Staff Security Engineer
Own end-to-end security for a fintech platform: authentication/authorization architecture, SAST/DAST in CI/CD, threat modeling, and CCPA compliance. Senior IC role requiring 8+ years in application security.
About the job
What you'll do
- Own the end-to-end authentication and authorization architecture across Collective's member platform, including session management, role-based access control, and the emerging patterns needed to secure agent-based workflows and service-to-service communication.
- Drive CCPA compliance across the platform, partnering with Legal and Engineering to map data flows, implement required access and deletion controls, and establish ongoing audit and reporting mechanisms.
- Design and maintain Collective's static and dynamic application security testing (SAST/DAST) frameworks, integrating them into CI/CD pipelines so security feedback is fast, automated, and actionable for product teams.
- Lead threat modeling for new features and platform changes, collaborating with product engineers early in the design process to identify and address risk before it reaches production.
- Define and maintain security standards, policies, and runbooks that give engineering teams clear guardrails without slowing down delivery.
- Respond to and lead post-incident security reviews, driving root-cause analysis and translating findings into durable platform improvements.
- Evaluate and integrate third-party security tooling, staying current on the threat landscape relevant to fintech platforms handling sensitive financial and tax data.
What you'll bring
- 8+ years of security engineering experience, with depth in application security and a track record of improving security posture on production platforms at scale.
- Strong expertise in authentication and authorization systems (OAuth 2.0, OIDC, SAML, JWT) and the nuances of securing both user-facing sessions and machine-to-machine flows, including AI agent authentication patterns.
- Hands-on experience building or owning SAST/DAST programs and embedding security testing into CI/CD pipelines; familiarity with tools like Semgrep, Snyk, Burp Suite, or equivalent.
- Working knowledge of CCPA (and ideally GDPR) compliance requirements as they apply to a SaaS platform handling personal financial data, including data mapping, subject rights workflows, and audit trails.
- Experience collaborating with Legal and Privacy teams to translate regulatory requirements into concrete engineering controls, not just documentation.
- Comfort operating as a senior individual contributor who influences platform direction without requiring a management chain to get things done — you write RFCs, lead design reviews, and bring engineers along through conviction and clarity.
- Product empathy: the ability to hold security rigor and member experience in the same frame, and to make the right tradeoffs with both in mind.
- Familiarity with AI-assisted development workflows and an interest in the security implications of agent-based systems is a strong plus.
Skills
Oauth 2.0, OIDC, SAML, Jwt, SAST, DAST, Semgrep, Snyk, Burp Suite, CCPA, GDPR
Similar jobs
Security Engineering jobsOwn the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.