# Senior Product Security Engineer

[Collibra](https://gurify.com/jobs?q=Collibra) · Remote, United States · Posted 3 months ago

Remote

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/collibra/jobs/7871324)

## Job description

### Joining Collibra’s Product Security team

Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product development teams. This role provides critical technical leadership and oversight, ensuring Collibra continues to deliver secure, resilient products and services to our customers. You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.

### Product Security Engineers at Collibra are responsible for

- Application Penetration Testing (Web-app, API,Thick Client)

- Network Penetration Testing (Internal, External)

- Cloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP)

- Threat Modeling

- Source-Code Reviews

- Ensure quality reports and services are delivered efficiently and on time

- Collaborate with cross-functional teams to ensure that security best practices are integrated into the development process

- Enable remediation of discovered vulnerabilities through the building of relationships with engineering teams

- Continue to develop professional skills with relevant industry specific certifications or training

- Assist with triaging Code Security findings identified by SAST, SCA, IAST, DAST, where necessary.

- Leverage AI and MCP to create intelligent, context-aware security guidance and automation.

### You have

- 5+ years of relevant Penetration Testing, Product Security, and Application Security experience.

- 2+ years securing Java, Python, and/or JavaScript web applications.

- Experience with advanced security tools and techniques for simulating real-world attacks.

- Familiarity with Open-Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Software Assurance Maturity Model (SAMM), National Institute of Standards and Technology (NIST) Special Publications, and PTES (Penetration Testing Execution Standard).

- Experience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.

- Strong working knowledge of at least two programming or scripting languages.

- Familiarity with best practices for securing the SDLC and DevOps processes.

- Ability to triage security incidents when needed.

- Experience with AI security tooling and context-aware SSDLC automation.

- Understanding of AI privacy and governance in developer workflows.

- Experience using and building collaborative agentic AI systems.

- Demonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.

- A Bachelor’s degree or equivalent certification and experience.

- Demonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.

- A bachelor’s degree or equivalent related working experience is required

- This position is not eligible for visa sponsorship

### You are

- Grounded in security principles, policies, and industry best practices.

- An excellent verbal and written communicator, able to produce assessment reports, presentations, and operating procedures.

- A developing or established leader who matures security practices and mentors junior teammates.

- An advocate for the remediation of application security risk and, simultaneously, the associated development/engineering teams.

### Preferred Experience

- Relevant security certifications strongly preferred (e.g. OSCP, OSWE, CRTP)

- Red/Purple team operations

- Possess a working knowledge of Python, Java, and/or JavaScript software development languages

- Experienced in performing security assessments against containerized cloud environments.

- Familiarity with AI standards and regulations, EU AI Act, SAIF and ISO 42001.

### Measures of success

- Within your first month, you will build foundational knowledge of Collibra’s processes, tools, and SDLC. You will use that knowledge to design and implement repeatable penetration-testing methodologies tailored to the environment.

- Within your first three months, you will independently plan and execute penetration-testing engagements, then partner with development teams to understand, prioritize, and remediate identified security issues.

- Within your first six months, you will partner with your leader to develop a security roadmap for comprehensive, proactive assessments across Collibra. You will incorporate threat intelligence to anticipate emerging threats and identify potential security gaps.

### Compensation for this role

The standard base salary range for this position is $168,000.00 - $210,000.00 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location. In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.

### Benefits at Collibra

Collibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about Collibra’s benefits.

We create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about diversity, equity, and inclusion at Collibra.

At Collibra, we’re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.

With this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our Accommodations for Applicants form.

**Live in Collibra’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- SY [SecOps Security Engineer (Staff-level, L6)](https://gurify.com/job/secops-security-engineer-staff-level-l6-at-synthesia-ae4d3d1cff9b) Synthesia · United States · today
- AD [Staff AI Security Engineer](https://gurify.com/job/staff-ai-security-engineer-at-addepar1-b9f9ad310cbf) Addepar1 · Remote, United States · last week
- GI [Intermediate Software Engineer, Security Factory: Vulnerability ...](https://gurify.com/job/intermediate-software-engineer-security-factory-vulnerability-at-1d9ec8f2ea7f) Gitlab · Remote, United States · 5 days ago
- GI [Senior Manager, Product Security Engineering ...](https://gurify.com/job/senior-manager-product-security-engineering-at-gitlab-22f4cbe911d9) Gitlab · Remote, United States · 5 days ago
- SS [Senior Security Engineer](https://gurify.com/job/senior-security-engineer-7a31c77709c6) Cincinnati, United States · 3 weeks ago
- FA [Senior Enterprise Security Engineer](https://gurify.com/job/senior-enterprise-security-engineer-at-faire-74499d70d3ab) Faire · San Francisco, CA · 3 weeks ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Product Security Engineer","description":"\u003Ch3\u003EJoining Collibra\u2019s Product Security team\u003C/h3\u003E\u003Cp\u003ECollibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product development teams. This role provides critical technical leadership and oversight, ensuring Collibra continues to deliver secure, resilient products and services to our customers. You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.\u003C/p\u003E\u003Ch3\u003EProduct Security Engineers at Collibra are responsible for\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EApplication Penetration Testing (Web-app, API,Thick Client)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ENetwork Penetration Testing (Internal, External)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECloud Service penetration testing tradecraft and methodologies across multiple service providers (AWS, Azure, GCP)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThreat Modeling\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESource-Code Reviews\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnsure quality reports and services are delivered efficiently and on time\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with cross-functional teams to ensure that security best practices are integrated into the development process\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnable remediation of discovered vulnerabilities through the building of relationships with engineering teams\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContinue to develop professional skills with relevant industry specific certifications or training\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAssist with triaging Code Security findings identified by SAST, SCA, IAST, DAST, where necessary.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELeverage AI and MCP to create intelligent, context-aware security guidance and automation.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYou have\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E5\u002B years of relevant Penetration Testing, Product Security, and Application Security experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003E2\u002B years securing Java, Python, and/or JavaScript web applications.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with advanced security tools and techniques for simulating real-world attacks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with Open-Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Software Assurance Maturity Model (SAMM), National Institute of Standards and Technology (NIST) Special Publications, and PTES (Penetration Testing Execution Standard).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong working knowledge of at least two programming or scripting languages.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with best practices for securing the SDLC and DevOps processes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to triage security incidents when needed.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with AI security tooling and context-aware SSDLC automation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUnderstanding of AI privacy and governance in developer workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience using and building collaborative agentic AI systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDemonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA Bachelor\u2019s degree or equivalent certification and experience.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDemonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA bachelor\u2019s degree or equivalent related working experience is required\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThis position is not eligible for visa sponsorship\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EYou are\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EGrounded in security principles, policies, and industry best practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAn excellent verbal and written communicator, able to produce assessment reports, presentations, and operating procedures.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA developing or established leader who matures security practices and mentors junior teammates.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAn advocate for the remediation of application security risk and, simultaneously, the associated development/engineering teams.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EPreferred Experience\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ERelevant security certifications strongly preferred (e.g. OSCP, OSWE, CRTP)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ERed/Purple team operations\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPossess a working knowledge of Python, Java, and/or JavaScript software development languages\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperienced in performing security assessments against containerized cloud environments.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with AI standards and regulations, EU AI Act, SAIF and ISO 42001.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EMeasures of success\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EWithin your first month, you will build foundational knowledge of Collibra\u2019s processes, tools, and SDLC. You will use that knowledge to design and implement repeatable penetration-testing methodologies tailored to the environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWithin your first three months, you will independently plan and execute penetration-testing engagements, then partner with development teams to understand, prioritize, and remediate identified security issues.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWithin your first six months, you will partner with your leader to develop a security roadmap for comprehensive, proactive assessments across Collibra. You will incorporate threat intelligence to anticipate emerging threats and identify potential security gaps.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECompensation for this role\u003C/h3\u003E\u003Cp\u003EThe standard base salary range for this position is $168,000.00 - $210,000.00 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location. In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.\u003C/p\u003E\u003Ch3\u003EBenefits at Collibra\u003C/h3\u003E\u003Cp\u003ECollibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about Collibra\u2019s benefits.\u003C/p\u003E\u003Cp\u003EWe create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about diversity, equity, and inclusion at Collibra.\u003C/p\u003E\u003Cp\u003EAt Collibra, we\u2019re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.\u003C/p\u003E\u003Cp\u003EWith this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our Accommodations for Applicants form.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-product-security-engineer-at-collibra-f1c88fa335cc"},"url":"https://gurify.com/job/senior-product-security-engineer-at-collibra-f1c88fa335cc","datePosted":"2026-05-11","validThrough":"2026-10-09T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Collibra","sameAs":"https://job-boards.greenhouse.io/collibra"},"directApply":false,"jobLocationType":"TELECOMMUTE","applicantLocationRequirements":{"@type":"Country","name":"United States"}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United States","item":"https://gurify.com/jobs/united-states"},{"@type":"ListItem","position":3,"name":"Senior Product Security Engineer","item":"https://gurify.com/job/senior-product-security-engineer-at-collibra-f1c88fa335cc"}]}
```
