Staff Security Engineer
At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.
Compass International Holdings (CIH) is the largest residential real estate platform in the world, established by the January 2026 merger of Compass and Anywhere Real Estate. By bringing together the technology, brands, and agent networks that power residential real estate transactions across the United States and globally. CIH's mission is to help everyone find their place in the world — and to build the single software platform for all real estate activity, at a scale and complexity few technology companies ever operate at.
Security at Compass International Holdings
The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: safe-by-default tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you will set technical direction for cloud security across the company — defining the architecture, standards, and roadmap that the rest of the security engineering team and the company build against.
What you will do:
- Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction that other security and platform engineers build on.
- Design and drive adoption of safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails that let engineering teams move fast without compromising security.
- Architect and evolve scalable controls across AWS, Azure, and (increasingly) GCP — including identity, network segmentation, workload, and container/Kubernetes security.
- Drive adoption of AI-powered security tooling (agentic SOC workflows, AI-assisted triage, and code/IaC scanning copilots) to scale the security team's productivity, while building the AI security posture management (AI-SPM) and governance needed to defend against AI-enabled threats — prompt injection, model/data exfiltration, adversarial inputs, and unsanctioned "shadow AI" usage across the merged engineering org.
- Lead the harmonization of cloud security posture, guardrails, and tooling across previously separate Compass and Anywhere technology stacks
- Act as the technical escalation point and senior partner for CNAPP tooling strategy (e.g., Wiz, Orca, Lacework, Upwind), driving consolidation decisions and maximizing signal-to-noise for engineering teams.
- Lead technical response for high-severity cloud security events, and drive the resulting engineering and process improvements to prevent recurrence.
- Set the bar for threat modeling and architectural security review, embedding these practices early in the development lifecycle across multiple engineering orgs.
- Mentor and level up senior and mid-level security engineers; act as a force multiplier through documentation, tooling, and technical coaching rather than one-off reviews.
- Represent Security in cross-functional and leadership forums — partnering directly with Engineering leadership, Compliance, and Legal on risk tradeoffs, roadmap prioritization, and audit readiness (e.g., SOC 2, public-company controls).
- Evaluate emerging AI tools and third-party integrations for security and compliance risk, balancing business velocity against data integrity and regulatory exposure.
Who you are:
- A recognized technical leader in cloud security who is equally comfortable writing the automation and setting the multi-quarter architectural strategy.
- You default to automation and self-service over manual gatekeeping, and you've built systems that scale security across hundreds of engineers, not just a single team.
- Deep, hands-on expertise securing AWS at scale, with strong working expertise in Azure and growing familiarity with GCP.
- A clear, credible communicator who can move fluidly between a whiteboard architecture review with staff engineers and a risk conversation with senior leadership.
- Experienced running or heavily shaping incident response for cloud-native environments, from detection through postmortem-driven remediation.
- Track record of driving org-wide adoption of security standards — not just defining them.
- Comfortable operating in ambiguity, particularly the kind that comes from integrating two large, previously independent technology estates.
Minimum Qualifications:
- 8+ years in security engineering roles, including 4+ years focused specifically on cloud security architecture at scale.
- Demonstrated experience owning cloud security strategy or architecture for an organization of significant scale (large engineering org, multi-cloud, or post-M&A environment strongly preferred).
- Deep, production-grade expertise with AWS security services (IAM, EC2, VPC, container services including ECR, ECS, EKS) and strong working knowledge of Azure security controls.
- Hands-on experience deploying and operationalizing a CNAPP or equivalent cloud security platform (e.g., Wiz, Orca Security, Lacework, Upwind) at an organizational level, including tool evaluation and consolidation.
- Strong proficiency in at least one programming language (e.g., Python, Go) used to build production-grade security automation and tooling, not just scripts.
- Deep fluency in core security principles — least privilege, defense-in-depth, zero trust, and security monitoring — and the judgment to apply them pragmatically.
- Strong experience with containerization (Docker) and Kubernetes security at scale.
- Demonstrated experience mentoring engineers and influencing technical direction beyond your immediate team.
Nice to have:
- Experience with GCP, OCI, or designing cloud-agnostic, multi-cloud security architectures.
- Experience securing environments through a merger, acquisition, or major infrastructure consolidation.
- Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
- Relevant certifications (e.g., AWS Security Specialty, CISSP, OSCP) — valued but never a substitute for demonstrated hands-on impact.
Perks that You Need to Know About:
Participation in our incentive programs (which may include eligible cash, equity, or commissions). Plus paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.
Office