Senior Security Engineer
Compass · New York, United States
About The Role
Join our team as a Senior Security Engineer, where you will play a crucial role in building secure, resilient, and scalable web and mobile applications for the real estate industry. You will work closely with diverse teams to provide and support automated security tooling and services, architect secure web products, and lead our effort to build security as a service. This role requires a blend of strategic partnership, hands-on engineering, infrastructure security, and automation. You will also assist in investigating and responding to security events, conduct security assessments for third-party integrations, and collaborate with cross-functional teams to build secure systems.
- Lead the effort to build security as a service, driving safe-by-default environments and enhancing customer trust.
- Design and implement scalable systems and controls to secure cloud infrastructure, collaborating closely with engineering and security teams.
- Conduct security assessments for third-party integrations and emerging AI tools, ensuring business productivity does not compromise data integrity or compliance.
- You can clearly communicate complex security vulnerabilities and remediation techniques to diverse audiences
- Excited to collaborate with cross-functional teams to build secure, reliable, and scalable systems
- You possess a proactive mindset, adept at identifying and resolving security gaps or inefficiencies through innovative automation and tooling
- Expertise in securing cloud platforms, particularly AWS and Azure
- You are comfortable guiding and educating development teams to achieve stronger security outcomes
- Experience with threat modeling and architectural review processes; you have a track record of identifying potential attack vectors early in the development lifecycle
- Automation is your default approach to security. You understand the unique challenges of securing systems at scale and consistently leverage automation to solve them
- Strong analytical and problem-solving skills, with the ability to critically and objectively assess complex security risks
- Familiarity with containerization technologies (Docker) and orchestration platforms (Kubernetes)
- Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind)
- Strong understanding of cloud platforms and security features, particularly AWS (IAM, EC2, VPC, container services like ECR, ECS, and EKS), with foundational knowledge of Azure and/or GCP
- Proficiency in at least one programming language (e.g., Python, Go) for automation
- Experience: At least 5+ years of experience in a security-related role, with at least 2+ years specifically focused on cloud security
- Technical Skills:
- Strong understanding of Azure services and how to secure them
- Knowledge of core security principles such as the principle of least privilege, defense-in-depth, and security monitoring
- Experience with GCP, OCI and multi-cloud networks and infrastructure, especially when designing cloud-agnostic systems
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring