Staff Security Engineer

CompassNew York, NY

About The Position

The Security organization protects one of the largest and most complex real estate technology estates in the industry. We are hands-on engineers who build security as a service: safe-by-default tooling, automated guardrails, and trusted partnership with Engineering, rather than gatekeeping. As a Staff Security Engineer, you will set technical direction for cloud security across the company — defining the architecture, standards, and roadmap that the rest of the security engineering team and the company build against.

Requirements

  • A recognized technical leader in cloud security who is equally comfortable writing the automation and setting the multi-quarter architectural strategy.
  • You default to automation and self-service over manual gatekeeping, and you've built systems that scale security across hundreds of engineers, not just a single team.
  • Deep, hands-on expertise securing AWS at scale, with strong working expertise in Azure and growing familiarity with GCP.
  • A clear, credible communicator who can move fluidly between a whiteboard architecture review with staff engineers and a risk conversation with senior leadership.
  • Experienced running or heavily shaping incident response for cloud-native environments, from detection through postmortem-driven remediation.
  • Track record of driving org-wide adoption of security standards — not just defining them.
  • Comfortable operating in ambiguity, particularly the kind that comes from integrating two large, previously independent technology estates.
  • 8+ years in security engineering roles, including 4+ years focused specifically on cloud security architecture at scale.
  • Demonstrated experience owning cloud security strategy or architecture for an organization of significant scale (large engineering org, multi-cloud, or post-M&A environment strongly preferred).
  • Deep, production-grade expertise with AWS security services (IAM, EC2, VPC, container services including ECR, ECS, EKS) and strong working knowledge of Azure security controls.
  • Hands-on experience deploying and operationalizing a CNAPP or equivalent cloud security platform (e.g., Wiz, Orca Security, Lacework, Upwind) at an organizational level, including tool evaluation and consolidation.
  • Strong proficiency in at least one programming language (e.g., Python, Go) used to build production-grade security automation and tooling, not just scripts.
  • Deep fluency in core security principles — least privilege, defense-in-depth, zero trust, and security monitoring — and the judgment to apply them pragmatically.
  • Strong experience with containerization (Docker) and Kubernetes security at scale.
  • Demonstrated experience mentoring engineers and influencing technical direction beyond your immediate team.

Nice To Haves

  • Experience with GCP, OCI, or designing cloud-agnostic, multi-cloud security architectures.
  • Experience securing environments through a merger, acquisition, or major infrastructure consolidation.
  • Experience operating in a publicly traded company, including familiarity with SOX-adjacent control environments and audit processes.
  • Relevant certifications (e.g., AWS Security Specialty, CISSP, OSCP) — valued but never a substitute for demonstrated hands-on impact.

Responsibilities

  • Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction that other security and platform engineers build on.
  • Design and drive adoption of safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails that let engineering teams move fast without compromising security.
  • Architect and evolve scalable controls across AWS, Azure, and (increasingly) GCP — including identity, network segmentation, workload, and container/Kubernetes security.
  • Drive adoption of AI-powered security tooling (agentic SOC workflows, AI-assisted triage, and code/IaC scanning copilots) to scale the security team's productivity, while building the AI security posture management (AI-SPM) and governance needed to defend against AI-enabled threats — prompt injection, model/data exfiltration, adversarial inputs, and unsanctioned "shadow AI" usage across the merged engineering org.
  • Lead the harmonization of cloud security posture, guardrails, and tooling across previously separate Compass and Anywhere technology stacks
  • Act as the technical escalation point and senior partner for CNAPP tooling strategy (e.g., Wiz, Orca, Lacework, Upwind), driving consolidation decisions and maximizing signal-to-noise for engineering teams.
  • Lead technical response for high-severity cloud security events, and drive the resulting engineering and process improvements to prevent recurrence.
  • Set the bar for threat modeling and architectural security review, embedding these practices early in the development lifecycle across multiple engineering orgs.
  • Mentor and level up senior and mid-level security engineers; act as a force multiplier through documentation, tooling, and technical coaching rather than one-off reviews.
  • Represent Security in cross-functional and leadership forums — partnering directly with Engineering leadership, Compliance, and Legal on risk tradeoffs, roadmap prioritization, and audit readiness (e.g., SOC 2, public-company controls).
  • Evaluate emerging AI tools and third-party integrations for security and compliance risk, balancing business velocity against data integrity and regulatory exposure.

Benefits

  • Participation in our incentive programs (which may include eligible cash, equity, or commissions).
  • Paid vacation, holidays, sick time, parental leave, and recharge leave
  • Medical, tele-health, dental and vision benefits
  • 401(k) plan
  • Flexible spending accounts (FSAs)
  • Commuter program
  • Life and disability insurance
  • Maven (a support system for new parents)
  • Carrot (fertility benefits)
  • UrbanSitter (caregiver referral network)
  • Employee Assistance Program
  • Pet insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service