Staff Security Engineer

Compass

$130K — $180K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security engineering roles with 4+ years focusing on cloud security architecture.
  • Experience owning cloud security strategy for a large-scale organization.
  • Deep expertise in AWS security services and knowledge of Azure security controls.
  • Hands-on experience with CNAPP deployment at an organizational level.
  • Proficiency in a programming language for building security automation.

Responsibilities

  • Own the technical strategy and architecture for cloud security in a multi-cloud environment.
  • Design safe-by-default infrastructure patterns and automated guardrails.
  • Architect scalable controls across AWS, Azure, and GCP.
  • Drive adoption of AI-powered security tooling and threat management processes.
  • Lead harmonization of security posture across technology stacks.
  • Act as technical escalation point for CNAPP tooling strategy.
  • Lead responses to high-severity cloud security events.

Benefits

  • Participation in incentive programs, including potential cash, equity, or commissions.
  • Paid vacation, holidays, sick time, parental leave, and recharge leave.
  • Comprehensive medical, dental, and vision benefits.
  • 401(k) plan and flexible spending accounts (FSAs).
  • Access to various employee support programs, including family planning and pet insurance.
Full Job Description
Security at Compass International Holdings

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: safe-by-default tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you will set technical direction for cloud security across the company - defining the architecture, standards, and roadmap that the rest of the security engineering team and the company build against.

What you will do:
  • Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction that other security and platform engineers build on.
  • Design and drive adoption of safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails that let engineering teams move fast without compromising security.
  • Architect and evolve scalable controls across AWS, Azure, and (increasingly) GCP - including identity, network segmentation, workload, and container/Kubernetes security.
  • Drive adoption of AI-powered security tooling (agentic SOC workflows, AI-assisted triage, and code/IaC scanning copilots) to scale the security team's productivity, while building the AI security posture management (AI-SPM) and governance needed to defend against AI-enabled threats - prompt injection, model/data exfiltration, adversarial inputs, and unsanctioned "shadow AI" usage across the merged engineering org.
  • Lead the harmonization of cloud security posture, guardrails, and tooling across previously separate Compass and Anywhere technology stacks
  • Act as the technical escalation point and senior partner for CNAPP tooling strategy (e.g., Wiz, Orca, Lacework, Upwind), driving consolidation decisions and maximizing signal-to-noise for engineering teams.
  • Lead technical response for high-severity cloud security events, and drive the resulting engineering and process improvements to prevent recurrence.
  • Set the bar for threat modeling and architectural security review, embedding these practices early in the development lifecycle across multiple engineering orgs.
  • Mentor and level up senior and mid-level security engineers; act as a force multiplier through documentation, tooling, and technical coaching rather than one-off reviews.
  • Represent Security in cross-functional and leadership forums - partnering directly with Engineering leadership, Compliance, and Legal on risk tradeoffs, roadmap prioritization, and audit readiness (e.g., SOC 2, public-company controls).
  • Evaluate emerging AI tools and third-party integrations for security and compliance risk, balancing business velocity against data integrity and regulatory exposure.

Who you are:
  • A recognized technical leader in cloud security who is equally comfortable writing the automation and setting the multi-quarter architectural strategy.
  • You default to automation and self-service over manual gatekeeping, and you've built systems that scale security across hundreds of engineers, not just a single team.
  • Deep, hands-on expertise securing AWS at scale, with strong working expertise in Azure and growing familiarity with GCP.
  • A clear, credible communicator who can move fluidly between a whiteboard architecture review with staff engineers and a risk conversation with senior leadership.
  • Experienced running or heavily shaping incident response for cloud-native environments, from detection through postmortem-driven remediation.
  • Track record of driving org-wide adoption of security standards - not just defining them.
  • Comfortable operating in ambiguity, particularly the kind that comes from integrating two large, previously independent technology estates.

Minimum Qualifications:
  • 8+ years in security engineering roles, including 4+ years focused specifically on cloud security architecture at scale.
  • Demonstrated experience owning cloud security strategy or architecture for an organization of significant scale (large engineering org, multi-cloud, or post-M&A environment strongly preferred).
  • Deep, production-grade expertise with AWS security services (IAM, EC2, VPC, container services including ECR, ECS, EKS) and strong working knowledge of Azure security controls.
  • Hands-on experience deploying and operationalizing a CNAPP or equivalent cloud security platform (e.g., Wiz, Orca Security, Lacework, Upwind) at an organizational level, including tool evaluation and consolidation.
  • Strong proficiency in at least one programming language (e.g., Python, Go) used to build production-grade security automation and tooling, not just scripts.
  • Deep fluency in core security principles - least privilege, defense-in-depth, zero trust, and security monitoring - and the judgment to apply them pragmatically.
  • Strong experience with containerization (Docker) and Kubernetes security at scale.
  • Demonstrated experience mentoring engineers and influencing technical direction beyond your immediate team.

Nice to have:
  • Experience with GCP, OCI, or designing cloud-agnostic, multi-cloud security architectures.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Relevant certifications (e.g., AWS Security Specialty, CISSP, OSCP) - valued but never a substitute for demonstrated hands-on impact.


Perks that You Need to Know About:

Participation in our incentive programs (which may include eligible cash, equity, or commissions). Plus paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.

Do your best work, be your authentic self.

Similar Jobs

More Jobs at Compass

More Information Technology Jobs

Find similar Staff Security Engineer jobs: