Compass logo
CompassPosted 1 month ago

Staff Security Engineer

On-siteNew York City, New York, United States

Full TimeSenior LevelLargeReal Estate

Job Summary

Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction for other security and platform engineers. Design safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails to enable fast engineering without compromising security. Architect scalable controls across AWS, Azure, and GCP, including identity, network segmentation, and container/Kubernetes security. Drive adoption of AI-powered security tooling and governance to defend against AI-enabled threats while harmonizing security posture across previously separate Compass and Anywhere stacks. Act as the technical escalation point for CNAPP tooling strategy and lead response for high-severity cloud security events, embedding threat modeling early in the development lifecycle. Mentor senior and mid-level engineers through documentation and technical coaching rather than one-off reviews. Represent Security in cross-functional forums to drive risk tradeoffs, roadmap prioritization, and audit readiness with Engineering leadership, Compliance, and Legal.

Required Qualifications

  • 8+ years in security engineering roles
  • 4+ years focused specifically on cloud security architecture at scale
  • Demonstrated experience owning cloud security strategy or architecture for an organization of significant scale
  • Deep, production-grade expertise with AWS security services (IAM, EC2, VPC, container services including ECR, ECS, EKS)
  • Strong working knowledge of Azure security controls
  • Hands-on experience deploying and operationalizing a CNAPP or equivalent cloud security platform (e.g., Wiz, Orca Security, Lacework, Upwind) at an organizational level
  • Strong proficiency in at least one programming language (e.g., Python, Go) used to build production-grade security automation and tooling
  • Deep fluency in core security principles — least privilege, defense-in-depth, zero trust, and security monitoring
  • Strong experience with containerization (Docker) and Kubernetes security at scale
  • Demonstrated experience mentoring engineers and influencing technical direction beyond your immediate team
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes

Desired Qualifications

  • Experience with GCP, OCI, or designing cloud-agnostic, multi-cloud security architectures
  • Experience operating in a post-M&A environment
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
  • Relevant certifications (e.g., AWS Security Specialty, CISSP, OSCP)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce