Collective
Fintech
StaffSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Staff Security Engineer at Collective. Skills: Application security, Authentication, Authorization, Compliance. Own authentication and authorization architecture. Manage sessions”
Industry & Context.
Root cause analysis
What They're Looking For.
Must Have
8+ years security engineering experience, Depth in application security, Track record of improving security posture at scale, Expertise in authentication and authorization systems, Hands-on experience building or owning SAST/DAST programs, Embedding security testing into CI/CD, Working knowledge of CCPA compliance, Experience collaborating with Legal and Privacy teams, Comfort operating as a senior individual contributor
Nice to Have
Familiarity with GDPR compliance, Familiarity with AI-assisted development workflows, Interest in security implications of agent-based systems
What You'll Do.
Own authentication and authorization architecture
Implement role-based access control
Secure agent-based workflows
Secure service-to-service communication
Drive CCPA compliance
Implement access controls
Implement deletion controls
Establish audit mechanisms
Establish reporting mechanisms
Design SAST frameworks
Design DAST frameworks
Maintain SAST frameworks
Maintain DAST frameworks
Integrate security testing into CI/CD
Provide actionable security feedback
Define security standards
Define security policies
Respond to security incidents
Lead post-incident reviews
Drive root-cause analysis
Translate findings into improvements
Evaluate security tooling
Integrate security tooling
Stay current on threat landscape
How You'll Work.
Team & Collaboration
Engineering; Product; Legal; Privacy teams; Product engineers
Full Job Description
About Collective: Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping, tax services, and access to a thriving community, all in one integrated platform. We believe in empowering self-employed people to enjoy the same tax savings that big companies get, so they can focus on their passion, not paperwork. Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more. We are backed by General Catalyst, Sound Ventures (Ashton Kutcher and Guy Oseary), QED Investors, Google’s Gradient Ventures, Expa, and other investors who have financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role: We're hiring a Staff Security Engineer to own the security of Collective's member platform end to end — from how code is written and tested to how data is protected and how our systems authenticate. This is a senior individual contributor role with broad product-security scope: you'll embed security into the development lifecycle, lead threat modeling and security reviews across the platform, and own the authentication, authorization, and compliance systems that keep our members' financial and tax data trustworthy. As Collective expands its use of AI and agent-based workflows, you'll shape how those systems authenticate and operate securely. You'll work closely with Engineering, Product, and Legal to make security a first-class property of everything we ship — without slowing the team down. What you'll do: - Own the end-to-end authentication and authorization architecture across Collective's member platform, including session management, role-based access control, and the emerging patterns needed to secure agent-based workflows and service-to-service communication. - Drive CCPA compliance across the platform, partnering with
Applying for this Staff Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Collective?
Real rants from real employees. Read before you apply.