{"schemaVersion":"jobsearcher.job.v1","id":"fe392093886ceac4a3a91ee1","url":"https://jobsearcher.com/jobs/fe392093886ceac4a3a91ee1","canonicalUrl":"https://jobsearcher.com/jobs/fe392093886ceac4a3a91ee1","title":"Staff Security Engineer (DevSecOps)","description":"Staff Security EngineerCompa is a venture-backed AI startup revolutionizing the future of compensation! We're bringing AI-forward tools and human-centered engineering to make pay competitive and fair, for all. By offering a premier, live compensation data platform that delivers top-tier intelligence to enterprise teams, we enable the world's largest companies to make smart and fair decisions while staying competitive and compliant. In dynamic job markets during the rise of AI, companies need the best data to stay competitive!\r\nOur force-multiplying team is powered by live data and thoughtful design, and our products have earned the trust of the world's largest companies: NVIDIA, Stripe, DoorDash, OpenAI, Moderna, Workday, Ulta, Target, and more.\r\nCome build with us!\r\nThe RoleWe're looking for a Staff Security Engineer to own DevSecOps at Compa, reporting directly to the Head of Security. This role has enterprise scope, and operates at the intersection of software engineering security operations - hands-on, in the code, partnering daily with Product, Platform, Engineering, and Security. You'll own threat modeling and feature risk assessment end to end, designing alongside Product and Engineering and staying with it through ship, making sure guardrails scale alongside the business and engineers are enabled each step of the way.\r\nWhat You'll DoBuild Security Tooling, and Ship It\r\nBuild and ship internal security tooling, automation, and guardrails.\r\nImplement secure-by-default patterns, libraries, and paved paths that strengthen posture while reducing developer friction.\r\nPrototype and deliver production-ready implementations for security initiatives.\r\nOwn Threat Modeling\r\nLead security design reviews for new features, third-party integrations, and emerging technologies.\r\nBuild and own threat detection across applications, APIs, cloud infrastructure, and data pipelines.\r\nSecure the Pipeline and Infrastructure\r\nEmbed security into CI/CD, such as container security scanning, dependency and image analysis, SAST/DAST, and automated checks in the release process, defining end-to-end security controls for code as built, shipped, and deployed.\r\nPartner on cloud security posture, infrastructure hardening, secrets management, workload identity, and security observability.\r\nContribute to incident response, investigations, and remediation when needed.\r\nLevel Up Engineers\r\nTrain engineers and operationalize security practices the team that drives security-first engineering culture. Turning one-off fixes into repeatable, self-serve patterns.\r\nAdvance AI Security\r\nSecure AI-native and AI-assisted development workflows, and translate emerging AI risks into practical engineering controls.\r\nServe as the security subject matter expert for Compa's AI-powered products and features across the product lifecycle.\r\nWhat We're Looking ForSenior or Staff level experience blending software engineering and security operations. Experience writing production code, not just reviewing it.\r\nHands-on DevSecOps background: CI/CD security, container security scanning, cloud/infra hardening, secrets management.\r\nSuccessful ownership and improvement of threat modeling and risk assessment end to end, from design through production.\r\nExperience building and operationalizing security tooling that engineers actually adopt\r\nHands-on AI work (professionally or on your own) across both AI-native development and AI as a product.\r\nAs a PlusExperience securing cloud-native infrastructure in AWS environments.\r\nExperience designing or implementing enterprise-facing capabilities such as SAML, SCIM, RBAC, audit logging, or customer-facing security controls.\r\nExperience building, operating, or securing AI-enabled products, agents, MCP servers, or retrieval systems.\r\nExperience building or scaling a Product Security or Security Engineering function in a high-growth technology company.\r\nCompa offers a competitive and comprehensive benefits package including medical, dental, vision, PTO and parental leave, equity, company offsites, continuous education, commuter benefits and a flexible work environment.","company":"Compa","rawCompany":"compa","city":"Irvine","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-07T01:40:36.433Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Staff Security Engineer (DevSecOps)","description":"Staff Security EngineerCompa is a venture-backed AI startup revolutionizing the future of compensation! We're bringing AI-forward tools and human-centered engineering to make pay competitive and fair, for all. By offering a premier, live compensation data platform that delivers top-tier intelligence to enterprise teams, we enable the world's largest companies to make smart and fair decisions while staying competitive and compliant. In dynamic job markets during the rise of AI, companies need the best data to stay competitive!\r\nOur force-multiplying team is powered by live data and thoughtful design, and our products have earned the trust of the world's largest companies: NVIDIA, Stripe, DoorDash, OpenAI, Moderna, Workday, Ulta, Target, and more.\r\nCome build with us!\r\nThe RoleWe're looking for a Staff Security Engineer to own DevSecOps at Compa, reporting directly to the Head of Security. This role has enterprise scope, and operates at the intersection of software engineering security operations - hands-on, in the code, partnering daily with Product, Platform, Engineering, and Security. You'll own threat modeling and feature risk assessment end to end, designing alongside Product and Engineering and staying with it through ship, making sure guardrails scale alongside the business and engineers are enabled each step of the way.\r\nWhat You'll DoBuild Security Tooling, and Ship It\r\nBuild and ship internal security tooling, automation, and guardrails.\r\nImplement secure-by-default patterns, libraries, and paved paths that strengthen posture while reducing developer friction.\r\nPrototype and deliver production-ready implementations for security initiatives.\r\nOwn Threat Modeling\r\nLead security design reviews for new features, third-party integrations, and emerging technologies.\r\nBuild and own threat detection across applications, APIs, cloud infrastructure, and data pipelines.\r\nSecure the Pipeline and Infrastructure\r\nEmbed security into CI/CD, such as container security scanning, dependency and image analysis, SAST/DAST, and automated checks in the release process, defining end-to-end security controls for code as built, shipped, and deployed.\r\nPartner on cloud security posture, infrastructure hardening, secrets management, workload identity, and security observability.\r\nContribute to incident response, investigations, and remediation when needed.\r\nLevel Up Engineers\r\nTrain engineers and operationalize security practices the team that drives security-first engineering culture. Turning one-off fixes into repeatable, self-serve patterns.\r\nAdvance AI Security\r\nSecure AI-native and AI-assisted development workflows, and translate emerging AI risks into practical engineering controls.\r\nServe as the security subject matter expert for Compa's AI-powered products and features across the product lifecycle.\r\nWhat We're Looking ForSenior or Staff level experience blending software engineering and security operations. Experience writing production code, not just reviewing it.\r\nHands-on DevSecOps background: CI/CD security, container security scanning, cloud/infra hardening, secrets management.\r\nSuccessful ownership and improvement of threat modeling and risk assessment end to end, from design through production.\r\nExperience building and operationalizing security tooling that engineers actually adopt\r\nHands-on AI work (professionally or on your own) across both AI-native development and AI as a product.\r\nAs a PlusExperience securing cloud-native infrastructure in AWS environments.\r\nExperience designing or implementing enterprise-facing capabilities such as SAML, SCIM, RBAC, audit logging, or customer-facing security controls.\r\nExperience building, operating, or securing AI-enabled products, agents, MCP servers, or retrieval systems.\r\nExperience building or scaling a Product Security or Security Engineering function in a high-growth technology company.\r\nCompa offers a competitive and comprehensive benefits package including medical, dental, vision, PTO and parental leave, equity, company offsites, continuous education, commuter benefits and a flexible work environment.","datePosted":"2026-08-07T01:40:36.433Z","dateModified":"2026-08-07T01:40:36.433Z","hiringOrganization":{"@type":"Organization","name":"Compa","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Irvine","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fe392093886ceac4a3a91ee1"},"url":"https://jobsearcher.com/jobs/fe392093886ceac4a3a91ee1"}}