Compass logo
CompassPosted 1 month ago

Staff Security Engineer, Product Security and Architecture

$210,000–$234,100 year

On-siteSeattle, Washington, United States

Full TimeSenior LevelLargeReal Estate

Job Summary

Automate and scale application security by building enhanced CI/CD pipeline tooling and tuning SAST, DAST, and SCA frameworks. Drive secure-by-design architectures by partnering with engineering teams to evaluate solution architectures and provide technical feedback. Serve as a trusted security advisor, offering risk evaluations for new product features, development processes, and AI integration while evangelizing secure-by-design approaches across the organization. Build collaborative relationships with Product and Engineering teams to mature security culture and adopt AI-powered security capabilities like code scanning copilots. Manage multiple complex initiatives in an Agile and DevOps environment, utilizing Python, Bash, and Terraform to provision secure infrastructure on AWS. Stay ahead of industry trends to ensure security capabilities keep pace with evolving business objectives and protect enterprise data assets from emerging threats.

Required Qualifications

  • Bachelor's degree in Computer Science, a related technical field, or equivalent practical work experience
  • Minimum of three (3) years of experience across the following areas: Administering and configuring automated pipeline tools (CI/CD)
  • Minimum of three (3) years of experience across the following areas: Administering and tuning application security testing tools (e.g., SAST, DAST, or SCA)
  • Minimum of three (3) years of experience across the following areas: Automation scripting using Python or Bash
  • Minimum of three (3) years of experience across the following areas: Product development using Python, JavaScript, TypeScript, Golang, or Java
  • Minimum of three (3) years of experience across the following areas: Performing security code reviews for solutions built in Python, JavaScript, TypeScript, Golang, or Java
  • Minimum of three (3) years of experience across the following areas: Participating in security-focused reviews for both vendor and custom business solutions
  • Minimum of three (3) years of experience across the following areas: Hands-on experience with Infrastructure as Code (IaC) tools (e.g., Terraform) to provision secure, reproducible infrastructure
  • Minimum of three (3) years of experience across the following areas: Practical experience working with AWS services, aligning both product solution delivery and security objectives
  • Minimum of three (3) years of experience across the following areas: Hands-on experience using Artificial Intelligence (AI) to assist with product security processes to drive team and operational efficiencies

Desired Qualifications

  • Relevant industry certifications (e.g., CEH, CISSP, CSSLP, GIAC, or cloud security certifications)
  • Direct experience working within high-performing DevOps and Agile cultures
  • Experience with Layer 7 security controls (e.g., Web Application Firewalls (WAF), API Gateways, OAuth2/OIDC implementation, and rate limiting)
  • Experience driving secure-by-design practices across multi-cloud strategies (e.g., AWS, Azure, GCP)
  • Experience reviewing and assessing the use of AI technologies within both vendor-provided and custom-developed business solutions
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce