacks.
- Familiarity with security testing standards like OSSTMM, OWASP, SAMM, NIST SPs, and PTES.
- Experience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.
- Strong working knowledge of at least two programming or scripting languages.
- Understanding of secure SDLC and DevOps security best practices.
- Ability to triage security incidents.
- Experience with AI security tools and context-aware SSDLC automation.
- Understanding of AI privacy and governance in development workflows.
- Experience using and building collaborative agentic AI systems.
- Demonstrated ability to use AI tools like Claude, Gemini, ChatGPT, or Copilot to solve business problems and improve workflows.
- A Bachelor's degree or equivalent related work experience.
- This position is not eligible for visa sponsorship.
Nice to have
- Security certifications such as OSCP, OSWE, or CRTP.
- Experience with Red/Purple team operations.
- Experience performing security assessments on containerized cloud environments.
- Familiarity with AI standards and regulations like the EU AI Act, SAIF, and ISO 42001.
Skills & tools
- Penetration Testing (Web App, API, Thick Client)
- Network Penetration Testing (Internal, External)
- Cloud Security Testing (AWS, Azure, GCP)
- Threat Modeling
- Source Code Review
- SAST, SCA, IAST, DAST tools
- Java, Python, JavaScript
- AI Security Tooling
- Claude, Gemini, ChatGPT, Copilot
Practical notes
Compensation for this role is between $168,000.00 and $210,000.00 per year, based on factors including experience, skills, and location. Collibra offers a comprehensive benefits package including bonus potential, equity for eligible roles, a Flex Fund stipend, and retirement plans.