Staff Security Engineer (Product Security And Architecture)
Compass · Boston, United States
About The Role
Join our Security organization as a Staff Security Engineer, where you will play a crucial role in protecting one of the largest and most complex real estate technology estates in the industry. You will be responsible for automating and scaling application security, driving secure-by-design architectures, serving as a trusted security advisor, evangelizing product security, cultivating collaboration, and driving the adoption of AI-powered security capabilities. You will also stay ahead of industry trends and continuously innovate to ensure our security capabilities keep pace with evolving business and engineering objectives.
- Automate and scale application security by building and enhancing automated application security testing frameworks and tooling.
- Drive secure-by-design architectures by partnering closely with engineering teams to evaluate solution architectures and codebases.
- Serve as a trusted security advisor by acting as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations.
- Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously
- Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck
- Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges
- Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders
- Administering and configuring automated pipeline tools (CI/CD)
- Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java
- Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA)
- Practical experience working with AWS services, aligning both product solution delivery and security objectives
- Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies
- Minimum of three (3) years of experience across the following areas:
- Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure
- Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience
- Participating in security-focused reviews for both vendor and custom business solutions
- Product development using Python, JavaScript, TypeScript, Golang, or Java
- Automation scripting using Python or Bash
- Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus
- Direct experience working within high-performing DevOps and Agile cultures
- Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting)
- Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP)
- Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions
- Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
- Experience securing environments through a merger, acquisition, or major infrastructure consolidation
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring