urbancompass
Staff Security Engineer, Product Security and Architecture
At a Glance
- Location
- New York City
- Experience
- 8+ years
- Posted
- 2026-07-21T09:02:15-04:00
Key Requirements
Required Skills
Certifications
- CISSP
- OSCP
Domain Knowledge
- Automation
- Defense
- Engineering
- Insurance
- Medical
Requirements
A recognized technical leader in cloud security who is equally comfortable writing the automation and setting the multi-quarter architectural strategy.
You default to automation and self-service over manual gatekeeping, and you've built systems that scale security across hundreds of engineers, not just a single team.
Deep, hands-on expertise securing AWS at scale, with strong working expertise in Azure and growing familiarity with GCP.
Experienced running or heavily shaping incident response for cloud-native environments, from detection through postmortem-driven remediation.
Track record of driving org-wide adoption of security standards — not just defining them.
Comfortable operating in ambiguity, particularly the kind that comes from integrating two large, previously independent technology estates.
Responsibilities
Own the technical strategy and architecture for cloud security across CIH's multi-cloud environment, setting direction that other security and platform engineers build on.
Design and drive adoption of safe-by-default infrastructure patterns, paved-road tooling, and automated guardrails that let engineering teams move fast without compromising security.
Architect and evolve scalable controls across AWS, Azure, and (increasingly) GCP — including identity, network segmentation, workload, and container/Kubernetes security.
Drive adoption of AI-powered security tooling (agentic SOC workflows, AI-assisted triage, and code/IaC scanning copilots) to scale the security team's productivity, while building the AI security posture management (AI-SPM) and governance needed to defend against AI-enabled threats — prompt injection, model/data exfiltration, adversarial inputs, and unsanctioned "shadow AI" usage across the merged engineering org.
Lead the harmonization of cloud security posture, guardrails, and tooling across previously separate Compass and Anywhere technology stacks
Act as the technical escalation point and senior partner for CNAPP tooling strategy (e.g., Wiz, Orca, Lacework, Upwind), driving consolidation decisions and maximizing signal-to-noise for engineering teams.