Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API
AWS
Agentic AI @ 4
Azure
ChatGPT @ 6
Communication @ 7
Compliance @ 4
DevOps @ 3
GCP
Java @ 4
JavaScript @ 4
OWASP @ 3
Python @ 4
Security @ 4
Technical Leadership
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Collibra is seeking a Senior Product Security Engineer to join its Product Security team. The role is responsible for identifying vulnerabilities, providing remediation consulting to global product development teams, and providing technical leadership to help deliver secure and resilient products and services. The position also involves acting as an application security evangelist and using AI and MCP to create context-aware security automation.
Responsibilities
- Perform application penetration testing across web applications, APIs, and thick clients.
- Perform internal and external network penetration testing.
- Apply cloud service penetration-testing methodologies across AWS, Azure, and GCP.
- Conduct threat modeling and source-code reviews.
- Ensure security reports and services are delivered efficiently and on time.
- Collaborate with cross-functional teams to integrate security best practices into the development process.
- Build relationships with engineering teams to enable remediation of identified vulnerabilities.
- Continue developing professional skills through relevant certifications and training.
- Triage Code Security findings from SAST, SCA, IAST, and DAST tools when necessary.
- Leverage AI and MCP to create intelligent, context-aware security guidance and automation.
- Triage security incidents when needed.
- Produce assessment reports, presentations, and operating procedures.
- Mentor junior teammates and help mature security practices.
- Develop repeatable penetration-testing methodologies tailored to Collibra's environment.
- Plan and execute penetration-testing engagements and partner with development teams to understand, prioritize, and remediate security issues.
- Help develop a proactive security roadmap and use threat intelligence to anticipate emerging threats and identify security gaps.
Requirements
- At least 5 years of relevant penetration testing, product security, and application security experience.
- At least 2 years of experience securing Java, Python, and/or JavaScript web applications.
- Experience with advanced security tools and techniques for simulating real-world attacks.
- Familiarity with OSSTMM, OWASP, SAMM, NIST Special Publications, and PTES.
- Experience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.
- Strong working knowledge of at least two programming or scripting languages.
- Familiarity with best practices for securing SDLC and DevOps processes.
- Experience with AI security tooling and context-aware SSDLC automation.
- Understanding of AI privacy and governance in developer workflows.
- Experience using and building collaborative agentic AI systems.
- Demonstrated proficiency with AI tools such as Claude, Gemini, ChatGPT, and Copilot to solve business challenges, drive measurable outcomes, or streamline workflows.
- Bachelor's degree or equivalent certification and experience.
- Strong verbal and written communication skills.
- Relevant security certifications are strongly preferred, including OSCP, OSWE, or CRTP.
- Experience with red-team or purple-team operations.
- Working knowledge of Python, Java, and/or JavaScript.
- Experience performing security assessments against containerized cloud environments.
- Familiarity with AI standards and regulations, including the EU AI Act, SAIF, and ISO 42001.
- This position is not eligible for visa sponsorship.
Compensation
The standard base salary range is $168,000.00–$210,000.00 per year. The position is not eligible for additional commission-based compensation. Salary offers are based on factors including experience, skills, and location. Additional compensation and benefits may include bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401(k) plans, health coverage, and time off.
Company Information
Collibra is an equal opportunity employer committed to inclusion and belonging. Accommodation support is available for applicants who require it.