> Markdown version of [/jobs/ext/1428249-staff-security-engineer-product-security-and-architecture](https://www.wearedevelopers.com/jobs/ext/1428249-staff-security-engineer-product-security-and-architecture). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer, Product Security and Architecture - **Company:** Compass Inc - **Location:** New City, NY, United States - **Experience:** Experienced - **Salary:** $210,000.0 - $234,100.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Agile Methodology, Artificial Intelligence, Amazon Web Services, Application Firewall, Application Layers, Microsoft Azure, Bash Shell, Cloud Computing Security, Code Review, Continuous Delivery, Continuous Integration, DevOps, Information Security Management, Python (Programming Language), OAuth, OpenID, TypeScript, Scripting, Google Cloud, Delivery Pipeline, Software Security, Multi-Cloud, Rate Limiting, Infrastructure Automation Frameworks, Information Technology, Codebase, Api Gateway, Terraform, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=52e1fa0a0c938fbb ## About the Role * Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders. * Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges. * Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously., * Bachelor's degree in Computer Science, a related technical field, or equivalent practical work experience. * Minimum of three (3) years of experience across the following areas: * + Administering and configuring automated pipeline tools (CI/CD). + Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA). + Automation scripting using Python or Bash. + Product development using Python, JavaScript, TypeScript, Golang, or Java. + Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java. + Participating in security-focused reviews for both vendor and custom business solutions. + Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure. + Practical experience working with AWS services, aligning both product solution delivery and security objectives. + Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies. Nice to Have * Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus. * Direct experience working within high-performing DevOps and Agile cultures. * Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting). * Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP). * Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions. * Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes. * Experience securing environments through a merger, acquisition, or major infrastructure consolidation. ## Description * Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines. * Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start. * Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services. * Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture. * Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security. * Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned "shadow AI" usage). * Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)