Collective

Fintech

StaffSecurityEngineer

$200–260k San Francisco, California, United States FULL TIME Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Staff Security Engineer at Collective. Skills: Application security, Authentication, Authorization, Compliance. Own authentication and authorization architecture. Manage sessions”

Industry & Context.

Fintech
Problems you'll solve

Root cause analysis

What They're Looking For.

Must Have

8+ years security engineering experience, Depth in application security, Track record of improving security posture at scale, Expertise in authentication and authorization systems, Hands-on experience building or owning SAST/DAST programs, Embedding security testing into CI/CD, Working knowledge of CCPA compliance, Experience collaborating with Legal and Privacy teams, Comfort operating as a senior individual contributor

Nice to Have

Familiarity with GDPR compliance, Familiarity with AI-assisted development workflows, Interest in security implications of agent-based systems

What You'll Do.

Own authentication and authorization architecture

Implement role-based access control

Secure agent-based workflows

Secure service-to-service communication

Drive CCPA compliance

Implement access controls

Implement deletion controls

Establish audit mechanisms

Establish reporting mechanisms

Design SAST frameworks

Design DAST frameworks

Maintain SAST frameworks

Maintain DAST frameworks

Integrate security testing into CI/CD

Provide actionable security feedback

Define security standards

Define security policies

Respond to security incidents

Lead post-incident reviews

Drive root-cause analysis

Translate findings into improvements

Evaluate security tooling

Integrate security tooling

Stay current on threat landscape

How You'll Work.

Team & Collaboration

Engineering; Product; Legal; Privacy teams; Product engineers

Full Job Description

About Collective: Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping, tax services, and access to a thriving community, all in one integrated platform. We believe in empowering self-employed people to enjoy the same tax savings that big companies get, so they can focus on their passion, not paperwork. Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more. We are backed by General Catalyst, Sound Ventures (Ashton Kutcher and Guy Oseary), QED Investors, Google’s Gradient Ventures, Expa, and other investors who have financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role: We're hiring a Staff Security Engineer to own the security of Collective's member platform end to end — from how code is written and tested to how data is protected and how our systems authenticate. This is a senior individual contributor role with broad product-security scope: you'll embed security into the development lifecycle, lead threat modeling and security reviews across the platform, and own the authentication, authorization, and compliance systems that keep our members' financial and tax data trustworthy. As Collective expands its use of AI and agent-based workflows, you'll shape how those systems authenticate and operate securely. You'll work closely with Engineering, Product, and Legal to make security a first-class property of everything we ship — without slowing the team down. What you'll do:  - Own the end-to-end authentication and authorization architecture across Collective's member platform, including session management, role-based access control, and the emerging patterns needed to secure agent-based workflows and service-to-service communication. - Drive CCPA compliance across the platform, partnering with

Free ATS check

Applying for this Staff Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Collective?

Real rants from real employees. Read before you apply.

Read Company Rants →