Jobs and Careers
CO

Staff Security Engineer, Product Security and Architecture

Compass
United Statesfull_timeVerifiedPosted 22 Jul 2026
💰 $234,100/yr($210,000/yr$234,100/yr)

About the role

At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.

About Compass International Holdings (CIH)

Compass International Holdings (CIH) is the largest residential real estate platform in the world, established by the January 2026 merger of Compass and Anywhere Real Estate. By bringing together the technology, brands, and agent networks that power residential real estate transactions across the United States and globally. CIH's mission is to help everyone find their place in the world — and to build the single software platform for all real estate activity, at a scale and complexity few technology companies ever operate at.

 

Security at Compass International Holdings

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: secure-by-design tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you are empowered to directly drive technical security results and shaping the roadmaps that our engineering teams adopt and build against.

 

What You Will Do

  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines.
  • Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start.
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services.
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture.
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security.
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned "shadow AI" usage).
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives.

 

Who You Are

  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck.
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders.
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously.

 

Minimum Qualifications

  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical work experience.
  • Minimum of three (3) years of experience across the following areas:
    • Administering and configuring automated pipeline tools (CI/CD).
    • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA).
    • Automation scripting using Python or Bash.
    • Product development using Python, JavaScript, TypeScript, Golang, or Java.
    • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java.
    • Participating in security-focused reviews for both vendor and custom business solut

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Compass

View company profile →