Compass logo

Staff Security Engineer, Product Security and Architecture

Compass

Aventura, FLJob$210–234K/yrPosted 1mo agoVerified open 5 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$210–234K/yr
Location
Aventura, FL
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

Compass is hiring a Staff Security Engineer, Product Security and Architecture. The Staff Security Engineer, Product Security and Architecture, protects Compass International Holdings' real estate technology estate. This role involves building secure-by-design tooling, automated guardrails, and partnering with engineering teams. The engineer will drive technical security results and shape roadmaps for engineering teams, focusing on integrating security into the development lifecycle.

Key focus areas include Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines., Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start., and Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and...

Successful candidates bring Bachelor's Degree In Computer Science Or Equivalent, Three Years Experience In CI/CD Automation, and Experience Administering Application Security Testing Tools. Important skills include Application Security Testing Frameworks, CI/CD, Secure-by-Design Architectures, Technical Feedback, Security Guidance, and Risk Evaluations. Preferred (not required): High-Performing DevOps Cultures, Agile Cultures, and Layer 7 Security Controls.

Skills & qualifications

RequiredNice to have

Skills

Application Security Testing FrameworksCI/CDSecure-by-Design ArchitecturesTechnical FeedbackSecurity GuidanceRisk EvaluationsProduct Security EvangelismCollaborationAI-Powered Security CapabilitiesCode/IaC Scanning CopilotsAutomated TriageAI Security Posture Management FrameworksSecure-by-Design StandardsPrompt Injection ProtectionModel/Data Exfiltration ProtectionShadow AI Usage ProtectionContinuous InnovationIndustry Trend AwarenessAgile EnvironmentDevOps EnvironmentCoachingSecurity Concepts CommunicationTroubleshootingArchitectural Security Challenges DiagnosisPipeline Security Challenges DiagnosisSelf-MotivationOrganizational SkillsTime ManagementAutomated Pipeline Tools AdministrationAutomated Pipeline Tools ConfigurationApplication Security Testing Tools AdministrationApplication Security Testing Tools TuningSASTDASTSCAPythonBashJavaScriptTypeScriptGoJavaSecurity Code ReviewsSecurity-Focused ReviewsInfrastructure as CodeTerraformAWS ServicesAI for Product Security ProcessesHigh-Performing DevOps CulturesAgile CulturesLayer 7 Security Controls

Qualifications

Bachelor's Degree in Computer Science or Related Technical Field or Equivalent Practical Work Experience3+ Years Administering and Configuring Automated Pipeline Tools3+ Years Administering and Tuning Application Security Testing Tools3+ Years Automation Scripting Using Python or Bash3+ Years Product Development Using Python, JavaScript, TypeScript, Golang, or Java3+ Years Performing Security Code Reviews3+ Years Participating in Security-Focused Reviews3+ Years Hands-on Experience With Infrastructure as Code Tools3+ Years Practical Experience Working With AWS Services3+ Years Hands-on Experience Using Artificial Intelligence to Assist With Product Security ProcessesCEH CertificationCISSP Certification

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off
Parental Leave
401(k) Match

Full job description

At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.

About Compass International Holdings (CIH)

Compass International Holdings (CIH) is the largest residential real estate platform in the world, established by the January 2026 merger of Compass and Anywhere Real Estate. By bringing together the technology, brands, and agent networks that power residential real estate transactions across the United States and globally. CIH's mission is to help everyone find their place in the world — and to build the single software platform for all real estate activity, at a scale and complexity few technology companies ever operate at.

Security at Compass International Holdings

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: secure-by-design tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to directly drive technical security results and shaping the roadmaps that our engineering teams adopt and build against.

What You Will Do

  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines.
  • Drive Secure-by-Design Architectures : Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start.
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services.
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture.
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security.
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned "shadow AI" usage).
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives.

Who You Are

  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck.
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders.
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously.

Minimum Qualifications

  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience.
  • Minimum of three (3) years of experience across the following areas:
  • Administering and configuring automated pipeline tools (CI/CD).
  • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA).
  • Automation scripting using Python or Bash.
  • Product development using Python, JavaScript, TypeScript, Golang, or Java.
  • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java.
  • Participating in security-focused reviews for both vendor and custom business solutions.
  • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure.
  • Practical experience working with AWS services, aligning both product solution delivery and security objectives.
  • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies.

Nice to Have

  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus.
  • Direct experience working within high-performing DevOps and Agile cultures.
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting).
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP).
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation. Compensation: The base pay range for this position is $210,000 - $234,100; however, base pay offered may vary depending on job-related knowledge, skills, and experience. Bonuses and restricted stock units may be provided as part of the compensation package, in addition to a full range of benefits. Base pay is based on market location. Minimum wage for the position will always be met

Perks that You Need to Know About:

Participation in our incentive programs (which may include eligible cash, equity, or commissions). Plus paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.

Do your best work, be your authentic self. At Compass, we believe that everyone deserves to find their place in the world — a place where they feel like they belong, where they can be their authentic selves, where they can thrive. Our collaborative, energetic culture is grounded in our Compass Entrepreneurship Principles and our commitment to diversity, equity, inclusion, growth and mobility. As an equal opportunity employer, we offer competitive compensation packages, robust benefits and professional growth opportunities aimed at helping to improve our employees' lives and careers. Notice for California Applicants

Los Angeles County Fair Chance Notice

You've read the whole posting — now see how you match it.

Staff Security Engineer, Product Security and… | Olive Jobs