Senior Product Security Engineer

Collibra

Raleigh (NC)

On-site

USD 168,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive total rewards package
Pension/401k plans
Flex Fund monthly stipend
Bonus potential
Health coverage

Job summary

Collibra is seeking a Senior Product Security Engineer to enhance security for their product development teams in Raleigh, North Carolina. This hybrid role involves identifying vulnerabilities and providing expert remediation consulting, ensuring secure, reliable products for customers.

The ideal candidate will have significant experience in application security, Java, and Python, along with leadership skills to foster collaboration across teams. A competitive salary and flexible benefits are offered.

Qualifications

  • 5 years of application/product security experience.
  • 2 years of experience securing Java, Python, and/or JavaScript web applications.
  • A bachelor’s degree or equivalent relevant experience is required.

Responsibilities

  • Ensure application security for products supported by development teams.
  • Perform security testing and triage findings from penetration tests.
  • Provide remediation consulting for assigned development teams.
  • Manage vulnerability reporting and tracking.

Skills

Application security experience
Experience securing Java, Python, and JavaScript web applications
Knowledge of enterprise-level software architecture components
Building trusted advisor relationships
Understanding of AI privacy and governance
Experience with AI security tooling
Identifying vulnerabilities in source code
Knowledge of CI/CD concepts

Education

Bachelor's degree or equivalent experience

Tools

SAST
DAST
SCA
Python
Java
JavaScript
Linux

Job description

Joining Collibra’s Product Security team

Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product development teams. This role provides critical technical leadership and oversight, ensuring Collibra continues to deliver secure, resilient products and services to our customers. You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.

This is a hybrid role based in our Raleigh office. Our hybrid model means you’ll work from the office at least two days each week. This setup helps us stay connected, work more closely together, and keep making progress as a team.

Product Security Engineers at Collibra are responsible for
  • Application security for products and/or features supported by your assigned development teams.
  • Performing security testing and triaging findings identified by SAST, SCA, IAST, DAST, and penetration tests.
  • Leverage AI and MCP to create intelligent, context-aware security guidance and automation.
  • Providing remediation consulting services to assigned development teams.
  • Assist with vulnerability management reporting and tracking.
  • Coordinating third-party penetration testing engagements, analyzing reports, and opening tickets for remediation.
  • Contribute to the configuration and management of security tools.
You have
  • 5 years of application/product security experience.
  • 2 years of experience securing Java, Python, and/or JavaScript web applications.
  • Knowledge of enterprise-level software architecture components and cloud infrastructure.
  • Experience building trusted advisor relationships with engineers, product owners, and engineering management (up to director level).
  • Experience with AI security tooling, context-aware automation for SSDLC.
  • Understanding of AI privacy and governance in developer workflows.
  • Experience using and building agentic AI systems that work collaboratively.
  • Experience advocating for the remediation of application security risk and, simultaneously, the associated development/engineering team(s).
  • Experience in identifying vulnerabilities in source code, providing detailed steps to reproduce exploitation, and providing recommendations to engineering teams on how to remediate issues.
  • A bachelor’s degree or equivalent related working experience is required.
  • This position is not eligible for visa sponsorship.
  • Because this role supports the US government, it is required that this candidate be a US citizen who resides on US soil.
You are
  • Knowledgeable of CI/CD concepts and experience with integrated SAST, SCA, and DAST tooling.
  • Proficient at triaging application vulnerabilities associated with source code, open-source library dependencies, and 3rd party containers.
  • Able to assess and communicate the impact of Common Vulnerability Weaknesses (CVEs) on custom application software and advise on risk acceptance/deferment for false positive scenarios, severity adjustments, and acceptable reasoning for operational requirements.
  • Experienced in executing as a matrixed/embedded security resource (within a development team) responsible for product, application, or feature group vulnerability assessments, ensuring they are appropriately enumerated and executed.
  • Possess a working knowledge of Python, Java, and/or JavaScript software development languages.
  • Experienced in Linux and containerization in a cloud environment.
  • Experienced in communicating the impact of security vulnerabilities to engineering teams and product leaders.
  • Experienced in using SAST, DAST, and SCA tooling.
  • Experienced in being a point of contact for outside/3rd party security assessments (pen tests, questionnaires, etc.).
  • Knowledgeable of vulnerability management concepts, challenges, and reporting.
  • Possess a working knowledge of the OWASP Top 10 and can explain its concepts to a diverse audience of engineers and people leaders.
  • Familiarity with AI standards and regulations, EU AI Act, SAIF and ISO 42001.
Measures of success
  • Within your first month, you will absorb fundamental knowledge about Collibra processes/tools and SDLC.
  • Within your third month, you will own application security engineering tasks for one or more development teams responsible for product features.
  • Within your sixth month, you will be responsible for managing triaging efforts for 3rd party pen testing and be able to resolve customer product security inquiries independently.
Compensation for this role

The standard base salary range for this position is $168,000.00 – $210,000.00 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location. In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.

Benefits at Collibra

Collibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about Collibra’s benefits.

We create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about diversity, equity, and inclusion at Collibra.

At Collibra, we’re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.

With this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our Accommodations for Applicants form.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Collibra • United States

On-site
USD 110,000 - 150,000
Flexible benefits program
Competitive compensation
Health coverage
+1
Engineer, Security Operations & Engineering
Engineer, Security Operations & Engineering

Husprey (acq. by Collibra) • Indiana (PA)

On-site
USD 116,000 - 145,000
Bonus potential
Equity for eligible roles
Flex Fund monthly stipend
+1
Engineer, Security Operations & Engineering
Engineer, Security Operations & Engineering

Socket.dev • United States

On-site
USD 116,000 - 145,000
Engineer, Security Operations & Engineering
Engineer, Security Operations & Engineering

Collibra • United States

On-site
USD 116,000 - 145,000
Engineer, Security Operations & Engineering
Engineer, Security Operations & Engineering

Collibra Inc. • United States

On-site
USD 116,000 - 145,000
Senior Director, IT Systems
Senior Director, IT Systems

Collibra Inc. • New York (NY)

Hybrid
USD 204,000 - 255,000
Senior Director, IT Systems
Senior Director, IT Systems

Collibra • Raleigh (NC)

Hybrid
USD 204,000 - 255,000
Senior Director, IT Systems
Senior Director, IT Systems

Collibra Inc. • Raleigh (NC)

Hybrid
USD 204,000 - 255,000
Senior Director, IT Systems
Senior Director, IT Systems

Collibra • New York (NY)

Hybrid
USD 204,000 - 255,000
Senior Customer Support Engineer
Senior Customer Support Engineer

Collibra • New York (NY)

On-site
USD 116,000 - 145,000
Flexible offerings for diverse needs
Competitive total rewards package
Bonus potential and equity options