Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API
AWS
Agentic AI @ 4
Azure
ChatGPT @ 6
Communication @ 7
Compliance @ 4
DevOps @ 3
GCP
Java @ 4
JavaScript @ 4
OWASP @ 3
Python @ 4
Security @ 6
Software Development @ 4
Technical Leadership
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Collibra is seeking a Senior Product Security Engineer to identify vulnerabilities and provide expert remediation consulting for global product development teams. The role provides technical leadership and oversight to help deliver secure, resilient products and services. You will act as an application security evangelist, partner with engineers to accelerate secure time-to-value, and leverage AI and MCP to create context-aware security automation.
Responsibilities
- Perform application penetration testing across web applications, APIs, and thick clients.
- Perform internal and external network penetration testing.
- Apply cloud-service penetration-testing tradecraft and methodologies across AWS, Azure, and GCP.
- Conduct threat modeling and source-code reviews.
- Ensure quality reports and services are delivered efficiently and on time.
- Collaborate with cross-functional teams to integrate security best practices into the development process.
- Build relationships with engineering teams to enable remediation of discovered vulnerabilities.
- Continue developing professional skills through relevant industry certifications and training.
- Assist with triaging code-security findings from SAST, SCA, IAST, and DAST tools when necessary.
- Leverage AI and MCP to create intelligent, context-aware security guidance and automation.
- Triage security incidents when needed.
- Mentor junior teammates and help mature security practices.
Requirements
- 5+ years of relevant penetration testing, product security, and application security experience.
- 2+ years securing Java, Python, and/or JavaScript web applications.
- Experience with advanced security tools and techniques for simulating real-world attacks.
- Familiarity with OSSTMM, OWASP, SAMM, NIST Special Publications, and PTES.
- Experience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.
- Strong working knowledge of at least two programming or scripting languages.
- Familiarity with best practices for securing SDLC and DevOps processes.
- Experience with AI security tooling and context-aware SSDLC automation.
- Understanding of AI privacy and governance in developer workflows.
- Experience using and building collaborative agentic AI systems.
- Demonstrated proficiency using AI tools such as Claude, Gemini, ChatGPT, and Copilot to solve business challenges, drive measurable outcomes, or streamline workflows.
- Bachelor's degree or equivalent certification and experience.
- Strong verbal and written communication skills, including the ability to produce assessment reports, presentations, and operating procedures.
- This position is not eligible for visa sponsorship.
Preferred Experience
- Relevant security certifications such as OSCP, OSWE, or CRTP.
- Red-team or purple-team operations.
- Working knowledge of Python, Java, and/or JavaScript software development languages.
- Experience performing security assessments against containerized cloud environments.
- Familiarity with AI standards and regulations, including the EU AI Act, SAIF, and ISO 42001.
Measures of Success
- Within the first month, build foundational knowledge of Collibra's processes, tools, and SDLC, and design and implement repeatable penetration-testing methodologies tailored to the environment.
- Within the first three months, independently plan and execute penetration-testing engagements and partner with development teams to understand, prioritize, and remediate identified security issues.
- Within the first six months, partner with the leader to develop a security roadmap for comprehensive, proactive assessments across Collibra, incorporating threat intelligence to anticipate emerging threats and identify potential security gaps.
Benefits
The compensation package includes bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, health coverage, and time off. Collibra also provides flexible benefits offerings and supports diversity, equity, and inclusion.
More jobs at Collibra
Global Practitioner
Collibra · United States
USD 168,000-210,000 per year
Senior Enterprise Solution Architect, Federal
Collibra · Fayetteville, United States
USD 152,000-190,000 per year
Premium Support Engineer
Collibra · New York City, United States, Raleigh, United States
USD 116,000-145,000 per year
Senior Manager, Platform Operations
Collibra · United States
USD 168,000-210,000 per year
Senior Director, IT Systems
Collibra · New York City, United States, Raleigh, United States
USD 204,000-255,000 per year
Similar jobs
Senior Product Security Engineer
Collibra · Raleigh, United States
USD 168,000-210,000 per year
Principal Software Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 272,000-431,200 per year
Engineering Manager, GRC Platform
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 320,000-405,000 per year
Senior Software Engineer II
Confluent · Seattle, United States, United States
USD 197,400-232,000 per year
Software Engineer - Privacy & Compliance
OpenAI · San Francisco, United States, Seattle, United States
USD 230,000-385,000 per year
Software Engineer, Secure Development Engineering
Airbnb · United States
USD 162,000-186,000 per year
Strategic Solutions Engineer
Glean · Mountain View, United States
USD 160,000-235,000 per year
Senior Systems Software Engineer, Developer Productivity and Cloud Automation - GeForce NOW
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year