Jobs Companies Compa Product Security Engineer

Über diese Product Security Engineer Stelle bei Compa

Compa · Hybrid · Engineering Sites- Orange County, Denver, Seattle, San Francisco

About Compa

Compa is a venture-backed AI startup revolutionizing the future of compensation! We're bringing AI-forward tools and human-centered engineering to make pay competitive and fair, for all. By offering a premier, live compensation data platform that delivers top-tier intelligence to enterprise teams, we enable the world's largest companies to make smart and fair decisions while staying competitive and compliant. In dynamic job markets during the rise of AI, companies need the best data to stay competitive!

Our force-multiplying team is powered by live data and thoughtful design, and our products have earned the trust of the world’s largest companies: NVIDIA, Stripe, DoorDash, OpenAI, Moderna, Workday, Ulta, Target, and more.

Come build with us!

The Role

We are looking for a Product Security Engineer to build and scale the Product Security function at Compa. This is the first dedicated security hire at the product layer - a senior individual contributor role reporting directly to the Head of Security.

You’ll set the security bar, establish standards and patterns, provide architectural guidance, and build leverage through tooling and automation. You are an advisor, architect, and builder: Security sets the direction; Engineering builds at scale. You’ll define secure engineering practices, operationalize them through repeatable processes, automation, and developer tooling, and continuously improve them as we grow.

When a strategic security initiative spans application code, cloud infrastructure, identity, and platform, you will lead it from design through initial implementation, then partner with Engineering to scale and maintain.

You will be the security voice in the room when consequential decisions are made, proactively shaping how Engineering and Product think about security, risk, architecture, and secure software development.

Responsibilities

Set the Security Bar

  • Perform architecture reviews, threat modeling, and security design reviews across applications, APIs, cloud infrastructure, data pipelines, and AI-enabled systems.

  • Develop security standards, reference architectures, and secure design patterns that enable teams to build securely by default.

  • Define and continuously improve the Secure Software Development Lifecycle (SDLC), embedding security throughout engineering workflows and release processes.

  • Lead security assessments for new products, major features, third-party integrations, and emerging technologies.

  • Serve as a trusted technical advisor on security architecture, implementation decisions, and risk tradeoffs.

  • Communicate security concepts clearly across audiences — from engineering design reviews to product documentation, trust portal content, and customer diligence conversations.

Build Leverage Through Tooling and Enablement

  • Design and build reusable security patterns, libraries, and developer tooling that scale secure-by-default practices across engineering.

  • Implement security automation and guardrails that improve security posture while reducing developer friction.

  • Partner with Platform Engineering on cloud security posture, infrastructure hardening, secrets management, workload identity, and security observability.

Advance AI Security

  • Define and operationalize secure patterns for AI-enabled products, agents, MCP servers, tool integrations, and retrieval systems.

  • Evaluate emerging AI security risks and translate them into practical architectural guidance, engineering controls, and platform capabilities.

  • Partner with developers to improve the safe and scalable use of AI throughout the software development lifecycle, including AI-assisted tools and emerging workflows.

Build When It Matters

  • Prototype and deliver initial production-ready implementations for strategic initiatives, establishing patterns for broader adoption.

  • Contribute to security incident response, investigations, and remediation when needed.

Minimum Qualifications

  • 5+ years of Software Engineering experience to include building and shipping production software.

  • Strong programming fundamentals in at least one modern language, with aptitude to quickly learn others.

  • Experience performing application security reviews, threat modeling, or security design reviews.

  • Experience designing, building, or securing cloud-native applications and distributed systems.

  • Strong understanding of cloud security, IAM, CI/CD, containers, infrastructure-as-code, and software supply chain security.

  • Experience influencing engineering organizations through technical leadership and architectural guidance.

  • Strong systems thinking, sound judgment, and the ability to reason about architecture, scale, operational risk, and engineering tradeoffs while operating effectively in ambiguous, fast-moving environments.

  • Ability to translate security risk into business and engineering terms, and to influence decisions at the leadership level without direct authority.

Preferred Qualifications

  • Experience securing cloud-native infrastructure in AWS environments.

  • Experience designing or implementing enterprise-facing capabilities such as SAML, SCIM, RBAC, audit logging, or customer-facing security controls.

  • Experience building security automation, developer tooling, or internal platforms that improved engineering velocity and security outcomes.

  • Experience building, operating, or securing AI-enabled products, agents, MCP servers, or retrieval systems.

  • Experience building or scaling a Product Security or Security Engineering function in a high-growth technology company.

Compa offers a competitive and comprehensive benefits package including medical, dental, vision, PTO and parental leave, equity, company offsites, continuous education, commuter benefits and a flexible work environment.

Bereit, sich bei Compa zu bewerben?
Bei Compa bewerben

Wie sich dieses Gehalt für Application Security vergleicht

Diese Stelle zahlt $202,500/yrim Einklang mit der üblichen Spanne für Application Security Stellen.

$111,188 dem Median $190,000 $274,500

Übliche Spanne $160,000–$235,000/yr, aus 174 vergleichbaren Application Security Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Application Security ansehen →

Ähnliche Jobs

Asana
Application Security Engineer
Asana
⚡ Früh bewerben Warsaw Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Roblox
Principal Security Software Engineer, Application Security
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $326,060–$385,050
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Roblox
Senior Security Software Engineer, Application Security
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $269,170–$326,060
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Temporal Technologies
Senior Application Security Engineer
Temporal Technologies
⚡ Früh bewerben United States or Canada - Remo... · standortgebunden $180,000–$225,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Oscar Health
Senior Product Security Engineer I
Oscar Health
⚡ Früh bewerben New York, New York, United Sta... Vor Ort $215,176–$215,176
● Neu 👁 Gesehen ✓ Beworben vor 3 Std.
Smartsheet
Senior Security Engineer II, Application Security (Remote Eligible)
Smartsheet
⚡ Früh bewerben -REMOTE, USA- · standortgebunden $175,000–$245,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Stripe
Software Engineer, Product Security Data Platforms
Stripe
⚡ Früh bewerben Seattle Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Stripe
Software Engineer, Product Security Data Platforms
Stripe
⚡ Früh bewerben Seattle Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
TT
Sr Application Security Engineer
The Trade Desk
⚡ Früh bewerben Bellevue; Ventura Vor Ort $113,500–$208,100
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Compa

Alle Jobs bei Compa ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos