bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesCollectivStaff Security Engineer

Staff Security Engineer

Collectiv · San Francisco · Hybrid · Active · Ashby

Job facts

FieldValue
CompanyCollectiv
TitleStaff Security Engineer
Normalized title-
Department / teamEngineering / Engineering
LocationSan Francisco, CA, United States
Work modelHybrid / Hybrid
Employment typeFull Time
Salary-
Statusactive
ATS providerAshby
Posted / first seen / 2026-06-06
Changed / last seen2026-06-06 / 2026-06-19

Related slices

PageWhat it containsOpen
Company jobsActive postings from Collectiv.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Ashby.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in San Francisco.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyCollectiv
Sourced8eff73c-0a40-484e-8025-75c2e2306ce8
ATS providerAshby

Description

About Collective: Collective is on a mission to redefine the way businesses-of-one work. Our technology and team of trusted advisors help members achieve financial independence by taking care of everything from business incorporation to accounting, bookkeeping, tax services, and access to a thriving community, all in one integrated platform. We believe in empowering self-employed people to enjoy the same tax savings that big companies get, so they can focus on their passion, not paperwork. Featured in Forbes, Business Insider, Yahoo, Bloomberg, Financial Times, TechCrunch, and more. We are backed by General Catalyst, Sound Ventures (Ashton Kutcher and Guy Oseary), QED Investors, Google’s Gradient Ventures, Expa, and other investors who have financed iconic companies like YouTube, Substack, Twitch, Box, Hims, Instacart, and Lyft. About the role: We're hiring a Staff Security Engineer to own the security of Collective's member platform end to end — from how code is written and tested to how data is protected and how our systems authenticate. This is a senior individual contributor role with broad product-security scope: you'll embed security into the development lifecycle, lead threat modeling and security reviews across the platform, and own the authentication, authorization, and compliance systems that keep our members' financial and tax data trustworthy. As Collective expands its use of AI and agent-based workflows, you'll shape how those systems authenticate and operate securely. You'll work closely with Engineering, Product, and Legal to make security a first-class property of everything we ship — without slowing the team down. What you'll do: Own the end-to-end authentication and authorization architecture across Collective's member platform, including session management, role-based access control, and the emerging patterns needed to secure agent-based workflows and service-to-service communication. Drive CCPA compliance across the platform, partnering with Legal and Engineering to map data flows, implement required access and deletion controls, and establish ongoing audit and reporting mechanisms. Design and maintain Collective's static and dynamic application security testing (SAST/DAST) frameworks, integrating them into CI/CD pipelines so security feedback is fast, automated, and actionable for product teams. Lead threat modeling for new features and platform changes, collaborating with product engineers early in the design process to identify and address risk before it reaches production. Define and maintain security standards, policies, and runbooks that give engineering teams clear guardrails without slowing down delivery. Respond to and lead post-incident security reviews, driving root-cause analysis and translating findings into durable platform improvements. Evaluate and integrate third-party security tooling, staying current on the threat landscape relevant to fintech platforms handling sensitive financial and tax data. What you'll bring:  8+ years of security engineering experience, with depth in application security and a track record of improving security posture on production platforms at scale. Strong expertise in authentication and authorization systems (OAuth 2.0, OIDC, SAML, JWT) and the nuances of securing both user-facing sessions and machine-to-machine flows, including AI agent authentication patterns. Hands-on experience building or owning SAST/DAST programs and embedding security testing into CI/CD pipelines; familiarity with tools like Semgrep, Snyk, Burp Suite, or equivalent. Working knowledge of CCPA (and ideally GDPR) compliance requirements as they apply to a SaaS platform handling personal financial data, including data mapping, subject rights workflows, and audit trails. Experience collaborating with Legal and Privacy teams to translate regulatory requirements into concrete engineering controls, not just documentation. Comfort operating as a senior individual contributor who influences platform direction without requiring a management chain to get things done — you write RFCs, lead design reviews, and bring engineers along through conviction and clarity. Product empathy: the ability to hold security rigor and member experience in the same frame, and to make the right tradeoffs with both in mind. Familiarity with AI-assisted development workflows and an interest in the security implications of agent-based systems is a strong plus. What we offer: Hybrid Work Model: Based in San Francisco with a balance of in-office and remote flexibility. Fresh Lunch: Provided on in-office days. Commuter Support: $150 monthly reimbursement for transit expenses. Health & Wellness: $200 quarterly reimbursement to support your well-being. Time Off: Flexible PTO plus 14 company holidays. Comprehensive Coverage: 100% medical, dental, and vision for employees; 75% coverage for dependents. Parental Leave: 16 weeks fully paid. Retirement & Ownership : 401k plan plus an equity package. Team Connection: Quarterly virtual events and an annual in-person summit.

Full job record

Job ID8b75dfcc4c627278e3cd297c7b549fdd1d97c0a7
Org ID9af3ce98-4c7d-40f1-b509-a831ef030aa3
Source IDd8eff73c-0a40-484e-8025-75c2e2306ce8
Board IDd8eff73c-0a40-484e-8025-75c2e2306ce8
Providerashby
Provider Job Key72b49fac-c76d-4977-b71c-71c70a1bca9b
TitleStaff Security Engineer
Normalized Title
Statusactive
Activeyes
Location TextSan Francisco
DepartmentEngineering
TeamEngineering
Employment Typefull_time
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionCA
CitySan Francisco
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://jobs.ashbyhq.com/collective/72b49fac-c76d-4977-b71c-71c70a1bca9b
Apply URLhttps://jobs.ashbyhq.com/collective/72b49fac-c76d-4977-b71c-71c70a1bca9b/application
First Seen At2026-06-06 09:33:45Z
Last Seen At2026-06-19 09:43:20Z
Last Checked At2026-06-19 09:43:20Z
Last Changed At2026-06-06 09:33:45Z
Inactive At
Source Posted At
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=ashby/board=collective/date=2026-06-19/2026-06-19T09-43-13-022Z-164f527d62fd061fbd1f0cddfbf21be348bef4c1e30f46b52fc121d3fbefa19c.json
Event Fields
{
  "content_hash": "df107829899c6b1366644975a0cbc0d36c33f51a24a00bfcae71a30cb824e110",
  "source_hash": "ca1b4fcb4ab6cbd484013549b8c1cc72504c0d24b731bfc207172dd1056df0c1",
  "last_changed_at": "2026-06-06T09:33:45.467Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "San Francisco",
    "city": "San Francisco",
    "region": "CA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-19T09:43:20.091Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "San Francisco",
      "city": "San Francisco",
      "region": "CA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "id": "72b49fac-c76d-4977-b71c-71c70a1bca9b",
  "team": "Engineering",
  "title": "Staff Security Engineer",
  "jobUrl": "https://jobs.ashbyhq.com/collective/72b49fac-c76d-4977-b71c-71c70a1bca9b",
  "address": null,
  "applyUrl": "https://jobs.ashbyhq.com/collective/72b49fac-c76d-4977-b71c-71c70a1bca9b/application",
  "isListed": true,
  "isRemote": false,
  "location": "San Francisco",
  "updatedAt": null,
  "apiVersion": "ashby-non-user-graphql-v1",
  "department": "Engineering",
  "publishedAt": null,
  "workplaceType": "Hybrid",
  "employmentType": "FullTime",
  "secondaryLocations": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/8b75dfcc4c627278e3cd297c7b549fdd1d97c0a7?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/9af3ce98-4c7d-40f1-b509-a831ef030aa3JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/d8eff73c-0a40-484e-8025-75c2e2306ce8JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/8b75dfcc4c627278e3cd297c7b549fdd1d97c0a7/eventsJSON