Skip to content

Staff Security Engineer

Own end-to-end security for a fintech platform: authentication/authorization architecture, SAST/DAST in CI/CD, threat modeling, and CCPA compliance. Senior IC role requiring 8+ years in application security.

About the job

What you'll do

  • Own the end-to-end authentication and authorization architecture across Collective's member platform, including session management, role-based access control, and the emerging patterns needed to secure agent-based workflows and service-to-service communication.
  • Drive CCPA compliance across the platform, partnering with Legal and Engineering to map data flows, implement required access and deletion controls, and establish ongoing audit and reporting mechanisms.
  • Design and maintain Collective's static and dynamic application security testing (SAST/DAST) frameworks, integrating them into CI/CD pipelines so security feedback is fast, automated, and actionable for product teams.
  • Lead threat modeling for new features and platform changes, collaborating with product engineers early in the design process to identify and address risk before it reaches production.
  • Define and maintain security standards, policies, and runbooks that give engineering teams clear guardrails without slowing down delivery.
  • Respond to and lead post-incident security reviews, driving root-cause analysis and translating findings into durable platform improvements.
  • Evaluate and integrate third-party security tooling, staying current on the threat landscape relevant to fintech platforms handling sensitive financial and tax data.

What you'll bring

  • 8+ years of security engineering experience, with depth in application security and a track record of improving security posture on production platforms at scale.
  • Strong expertise in authentication and authorization systems (OAuth 2.0, OIDC, SAML, JWT) and the nuances of securing both user-facing sessions and machine-to-machine flows, including AI agent authentication patterns.
  • Hands-on experience building or owning SAST/DAST programs and embedding security testing into CI/CD pipelines; familiarity with tools like Semgrep, Snyk, Burp Suite, or equivalent.
  • Working knowledge of CCPA (and ideally GDPR) compliance requirements as they apply to a SaaS platform handling personal financial data, including data mapping, subject rights workflows, and audit trails.
  • Experience collaborating with Legal and Privacy teams to translate regulatory requirements into concrete engineering controls, not just documentation.
  • Comfort operating as a senior individual contributor who influences platform direction without requiring a management chain to get things done — you write RFCs, lead design reviews, and bring engineers along through conviction and clarity.
  • Product empathy: the ability to hold security rigor and member experience in the same frame, and to make the right tradeoffs with both in mind.
  • Familiarity with AI-assisted development workflows and an interest in the security implications of agent-based systems is a strong plus.

Skills

Oauth 2.0, OIDC, SAML, Jwt, SAST, DAST, Semgrep, Snyk, Burp Suite, CCPA, GDPR

Lob

Lob

United States

Staff Security Engineer, Cloud and Product Security
$198k+/yrRemote8+ YOESecurity Engineering

Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.

Illumio

Illumio

Sunnyvale, CA

Staff Engineer - Container Security
$194k+/yrOn-site8+ YOESecurity Engineering

Build and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.

Upside

Upside

Washington, DC
Staff Application Security Engineer
$210k+/yrRemote6+ YOESecurity Engineering

Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.

Reddit

Reddit

United States

Staff Software Engineer - Site Defense
$217k+/yrRemote7+ YOESecurity Engineering

Design and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.

Grow Therapy

Grow Therapy

Seattle, WA
Senior/Staff Engineer, Application & Product Security
$182k+/yrRemote6+ YOESecurity Engineering

Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.