380,223open jobs
9,940companies
48,310added this week
Browse all
Salary
$195k – $260k per year
Location
Remote/Hybrid (San Francisco, United States)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

About Collective:

Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping, tax services, and access to a thriving community, all in one integrated platform. We believe in empowering self-employed people to enjoy the same tax savings that big companies get, so they can focus on their passion, not paperwork.

Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more. We are backed by General Catalyst, Sound Ventures (Ashton Kutcher and Guy Oseary), QED Investors, Google’s Gradient Ventures, Expa, and other investors who have financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft.

About the role:

We're hiring a Senior/Staff Product Security Engineer to build the security-critical systems at the heart of Collective's member platform. This is a software engineering role first: you'll design and ship the code that governs how our platform authenticates users and services, what they're authorized to do, and how our members' data is protected. You'll own the authentication and authorization architecture end to end - not as a reviewer or advisor, but as the engineer whose commits land in production. You'll set the direction of this work, not just execute it: what gets built and in what order. As Collective expands its use of AI and agent-based workflows, you'll build the patterns those systems use to authenticate and operate safely. You'll sit on the Security team and spend your days in the product codebase, working alongside product engineers.

What you'll do:

  • Own the end-to-end authentication and authorization architecture of Collective's member platform - session management, multi-factor authentication, authorization enforcement, and machine-to-machine authentication - and personally design, write, and ship the changes that improve it.

  • Extend those patterns to delegated and agent-based access: how AI agents and third parties act on a member's behalf with scoped, time-boxed, revocable authority - and how their actions are attributed and audited.

  • Drive the programmatic protection of sensitive member data: design and implement application-layer encryption for member documents and data - key management, envelope encryption, rotation - and build the controls that protect sensitive data in code (scoped access, tokenization, redaction in logs and pipelines) rather than in policy.

  • Lead the design process for the systems you own: write RFCs, run design reviews, and bring product engineers along on security-critical changes.

  • Threat-model the identity and data-protection systems you build, and own remediation of findings that touch your domain.

  • Ground encryption and access-control decisions in the regulatory requirements that apply to a platform handling sensitive member data.

What you'll bring:

  • 8+ years of software engineering experience, including significant time building or owning authentication, identity, authorization, or data-protection systems in production.

  • Strong backend engineering skills - you're fluent shipping production code in a modern web stack (we run Python/Django on AWS), and you're comfortable making substantial changes to a codebase other teams depend on.

  • Deep working knowledge of authentication standards and their failure modes: OAuth 2.0 (including token exchange and delegation patterns), OIDC, SAML, JWT, session management, and the differences between securing user-facing and machine-to-machine flows.

  • Practical applied-cryptography literacy: envelope encryption, KMS-based key management, key rotation, and the tradeoffs of encrypting data at the field, document, and storage layers. You don't need to be a cryptographer - you need to know how to use cryptography correctly in a production system.

  • Enough security fluency to reason about threats to the systems you build and to hold your own in a threat-modeling session. Deep security specialization is not required - you'll have teammates who bring it; what can't be delegated is the engineering.

  • Comfort operating as a senior individual contributor who influences platform direction through RFCs, design reviews, and working code rather than a management chain.

  • Product empathy: the ability to hold security rigor and member experience in the same frame - auth flows are the front door of the product, and getting them wrong in either direction is expensive.

What we offer:

  • Hybrid Work Model: Based in San Francisco with a balance of in-office and remote flexibility.

  • Fresh Lunch: Provided on in-office days.

  • Commuter Support: $150 monthly reimbursement for transit expenses.

  • Health & Wellness: $200 quarterly reimbursement to support your well-being.

  • Time Off: Flexible PTO plus 14 company holidays.

  • Comprehensive Coverage: 100% medical, dental, and vision for employees; 75% coverage for dependents.

  • Parental Leave: 16 weeks fully paid.

  • Retirement & Ownership: 401k plan plus an equity package.

  • Team Connection: Quarterly virtual events and an annual in-person summit.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
380,223 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$181k – $326k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • United States
Python
TypeScript
AI/ML
AI Agents
Apply
$160k – $180k per year • Equity 0.1–0.2% • In office • Full-Time • New York
Python
TypeScript
Databases
PostgreSQL
Frontend
Next.js
React.js
DevOps
AWS
Apply
In office • 5+ years exp • Bachelor's Degree
Python
DevOps
CI/CD
Git
Chips/EDA
Vitis
IoT
FreeRTOS
Apply
In office • 3+ years exp • Bachelor's Degree
Python
Python
PyQt
AI/ML
NumPy
Pandas
SciPy
DevOps
Git
Management
Jira
Apply
Remote/Hybrid • Full-Time • Singapore
C#
Java
Python
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
Kafka
Frontend
Angular
React.js
Vue.js
DevOps
CI/CD
Kubernetes
WebSockets
Cybersecurity
Volatility
Apply
IT Support Engineer 7 hours ago
$160k – $189k per year • Equity • Remote/Hybrid • Full-Time • 3+ years exp • San Francisco
Python
Management
Google Workspace
Marketing
YouTube
Apply
$127k – $190k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp
Python
SQL
Databases
BigQuery
Google BigQuery
AI/ML
AI Agents
Claude
Claude Code
dbt
Human-in-the-Loop
LLM
LLM Evaluation
Analytics
Metabase
Marketing
YouTube
Apply
$170k – $200k per year • Equity • Remote/Hybrid • Full-Time • 3+ years exp • San Francisco
Python
SQL
Python
Django
Databases
BigQuery
Google BigQuery
AI/ML
AI Agents
Marketing
YouTube
Apply
$215k – $255k per year • Equity • Remote/Hybrid • Full-Time • 7+ years exp • San Francisco
AI/ML
AI Agents
Human-in-the-Loop
Marketing
YouTube
Apply
$195k – $230k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • San Francisco
Python
JavaScript
Python
Django
AI/ML
AI Agents
Frontend
React.js
Marketing
YouTube
Apply
$70k – $206k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Dallas • Milwaukee • Columbus • Kirkland • Cincinnati
C++
Java
Python
Rust
TypeScript
AI/ML
AI Agents
LLM
Model Context Protocol
DevOps
AWS
Azure
CI/CD
GCP
Apply
$94k – $294k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Dallas • Milwaukee • Columbus • Kirkland • Cincinnati
C++
Java
Python
Rust
TypeScript
AI/ML
AI Agents
LLM
Model Context Protocol
DevOps
AWS
Azure
CI/CD
GCP
Apply
$197k – $314k per year • In office • Full-Time • 7+ years exp • PhD • San Francisco • Washington
Apex
Apex
MuleSoft
AI/ML
Agentforce
AI Agents
LLM
Model Context Protocol
Marketing
Salesforce
Apply
$173k – $314k per year • Remote • Full-Time • 10+ years exp • PhD • San Francisco • Boston • Chicago • New York • Austin
AI/ML
Agentforce
AI Agents
LLM
LLM Guardrails
Marketing
Salesforce
Apply
$183k – $216k per year • Equity • Remote • Full-Time • 5+ years exp • San Francisco • Seattle • New York
AI/ML
AI Agents
LLM
Apply
See all jobs
This is one of many
380,223 more open roles from verified company boards, updated every day.