Compass logo

Staff Security Engineer (Product Security And Architecture)

Compass

RemoteFull timeMid level$210k – $234kPosted today
Apply with JobAssist

About the role

  • The Security organization protects one of the largest and most complex real estate technology estates in the industry
  • We are hands-on engineers who build security as a service: secure-by-design tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping
  • As a Staff Security Engineer, you are empowered to directly drive technical security results and shaping the roadmaps that our engineering teams adopt and build against
  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines
  • Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned “shadow AI” usage)
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives- Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously
  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders
  • Administering and configuring automated pipeline tools (CI/CD)
  • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java
  • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA)
  • Practical experience working with AWS services, aligning both product solution delivery and security objectives
  • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies
  • Minimum of three (3) years of experience across the following areas:
  • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure
  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience
  • Participating in security-focused reviews for both vendor and custom business solutions
  • Product development using Python, JavaScript, TypeScript, Golang, or Java
  • Automation scripting using Python or Bash
  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus
  • Direct experience working within high-performing DevOps and Agile cultures
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting)
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP)
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Compass was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.