Skip to content
← Back to job listings

Staff Security Engineer (Product Security and Architecture)

Compass · New York, United States

External listingfull-time11 days ago

About The Role

Join our Security organization as a Staff Security Engineer, where you will play a crucial role in protecting one of the largest and most complex real estate technology estates in the industry. You will drive technical security results, automate application security, and advocate for secure-by-design approaches across the organization. Your expertise will help shape the roadmaps that our engineering teams adopt and build against.

  • Automate and scale application security by building and enhancing automated testing frameworks.
  • Drive secure-by-design architectures by partnering with engineering teams to evaluate solution architectures.
  • Serve as a trusted security advisor by offering security guidance and risk evaluations for new product features.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges
  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders
  • Administering and configuring automated pipeline tools (CI/CD)
  • Product development using Python, JavaScript, TypeScript, Golang, or Java
  • Minimum of three (3) years of experience across the following areas:
  • Participating in security-focused reviews for both vendor and custom business solutions
  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience
  • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java
  • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies
  • Automation scripting using Python or Bash
  • Practical experience working with AWS services, aligning both product solution delivery and security objectives
  • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA)
  • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure
  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus
  • Direct experience working within high-performing DevOps and Agile cultures
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting)
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP)
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation

This is an external listing. JobSpring does not represent or verify the employer. Report this listing