Senior Product Security Engineer

<h3><strong>Joining Collibra’s Product Security team</strong></h3> <p>Collibra is seeking a Senior Product Security Engineer to join our high-impact team. You will be a key individual responsible for identifying vulnerabilities and providing expert remediation consulting for our global product development teams. This role provides critical technical leadership and oversight, ensuring Collibra continues to deliver secure, resilient products and services to our customers. You will act as an application security evangelist, partnering with engineers to accelerate secure time-to-value while leveraging cutting-edge AI and MCP to create context-aware security automation.</p> <h3><strong>Product Security Engineers at Collibra are responsible for</strong></h3> <ul> <li>Application security for products and/or features supported by your assigned development teams.</li> <li>Performing security testing and triaging findings identified by SAST, SCA, IAST, DAST, and penetration tests.</li> <li>Leverage AI and MCP to create intelligent, context-aware security guidance and automation.</li> <li>Providing remediation consulting services to assigned development teams.</li> <li>Assist with vulnerability management reporting and tracking.</li> <li>Coordinating third-party penetration testing engagements, analyzing reports, and opening tickets for remediation.</li> <li>Contribute to the configuration and management of security tools.</li> </ul> <h3><strong>You have</strong></h3> <ul> <li>5+ years of application/product security experience.</li> <li>2+ years of experience securing Java, Python, and/or JavaScript web applications.</li> <li>Knowledge of enterprise-level software architecture components and cloud infrastructure.</li> <li>Experience building trusted advisor relationships with engineers, product owners, and engineering management (up to director level).</li> <li>Experience with AI security tooling, context-aware automation for SSDLC.</li> <li>Understanding of AI privacy and governance in developer workflows.</li> <li>Experience using and building agentic AI systems that work collaboratively.</li> <li>Experience advocating for the remediation of application security risk and, simultaneously, the associated development/engineering team(s).</li> <li>Experience in identifying vulnerabilities in source code, providing detailed steps to reproduce exploitation, and providing recommendations to engineering teams on how to remediate issues.</li> <li>A bachelor’s degree or equivalent related working experience is required.</li> </ul> <h3><strong>You are</strong></h3> <ul> <li>Knowledgeable of CI/CD concepts and experience with integrated SAST, SCA, and DAST tooling.</li> <li>Proficient at triaging application vulnerabilities associated with source code, open-source library dependencies, and 3rd party containers.</li> <li>Able to assess and communicate the impact of Common Vulnerability Weaknesses (CVEs) on custom application software and advise on risk acceptance/deferment for false positive scenarios, severity adjustments, and acceptable reasoning for operational requirements.</li> <li>Experienced in executing as a matrixed/embedded security resource (within a development team) responsible for product, application, or feature group vulnerability assessments, ensuring they are appropriately enumerated and executed.</li> <li>Possess a working knowledge of Python, Java, and/or JavaScript software development languages.</li> <li>Experienced in Linux and containerization in a cloud environment.</li> <li>Experienced in communicating the impact of security vulnerabilities to engineering teams and product leaders.</li> <li>Experienced in using SAST, DAST, and SCA tooling.</li> <li>Experienced in being a point of contact for outside/3rd party security assessments (pen tests, questionnaires, etc.).</li> <li>knowledgeable of vulnerability management concepts, challenges, and reporting.</li> <li>Possess a working knowledge of the OWASP Top 10 and can explain its concepts to a diverse audience of engineers and people leaders.</li> <li>Familiarity with AI standards and regulations, EU AI Act, SAIF and ISO 42001.</li> </ul> <h3><strong>Measures of success</strong></h3> <ul> <li>Within your first month, you will absorb fundamental knowledge about Collibra processes/tools and SDLC.</li> <li>Within your third month, you will own application security engineering tasks for one or more development teams responsible for product features.</li> <li>Within your sixth month, you will be responsible for managing triaging efforts for 3rd party pen testing and be able to resolve customer product security inquiries independently.</li> </ul> <p> </p><div class="content-conclusion"><h3>Benefits at Collibra</h3> <p>Collibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about <a href="https://www.collibra.com/us/en/company/careers/benefits">Collibra’s benefits</a>.</p> <p>We create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about <a href="https://www.collibra.com/us/en/company/careers/dei">diversity, equity, and inclusion</a> at Collibra.</p> <p>At Collibra, we’re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.</p> <p>With this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our <a href="https://www.collibra.com/us/en/company/careers/accommodations">Accommodations for Applicants form</a>.</p></div>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...