Senior Security Engineer, Cloud Red Team, Cloud CISO
About the role
The CISO will report directly to the CTO and serve as the company's foremost authority on information security, risk management, and compliance. This leader will partner across Engineering, Product, Legal, and Finance to embed security into the DNA of how Compass builds and operates.
Responsibilities
- Design and drive a comprehensive, enterprise-wide information security and risk management program — covering integrity, confidentiality, and availability of all data owned, processed, or controlled by Compass and its affiliates, including Title & Escrow, Brokerage, and Technology platforms
- Lead all critical security domains: incident response, application security, threat intelligence, monitoring and detection, security engineering, information governance, and product security
- Establish and maintain SOX-compliant internal controls and ensure ongoing CPRA compliance, with direct accountability to audit and regulatory requirements
- Serve as the primary security voice to the Board, executive leadership, regulators, investment partners, and external customers — including public defense of the company's security posture when required
- Define the security roadmap and operating model for a company that spans agents, buyers, sellers, and technology platforms across the full real estate transaction lifecycle
- Partner closely with Engineering and Product to ensure all applications and services are built on secure-by-default principles across people, processes, and technology
- Strengthen third-party and vendor security controls as Compass scales its ecosystem of affiliated businesses and technology integrations
Requirements
Technical Depth: 12+ years of technical experience in software, systems, or security engineering, with a deep command of security architecture and Computer Science fundamentals. Technical roots preferred — candidates with hands-on engineering or security engineering backgrounds are strongly favored, though exceptional leaders who have built and maintained technical credibility through other means will be considered.
Security Leadership: 10+ years of senior security leadership experience within a complex, global technology organization — ideally in a publicly traded company with international scope. Mastery across multiple security domains with deep expertise in Computer Science and Business Systems. Demonstrated expertise across the full security stack: AppSec, cloud security, identity, GRC, threat modeling, incident response, and security operations. Hands-on experience building and operating SOX-compliant programs and deep familiarity with CPRA and related privacy regulations.
Product & Platform Experience: Experience in a product-led business, ideally a web product responsible for hosting and protecting sensitive customer data at scale. Cloud-native/SaaS-first fluency — deep familiarity operating in modern infrastructure environments (AWS, GCP, or Azure) with a security posture built for cloud from the ground up.
Risk & Business Acumen: Data and metrics-driven approach to risk — ability to quantify, prioritize, and communicate security risk using a structured, evidence-based framework. Track record of translating security strategy into measurable business value, with a data-first approach to communicating risk to non-technical stakeholders. Ability to operate and prioritize in a high-velocity, high-complexity environment where the business model spans technology, brokerage, and financial services.
Leadership & Communication: Proven ability to build, scale, and lead high-performing security teams across multiple time zones. Strong executive presence and communication skills; experience presenting to Boards, regulators, and external partners on matters of security and risk.
Qualifications
Exceptional leadership and technical acumen, with a proven track record of driving successful security programs and partnerships across diverse teams and geographies.
Experience in a complex, global technology organization with a demonstrated ability to manage and mitigate security risks at scale.
Proven ability to translate security strategies into measurable business outcomes and influence decision-making at all levels of the organization.
Strong interpersonal and communication skills, with the ability to collaborate effectively with cross-functional teams and stakeholders.
Ability to lead and inspire a diverse team of security professionals, fostering a culture of innovation and continuous improvement.
Skills
Deep understanding of security architecture, risk management, and compliance frameworks such as SOX and CPRA.
Expertise in multiple security domains including incident response, application security, threat intelligence, monitoring and detection, security engineering, information governance, and product security.
Experience in building and maintaining SOX-compliant programs and deep familiarity with CPRA and related privacy regulations.
Strong technical background with hands-on experience in software, systems, or security engineering.
Experience in a product-led business, ideally a web product responsible for hosting and protecting sensitive customer data at scale.
Cloud-native/SaaS-first fluency with a security posture built for cloud from the ground up.
Benefits
Competitive executive compensation package including bonus and equity
Full range of benefits including medical, tele-health, dental and vision benefits, 401(k) plan, flexible spending accounts (FSAs), commuter program, life and disability insurance, Maven (a support system for new parents), Carrot (fertility benefits), UrbanSitter (caregiver referral network), Employee Assistance Program, and pet insurance.
Pay
The base pay range for this position is $350,000 - $400,000; however, base pay offered may vary depending on job-related knowledge, skills, and experience.
Schedule
Full-time position