Product Security Engineer at Collective
San Francisco, CA
$170,000–$200,000
Jul 16, 2026
San Francisco, CA
Jul 21, 2026
What this job asks for AI summary
A hands-on application security engineering role focused on building and running an AI-driven security program for a fintech platform that handles members' financial and tax data. Day-to-day work spans designing agentic pipelines for SAST, DAST, and dependency scanning integrated into CI/CD, leading threat modeling, driving vulnerability remediation end to end, and shipping framework-level fixes that eliminate whole vulnerability classes. Suits someone with deep appsec knowledge who is comfortable making targeted changes in a production Python/Django codebase and building with LLMs to automate security workflows.
Senior level · 4+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 2,500 people nationally plausibly meet what this posting asks for (information security analysts). range 730–3,700
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The JD describes a hybrid role based in San Francisco, but the caller has declared this fully remote with a national candidate pool — metro has been left blank accordingly.
Semgrep, CodeQL, and Bandit are listed together as examples of SAST tooling under the requirements section with 'or equivalent'; Semgrep is used as the primary name with CodeQL and Bandit as alternatives.
OWASP ZAP and Burp Suite are listed as DAST tool examples under the requirements section; OWASP ZAP is primary with Burp Suite as an alternative.
LLMs/AI agents are firmly required — the JD gates on genuine hands-on experience building with them for security automation, stated in the 'What you'll bring' section.
Python and Django appear in a parenthetical stack note ('we run Python/Django on AWS') within the requirements section. Python is treated as a hard gate given the explicit expectation of making confident code changes in the production codebase; Django and AWS are treated as preferred since they appear as contextual stack color rather than explicit gates.
No compensation figures are provided in the posting.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.