Staff Security Engineer, Product Security and Architecture

Compass

$210K — $234K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related technical field, or equivalent experience.
  • 3+ years of experience with CI/CD pipeline tools.
  • Experience with application security testing tools like SAST, DAST, or SCA.
  • Proficiency in automation scripting (Python or Bash).
  • Product development experience in Python, JavaScript, TypeScript, Golang, or Java.
  • Hands-on experience with Infrastructure as Code (e.g., Terraform) and AWS.
  • Experience applying AI to enhance product security processes.

Responsibilities

  • Automate and enhance application security testing frameworks.
  • Evaluate solution architectures and codebases with a focus on secure design.
  • Provide security guidance for product features and development processes.
  • Advocate for secure development practices throughout the organization.
  • Foster collaboration between product and engineering teams on security matters.
  • Drive adoption of AI-powered security tools and practices.
  • Stay updated on industry trends to enhance security capabilities.

Benefits

  • Participation in incentive programs including potential cash and equity.
  • Paid vacation, holidays, and parental leave.
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) plan and flexible spending accounts (FSAs).
  • Employee Assistance Program and pet insurance.
Full Job Description
What You Will Do
  • Automate & Scale Application Security: Build, enhance, and support automated application security testing frameworks and tooling to seamlessly integrate security into continuous integration and delivery (CI/CD) pipelines.
  • Drive Secure-by-Design Architectures: Partner closely with engineering teams to evaluate solution architectures and codebases, providing technical feedback that embeds secure-by-design principles from the start.
  • Serve as a Trusted Security Advisor: Act as a key resource and subject matter expert for product and engineering teams, offering security guidance and risk evaluations for new product features, development processes, tooling, and services.
  • Evangelize Product Security: Advocate for secure-by-design approaches across the organizations helping to mature the overall security culture.
  • Cultivate Collaboration: Build strong, collaborative relationships across the Product and Engineering organization to help product teams efficiently achieve their delivery goals without compromising on security.
  • Secure & Accelerate with AI: Drive the adoption of AI-powered security capabilities (e.g., code/IaC scanning copilots and automated triage) to foster operational efficiencies, while establishing a AI Security Posture Management (AI-SPM) frameworks and secure-by-design standards needed to safely integrate AI into CIH products and protect enterprise data assets from emerging threats (such as prompt injection, model/data exfiltration, and unsanctioned "shadow AI" usage).
  • Continuous Innovation: Stay ahead of industry trends, embracing and adopting new technologies to ensure security capabilities keep pace with evolving business and engineering objectives.


Who You Are
  • Strategic Collaborator: You thrive in Agile and DevOps environments, viewing security as an enabler of engineering velocity rather than a bottleneck.
  • Technical Leader & Advocate: You are passionate about mentoring others and can articulately champion security concepts to both deeply technical engineers and business stakeholders.
  • Analytical Problem Solver: You possess exceptional troubleshooting skills and the logical capacity to diagnose complex architectural and pipeline security challenges.
  • Self-Driven Achiever: You are highly self-motivated, with the organizational and time-management skills required to manage multiple complex initiatives simultaneously.


Minimum Qualifications
  • Bachelor's degree in Computer Science, a related technical field, or equivalent practical work experience.
  • Minimum of three (3) years of experience across the following areas:
    • Administering and configuring automated pipeline tools (CI/CD).
    • Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA).
    • Automation scripting using Python or Bash.
    • Product development using Python, JavaScript, TypeScript, Golang, or Java.
    • Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java.
    • Participating in security-focused reviews for both vendor and custom business solutions.
    • Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure.
    • Practical experience working with AWS services, aligning both product solution delivery and security objectives.
    • Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies.


Nice to Have
  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications) are a strong plus.
  • Direct experience working within high-performing DevOps and Agile cultures.
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting).
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP).
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation.

Compensation: The base pay range for this position is $210,000 - $234,100; however, base pay offered may vary depending on job-related knowledge, skills, and experience. Bonuses and restricted stock units may be provided as part of the compensation package, in addition to a full range of benefits. Base pay is based on market location. Minimum wage for the position will always be met

Perks that You Need to Know About:

Participation in our incentive programs (which may include eligible cash, equity, or commissions). Plus paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.

Similar Jobs

More Jobs at Compass

More Information Technology Jobs

Find similar Staff Security Engineer, Product Security and Architecture jobs: