Jobs · Information Technology · Indiana

Senior Product Security Engineer

Husprey (acq. by Collibra) · Marion County, IN · 5 days ago
Information Technology$168k–$210k/yrFull-time

About the role

Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product development teams. This role provides critical technical leadership and oversight, ensuring Collibra continues to deliver secure, resilient products and services to our customers. You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.

Responsibilities

  • Identify vulnerabilities and provide expert remediation consulting for Collibra’s global product development teams.
  • Act as an application security evangelist, partnering with engineers to accelerate secure time-to-value.
  • Leverage cutting-edge AI and MCP to create context-aware security automation.
  • Ensure quality reports and services are delivered efficiently and on time.
  • Collaborate with cross-functional teams to ensure that security best practices are integrated into the development process.
  • Enable remediation of discovered vulnerabilities through the building of relationships with engineering teams.
  • Develop professional skills with relevant industry-specific certifications or training.
  • Aid in triaging Code Security findings identified by SAST, SCA, IAST, DAST, where necessary.
  • Perform Application Penetration Testing (Web-app, API, Thick Client), Network Penetration Testing (Internal, External), Cloud Service penetration testing, tradecraft and methodologies across multiple service providers (AWS, Azure, GCP).
  • Ensure quality reports and services are delivered efficiently and on time.
  • Participate in threat modeling and source-code reviews.
  • Collaborate with cross-functional teams to ensure that security best practices are integrated into the development process.
  • Enable remediation of discovered vulnerabilities through the building of relationships with engineering teams.
  • Develop professional skills with relevant industry-specific certifications or training.
  • Aid in triaging Code Security findings identified by SAST, SCA, IAST, DAST, where necessary.
  • Leverage AI and MCP to create intelligent, context-aware security guidance and automation.

Requirements

  • 5+ years of relevant Penetration Testing, Product Security, and Application Security experience.
  • 2+ years securing Java, Python, and/or JavaScript web applications.
  • Experience with advanced security tools and techniques for simulating real-world attacks.
  • Familiarity with Open-Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), Software Assurance Maturity Model (SAMM), National Institute of Standards and Technology (NIST) Special Publications, and PTES (Penetration Testing Execution Standard).
  • Experience testing against compliance frameworks such as PCI, FISMA, HIPAA, FedRAMP, or HITRUST.
  • Strong working knowledge of at least two programming or scripting languages (Python, Java, JavaScript).
  • Familiarity with best practices for securing the SDLC and DevOps processes.
  • Ability to triage security incidents when needed.
  • Experience with AI security tooling and context-aware SDLC automation.
  • Understanding of AI privacy and governance in developer workflows.
  • Experience using and building collaborative agent AI systems.
  • Demonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.

Qualifications

  • Bachelor’s degree or equivalent related working experience is required.
  • Relevant security certifications strongly preferred (e.g. OSCP, OSWE, CRTP).
  • Red/Purple team operations.
  • Possess a working knowledge of Python, Java, and/or JavaScript software development languages.
  • Experienced in performing security assessments against containerized cloud environments.
  • Familiarity with AI standards and regulations, EU AI Act, SAIF and ISO 42001.

Skills

  • Strong verbal and written communication skills.
  • Excellent ability to produce assessment reports, presentations, and operating procedures.
  • Matured security practices and mentoring junior teammates.
  • Advocate for the remediation of application security risk and, simultaneously, the associated development/engineering teams.

Benefits

  • Competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.
  • Flexible benefits program to support various life events and circumstances.
  • Inclusive and belonging-focused culture through onboarding, meetings, connections, engagement, and communication.
  • Equal opportunity employer committed to diversity, equity, and inclusion.

Pay

The standard base salary range for this position is $168,000.00 - $210,000.00 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location. In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.

Similar jobs