Senior Security Engineer - Enterprise
Listed on 2026-10-04
-
IT/Tech
Cybersecurity
At Compass, our mission is to help everyone find their place in the world. Founded in 2012, we’re revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.
Engineering @ CompassCompass is building the first modern end-to-end real estate platform by integrating agents, buyers and sellers through technology. Until Compass, no one has achieved the blend of the Natural Intelligence that hundreds of thousands of enterprising real estate agents bring to this market, with the “Artificial Intelligence” that cloud, mobile and AI technologies enable. We are building AI to empower AI - Artificial Intelligence to empower Agent Intelligence.
Security@ Compass
We recognize that the most innovative teams are built from diverse backgrounds and unique skill sets, which is why we don't expect any single candidate to check every box. You do not need to meet 100% of these qualifications to apply. We are primarily looking for deep, practical experience in at least one of our core domains—such as endpoint management, identity, AI security, or Infrastructure-as-Code—along with a strong desire to learn the rest.
If you are passionate about solving complex security challenges and eager to grow alongside Compass, we highly encourage you to submit your application.
- Ensure Safe-by-Default Environments: Empower team members by securing all enterprise technologies, including SaaS applications, corporate endpoints, office networks, and Business/Data Intelligence tools.
- Modernize Endpoint Management: Work across endpoint management, identity, and security operations to improve how Compass manages macOS, iOS, Windows, and Linux devices. In your first year, you will strengthen endpoint security architecture, expand automation, and improve the reliability and auditability of control deployments.
- Drive Git Ops & IaC Workflows: Manage endpoint and SaaS security configurations through Terraform, version control, merge requests, continuous integration (CI) pipelines, and automated rollouts.
- Automate Lifecycle Security: Design and support automation for secure endpoint deployment, configuration, patching, and software distribution that aligns with strict security and operational compliance.
- Govern AI & MCP Security: Manage AI guardrails for business applications and Model Context Protocol (MCP) server management. Enforce secure MCP usage, conduct prompt security evaluations, review vibe-coded apps, and manage approved AI agents and endpoint tools to reduce the risk surface.
- Assess Third-Party & AI Risk: Evaluate the security properties and AI-feature risks of 3rd-party systems integrating into our enterprise environment. Provide comprehensive architecture, design, and process automation reviews.
- Partner on Detection & Response: Collaborate with the Detection and Response team to select corporate focus areas, develop incident workflows, and implement new solutions to thwart business email compromise (BEC).
- Iterate and Improve: Conduct regular security assessments on controls and applications, and provide the foundational security principles and tooling necessary to support our rapidly growing agent population and expansion into new markets.
- Empathetic & Accountable: You bring a practical, security-focused approach to problem solving, building customer trust while helping to improve the overall security program.
- Clear Communicator: Able to articulate security vulnerabilities, remediation techniques, and technical protocol functions (SAML, SCIM, OAuth, OIDC, SMTP, DNS) in an accessible way across a distributed, all-remote workforce.
- Automation-First Engineer: You have strong proficiency in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).