Staff Security Engineer, Product Security and Architecture

Compass Inc
Miami, FL, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$210,000.0 - $234,100.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Agile Methodology Artificial Intelligence Amazon Web Services Application Firewall Application Layers Microsoft Azure Bash Shell Cloud Computing Security Code Review Continuous Delivery
+21 more
Continuous Integration DevOps Information Security Management Python (Programming Language) OAuth OpenID TypeScript Scripting Google Cloud Delivery Pipeline Software Security Multi-Cloud Rate Limiting Infrastructure Automation Frameworks Information Technology Codebase Api Gateway Terraform Static Application Security Testing Golang Dynamic Application Security Testing

Job description

  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines.
  • Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start.
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services.
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture.
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security.
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned “shadow AI” usage).
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives.

Requirements

  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders.
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously., * Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience.
  • Minimum of three (3) years of experience across the following areas: *

  • Administering and configuring automated pipeline tools (CI/CD).
  • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA).
  • Automation scripting using Python or Bash.
  • Product development using Python, JavaScript, TypeScript, Golang, or Java.
  • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java.
  • Participating in security-focused reviews for both vendor and custom business solutions.
  • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure.
  • Practical experience working with AWS services, aligning both product solution delivery and security objectives.
  • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies.

Nice to Have

  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus.
  • Direct experience working within high-performing DevOps and Agile cultures.
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting).
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP).
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation.

Benefits & conditions

3.83.8 out of 5 stars Miami, FL $210,000 - $234,100 a year, Pulled from the full job description

  • Pet insurance
  • Parental leave
  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Flexible spending account, Compensation: The base pay range for this position is $210,000 - $234,100; however, base pay offered may vary depending on job-related knowledge, skills, and experience. Bonuses and restricted stock units may be provided as part of the compensation package, in addition to a full range of benefits. Base pay is based on market location. Minimum wage for the position will always be met

Perks that You Need to Know About:

Participation in our incentive programs (which may include eligible cash, equity, or commissions). Plus paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance. Do your best work, be your authentic self. At Compass, we believe that everyone deserves to find their place in the world - a place where they feel like they belong, where they can be their authentic selves, where they can thrive. Our collaborative, energetic culture is grounded in our Compass Entrepreneurship Principles and our commitment to diversity, equity, inclusion, growth and mobility. As an equal opportunity employer, we offer competitive compensation packages, robust benefits and professional growth opportunities aimed at helping to improve our employees’ lives and careers.

Notice for California Applicants

Los Angeles County Fair Chance Notice

About the company

At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.

About Compass International Holdings (CIH)

Compass International Holdings (CIH) is the largest residential real estate platform in the world, established by the January 2026 merger of Compass and Anywhere Real Estate. By bringing together the technology, brands, and agent networks that power residential real estate transactions across the United States and globally. CIH’s mission is to help everyone find their place in the world - and to build the single software platform for all real estate activity, at a scale and complexity few technology companies ever operate at.

Security at Compass International Holdings

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: secure-by-design tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to directly drive technical security results and shaping the roadmaps that our engineering teams adopt and build against.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz ¡ WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo ¡ LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum ¡ WWC Europe 2026

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal ¡ LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter ¡ WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz ¡ WWC Europe 2026

Videos

See all

Related articles

See all