Compass logo
CompassPosted 1 month ago

Senior Security Engineer II

$176,000–$196,000 year

On-siteSeattle, Washington, United States

Full TimeSenior LevelLargeReal Estate

Job Summary

Empower engineers with safe-by-default tooling by automating security requirements and building robust guardrails. Design and implement scalable systems and controls to secure cloud infrastructure effectively, collaborating closely with engineering teams to drive the deployment of critical security enhancements. Conduct security assessments for third-party integrations and emerging AI tools, ensuring business productivity does not compromise data integrity or compliance. Assist in investigating and responding to security events, then work with teams to guide and improve their security practices. Build enduring, high-trust partnerships with colleagues across the Engineering organization to lead the effort in building security as a service. This role blends strategic partnership, hands-on engineering, infrastructure security, and automation within Security @ Compass.

Required Qualifications

  • At least 5+ years of experience in a security-related role
  • At least 2+ years specifically focused on cloud security
  • Strong understanding of cloud platforms and security features, particularly AWS (IAM, EC2, VPC, container services like ECR, ECS, and EKS)
  • Foundational knowledge of Azure and/or GCP
  • Strong understanding of Azure services and how to secure them
  • Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind)
  • Proficiency in at least one programming language (e.g., Python, Go) for automation
  • Knowledge of core security principles such as the principle of least privilege, defense-in-depth, and security monitoring
  • Familiarity with containerization technologies (Docker) and orchestration platforms (Kubernetes)
  • Experience with threat modeling and architectural review processes
  • Track record of identifying potential attack vectors early in the development lifecycle
  • Automation is your default approach to security
  • You understand the unique challenges of securing systems at scale
  • Consistently leverage automation to solve them
  • You possess a proactive mindset
  • Adept at identifying and resolving security gaps or inefficiencies through innovative automation and tooling
  • Strong analytical and problem-solving skills
  • Ability to critically and objectively assess complex security risks
  • You can clearly communicate complex security vulnerabilities and remediation techniques to diverse audiences
  • You are comfortable guiding and educating development teams to achieve stronger security outcomes

Desired Qualifications

  • Experience with GCP, OCI and multi-cloud networks and infrastructure, especially when designing cloud-agnostic systems

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce