Senior Security Engineer II
Compass · New York, NY · 2 days ago
Information Technology$176k–$196k/yrFull-time
About the role
This role blends strategic partnership, hands-on engineering, infrastructure security, and automation. Empower engineers with safe-by-default tooling, ensuring engineering velocity by automating security requirements and building robust guardrails.
Responsibilities
- Design and implement scalable systems and controls to secure our cloud infrastructure effectively.
- Collaborate closely with engineering and security teams to drive the deployment of critical security enhancements and control changes across our cloud infrastructure.
- Build enduring, high-trust partnerships with colleagues across the Engineering organization.
- Assist in investigating and responding to security events, then work with teams to guide and improve their security practices.
- Conduct security assessments for third-party integrations and emerging AI tools, ensuring that business productivity does not compromise data integrity or compliance.
Requirements
- Experience: At least 5+ years of experience in a security-related role, with at least 2+ years specifically focused on cloud security.
- Technical Skills: Strong understanding of cloud platforms and security features, particularly AWS (IAM, EC2, VPC, container services like ECR, ECS, and EKS), with foundational knowledge of Azure and/or GCP.
- Proven experience with a CNAPP or similar cloud security tool (e.g., Wiz, Orca Security, Lacework, Upwind).
- Proficiency in at least one programming language (e.g., Python, Go) for automation.
- Knowledge of core security principles such as the principle of least privilege, defense-in-depth, and security monitoring.
- Familiarity with containerization technologies (Docker) and orchestration platforms (Kubernetes).
Qualifications
- Expertise in securing cloud platforms, particularly AWS and Azure.
- Strong analytical and problem-solving skills, with the ability to critically and objectively assess complex security risks.
- Excited to collaborate with cross-functional teams to build secure, reliable, and scalable systems.
- Ability to clearly communicate complex security vulnerabilities and remediation techniques to diverse audiences.
- Experience with threat modeling and architectural review processes; you have a track record of identifying potential attack vectors early in the development lifecycle.
Skills
- Automation is your default approach to security.
- You possess a proactive mindset, adept at identifying and resolving security gaps or inefficiencies through innovative automation and tooling.
Benefits
- Base pay range: $176,000 - $196,000.
- Bonuses and restricted stock units may be provided as part of the compensation package, in addition to a full range of benefits.
- Perks: participation in incentive programs, paid vacation, holidays, sick time, parental leave, and recharge leave; medical, tele-health, dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.
Pay
The base pay range for this position is $176,000 - $196,000; however, base pay offered may vary depending on job-related knowledge, skills, and experience.
Schedule
Not specified.