Senior/Staff Security Engineer

53 Stations

San Francisco (CA)

Hybrid

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid Work Model
Fresh Lunch
Commuter Support: $150 monthly
Health & Wellness: $200 quarterly
Time Off: Flexible PTO + 14 holidays
Comprehensive Coverage: 100% medical/d
Parental Leave: 16 weeks fully paid
Retirement & Ownership: 401k + equity
Team Connection: Annual summit

Job summary

Collective is hiring a Senior/Staff Product Security Engineer to build authentication, authorization, and data‑protection systems at the heart of our member platform. This is a software engineering role first: you will design and ship the code that governs how our platform authenticates users and services, what they're authorized to do, and how our members' data is protected.

Based in San Francisco with a hybrid work model, you will own end-to-end identity, drive patterns for AI agents, and lead

Qualifications

  • 8+ years of software engineering experience in production auth/identity/data-protection systems.
  • Backend experience with Python/Django on AWS.
  • Deep knowledge of OAuth2.0, OIDC, SAML, JWT.
  • Envelope encryption, KMS-based key management, key rotation.
  • Ability to conduct RFCs and design reviews with engineers.

Responsibilities

  • Own end-to-end authentication and authorization architecture for the member platform.
  • Extend patterns to delegated and agent-based access for AI agents and third parties.
  • Design and implement application-layer encryption and data protection controls.
  • Lead RFCs, design reviews, and security-focused changes with product engineers.
  • Threat-model identity/data-protection systems and remediate findings.
  • Ground encryption decisions in applicable regulatory requirements.

Skills

Authentication systems
Backend engineering
OAuth/OIDC/SAML/JWT
Applied cryptography
Threat modeling
RFCs & design reviews
Security-minded product mindset

Tools

Python/Django
AWS

Job description

About Collective:

Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping, tax services, and access to a thriving community, all in one integrated platform. We believe in empowering self-employed people to enjoy the same tax savings that big companies get, so they can focus on their passion, not paperwork.

Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more. We are backed by General Catalyst, Sound Ventures (Ashton Kutcher and Guy Oseary), QED Investors, Google’s Gradient Ventures, Expa, and other investors who have financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft.

About the role:

We're hiring a Senior/Staff Product Security Engineer to build the security‑critical systems at the heart of Collective's member platform. This is a software engineering role first: you'll design and ship the code that governs how our platform authenticates users and services, what they're authorized to do, and how our members' data is protected. You'll own the authentication and authorization architecture end to end — not as a reviewer or advisor, but as the engineer whose commits land in production. You'll set the direction of this work, not just execute it: what gets built and in what order. As Collective expands its use of AI and agent‑based workflows, you'll build the patterns those systems use to authenticate and operate safely. You'll sit on the Security team and spend your days in the product codebase, working alongside product engineers.

What you'll do:
  • Own the end‑to‑end authentication and authorization architecture of Collective's member platform — session management, multi‑factor authentication, authorization enforcement, and machine‑to‑machine authentication — and personally design, write, and ship the changes that improve it.

  • Extend those patterns to delegated and agent‑based access: how AI agents and third parties act on a member's behalf with scoped, time‑boxed, revocable authority — and how their actions are attributed and audited.

  • Drive the programmatic protection of sensitive member data: design and implement application‑layer encryption for member documents and data — key management, envelope encryption, rotation — and build the controls that protect sensitive data in code (scoped access, tokenization, redaction in logs and pipelines) rather than in policy.

  • Lead the design process for the systems you own: write RFCs, run design reviews, and bring product engineers along on security‑critical changes.

  • Threat‑model the identity and data‑protection systems you build, and own remediation of findings that touch your domain.

  • Ground encryption and access‑control decisions in the regulatory requirements that apply to a platform handling sensitive member data.

What you'll bring:
  • 8+ years of software engineering experience, including significant time building or owning authentication, identity, authorization, or data‑protection systems in production.

  • Strong backend engineering skills — you're fluent shipping production code in a modern web stack (we run Python/Django on AWS), and you're comfortable making substantial changes to a codebase other teams depend on.

  • Deep working knowledge of authentication standards and their failure modes: OAuth 2.0 (including token exchange and delegation patterns), OIDC, SAML, JWT, session management, and the differences between securing user‑facing and machine‑to‑machine flows.

  • Practical applied‑cryptography literacy: envelope encryption, KMS‑based key management, key rotation, and the tradeoffs of encrypting data at the field, document, and storage layers. You don't need to be a cryptographer — you need to know how to use cryptography correctly in a production system.

  • Enough security fluency to reason about threats to the systems you build and to hold your own in a threat‑modeling session. Deep security specialization is not required — you'll have teammates who bring it; what can't be delegated is the engineering.

  • Comfort operating as a senior individual contributor who influences platform direction through RFCs, design reviews, and working code rather than a management chain.

  • Product empathy: the ability to hold security rigor and member experience in the same frame — auth flows are the front door of the product, and getting them wrong in either direction is expensive.

What we offer:
  • Hybrid Work Model: Based in San Francisco with a balance of in‑office and remote flexibility.

  • Fresh Lunch: Provided on in‑office days.

  • Commuter Support: $150 monthly reimbursement for transit expenses.

  • Health & Wellness: $200 quarterly reimbursement to support your well‑being.

  • Time Off: Flexible PTO plus 14 company holidays.

  • Comprehensive Coverage: 100% medical, dental, and vision for employees; 75% coverage for dependents.

  • Parental Leave: 16 weeks fully paid.

  • Retirement & Ownership: 401k plan plus an equity package.

  • Team Connection: Quarterly virtual events and an annual in‑person summit.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior/Staff Security Engineer
Senior/Staff Security Engineer

wine collective • San Francisco (CA)

Hybrid
USD 180,000 - 260,000
Hybrid Work Model
Fresh Lunch
Transit stipend
+6
Staff Security Engineer
Staff Security Engineer

Collective Hub Inc. • San Francisco (CA)

Hybrid
USD 140,000 - 180,000
Hybrid Work Model
Fresh Lunch
Commuter Support
+6
Product Security Engineer
Product Security Engineer

Collective • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid work in SF
Fresh lunch
Commuter support
+6
Product Security Engineer
Product Security Engineer

Collective Hub Inc. • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid Work Model
Fresh Lunch Provided on in-office days
Commuter Support: $150 monthly
+6
Product Security Engineer
Product Security Engineer

wine collective • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Fresh lunch provided
Commuter support
+6
Senior Software Engineer
Senior Software Engineer

Collective • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
Hybrid Work Model
Fresh Lunch
Commuter Support
+6
Senior Software Engineer
Senior Software Engineer

wine collective • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid Work Model
Fresh Lunch
Transit reimbursement
+6
Engineering Manager – Senior Manager
Engineering Manager – Senior Manager

Collective • San Francisco (CA)

Hybrid
USD 170,000 - 210,000
Hybrid work model
Fresh lunch
Commuter support
+6
Engineering Manager/Senior Manager
Engineering Manager/Senior Manager

Collective Hub Inc. • San Francisco (CA)

Hybrid
USD 150,000 - 190,000
Hybrid work model
Fresh lunch
Transit stipend
+6
Engineering Manager/Senior Manager
Engineering Manager/Senior Manager

wine collective • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Hybrid Work Model
Fresh Lunch
Commuter Support
+6