Staff Security Engineer AI
Boston, MA - USA
Job Summary
At Compass our mission is to help everyone find their place in the world. Founded in 2012 were revolutionizing the real estate industry with our end-to-end platform that empowers residential real estate agents to deliver exceptional service to seller and buyer clients.
Compass has built the first modern end-to-end real estate platform by integrating agents buyers and sellers through technology. Until Compass no one has achieved the blend of the Natural Intelligence that hundreds of thousands of enterprising real estate agents bring to this market with the Artificial Intelligence that cloud mobile and AI technologies enable. We are building AI to empower AI - Artificial Intelligence to empower Agent Intelligence.
As one of the fastest growing technology companies of our generation in an industry larger than any other we have an opportunity and obligation to build a world-class engineering team and the operating platform that will transform real estate.
We are hands-on security engineers helping to build secure resilient and scalable web apps mobile apps and platforms for the real estate industry. We work with a diverse set of teams to provide transparent and automated security tooling and services. We architect secure products perform simulated attacks identify weaknesses and partner with teams to remediate and protect.
Compass is embedding generative and agentic AI directly into the products our agents and clients use every day. This role owns the security of that surface. You will be the technical authority on how Compass builds AI features safely from the model and retrieval layer through agent tool invocation to what ultimately reaches a clients screen. You will work shoulder-to-shoulder with the teams building the AI platform so that platform standards and security standards are one bar not two.
- Own the AI product security roadmap. Define the multi-year vision strategy and standards for securing AI capabilities in the Compass platform developed jointly with the AI platform and product engineering teams.
- Threat model AI capability builds. Drive architectural reviews and threat modeling for new AI features RAG pipelines multi-agent workflows and automated decisioning before they ship.
- Build production guardrails. Architect deploy and automate real-time protections for LLM inputs and outputs including injection mitigation jailbreak defense output verification and sensitive-data egress checks on generated responses.
- Constrain autonomy. Design blast-radius controls for autonomous agents: scoped permissions human-in-the-loop checkpoints for consequential actions action audit trails and safe tool-invocation patterns.
- Secure the retrieval layer. Enforce data access controls source integrity tenancy boundaries and retrieval-boundary protections across RAG and vector store implementations.
- Harden the AI supply chain. Assess the security posture privacy controls data retention and training-use terms of third-party foundation models inference providers and vector stores used in production.
- Instrument and detect. Build detections and telemetry for AI-specific abuse in production anomalous tool invocation prompt abuse patterns unusual retrieval behavior and data exfiltration through model responses and integrate them into our monitoring estate.
- Automate the standard. Ship reusable libraries CI/CD checks and evaluation harnesses so secure AI patterns are the default path for product engineers rather than a review gate.
- Advise and evangelize. Act as the primary technical consultant for AI architecture decisions and translate emerging AI risk into concrete engineering roadmaps for both engineers and executives.
- Automation is your default approach to security especially when securing complex AI systems at scale.
- You have a deep working understanding of transformer architectures inference pipelines RAG prompt engineering and the OWASP Top 10 for LLMs.
- You write production code strong proficiency in Python or Go with experience building real integrations and security pipelines not just prototypes.
- You are proactive about finding and closing gaps in AI/ML workflows through tooling rather than policy.
- You communicate well across audiences translating emerging AI risk into technical roadmaps for engineers and business impact for leadership.
- 7 years in security engineering with 2 years focused on AI/ML or LLM application security.
- Demonstrated experience securing a production AI or ML system end to end development lifecycle deployment and runtime.
- Expertise in adversarial ML and LLM risks including prompt injection model poisoning data extraction and unsafe tool use with hands-on red teaming experience.
- Strong application and cloud security fundamentals: AWS and/or GCP Kubernetes IAM API security and DevSecOps practices.
- Experience threat modeling complex distributed systems and driving remediation with engineering teams.
- Strong strategic communication skills with a proven ability to translate complex technical AI risk into business impact for executive leadership.
- Experience with multi-agent autonomous systems or Model Context Protocol (MCP) based architectures.
- Familiarity with MITRE ATLAS NIST AI RMF or comparable AI threat/risk frameworks.
- Background building evaluation and safety-testing harnesses for LLM applications.
- Experience in a regulated or consumer-data-heavy environment where model outputs touch customer-facing decisions.
- Prior work on AI platform security architecture or secure-by-default AI SDKs.
The base pay range for this position is $210000 - $234000; however base pay offered may vary depending on job-related knowledge skills and experience. Bonuses and restricted stock units may be provided as part of the compensation package in addition to a full range of benefits. Base pay is based on market location. Minimum wage for the position will always be met.
Perks that You Need to Know About:
Participation in our incentive programs (which may include eligible cash equity or commissions). Plus paid vacation holidays sick time parental leave and recharge leave; medical tele-health dental and vision benefits; 401(k) plan; flexible spending accounts (FSAs); commuter program; life and disability insurance; Maven (a support system for new parents); Carrot (fertility benefits); UrbanSitter (caregiver referral network); Employee Assistance Program; and pet insurance.
Required Experience:
Staff IC
About Company
Compass is the home for everyone who wants to be part of a much more equal, democratic and sustainable future.