# Product Security Engineer

**Company:** [Collective Intelligence Project](https://hotfix.jobs/companies/collective-intelligence-project)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $170k – $200k/yr
**Experience:** 4+ years
**Skills:** Application Security, SAST, DAST, sca, semgrep, codeql, bandit, owasp zap, burp suite, LLMs, AI Agents, Python, Django, AWS, Threat Modeling
**Posted:** 2026-07-17

> Build and operate an agentic application security program using AI for automated testing, triage, and PR review. Drive end-to-end vulnerability remediation, eliminate vulnerability classes via code changes, and lead threat modeling for a fintech platform handling sensitive financial data. Requires 4+ years appsec experience, hands-on tooling expertise, enthusiasm for LLMs, and Python engineering skills.

## Job Description

## What you'll do
- Build and operate an agentic application security program: integrate SAST, DAST, and SCA into CI/CD, use LLM-based triage to reduce noise, and implement automated security review of pull requests for fast feedback.
- Drive vulnerability remediation end-to-end: triage findings from scanners, penetration tests, and researchers; route fixes to teams; track to closure against SLAs; and verify fixes.
- Eliminate vulnerability classes at the root by shipping secure defaults, paved-path libraries, and framework-level fixes through targeted code changes in the product codebase.
- Lead threat modeling and security review for new features, engaging early with product engineers; automate the practice so threat models are living documents drafted by agents.
- Tune and evolve the program's signal quality with new rules, better prompts, and fewer false positives, treating the agentic pipeline as an iterated product.
- Stay current on vulnerabilities relevant to a fintech platform handling financial and tax data and translate insights into program changes.

## What you'll bring
- 4+ years of security engineering experience with deep application security knowledge of major vulnerability classes (introduction, exploitation, durable fixes) and improving production platform security posture.
- Hands-on experience with SAST, DAST, and SCA tooling (Semgrep, CodeQL, Bandit, OWASP ZAP, Burp Suite or equivalents) and CI/CD integration, plus judgment on which findings matter.
- Genuine enthusiasm for building with LLMs and AI agents: experience using them to automate security work, writing/evaluating prompts and workflows for reliable agentic tooling.
- Sufficient software engineering skills to make confident changes in a production codebase (Python/Django on AWS), including reading unfamiliar code, shipping libraries, and fixing vulnerability patterns across services.
- Experience driving remediation through un-managed teams with clear writeups, defensible severity calls, and persistence without damaging relationships.
- Product empathy to shape security feedback that engineers act on, optimizing for fixed vulnerabilities.

## Similar roles

- [Endpoint Security Engineer](https://hotfix.jobs/jobs/e9f904e5-b1d3-4a26-b61e-06c5e375ab90) - Crusoe - San Francisco, CA - $170k – $205k/yr
- [Software Engineer, Trust & Safety](https://hotfix.jobs/jobs/7d005694-1f26-43da-8d18-cb58960d2d1e) - Suno - San Francisco, CA - $170k – $240k/yr
- [Vulnerability Automation Engineer](https://hotfix.jobs/jobs/1a05493d-ddf1-4123-8eaa-22774b293d93) - Lumin Digital - Remote - $170k – $190k/yr
- [Software Engineer, Security Infrastructure](https://hotfix.jobs/jobs/10bace96-4568-4b74-8991-363cb538257c) - Siftstack - Marina del Rey, CA - $170k – $220k/yr
- [Incident Response Security Engineer](https://hotfix.jobs/jobs/d002a19f-a1ab-4434-977e-b1a71be0e1c8) - Clickhouse - Remote - $169k – $225k/yr

**Apply:** https://hotfix.jobs/jobs/04dc8629-c86c-4c38-a6ac-226ed3e7a745
**Canonical:** https://hotfix.jobs/jobs/04dc8629-c86c-4c38-a6ac-226ed3e7a745