Compa logo
Compa

Compa is a venture-backed SaaS startup revolutionizing the future of compensation. In a dynamic job market with hiring challenges, accountability, and the rise of AI, companies need the best data to stay ahead of industry changes, competition, and costs. Compa has developed the premier real-time compensation data platform, delivering top-tier compensation intelligence to leading enterprise teams. Compa is a compensation intelligence company built to augment enterprise compensation teams in the era of AI. Our customers include the world’s biggest companies: Apple, NVIDIA, Tesla, Mastercard, T-Mobile, Sanofi, Moderna, Gilead Sciences, and more.

Enterprise Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 70Since 2020Company Site

Location

California

Posted

3 days ago

Salary

$175K - $205K / year

Seniority

Senior

English

Job Description

Enterprise Security Engineer

Compa

About CompaCompa is a venture-backed AI startup revolutionizing the future of compensation. In a dynamic job market with hiring challenges, accountability, and the rise of AI, companies need the best data to stay ahead of industry changes, competition, and costs. Compa has developed the premier real-time compensation data platform, delivering top-tier compensation intelligence to leading enterprise teams. Compa is a compensation intelligence company built to augment enterprise compensation teams in the era of AI. Our customers include the world’s biggest companies: NVIDIA, Stripe, DoorDash, Open AI, TMobile, Moderna, Workday, Ulta, Target, and more. Locations: Compa headquarters are located in Irvine, California, with growing sites in Denver, Colorado and San Francisco, California. We’re a collaborative, curious, and driven team that values transparency, ownership, and continuous learning and prioritizing in person work where possible. The Role We are looking for an Enterprise Security Engineer to help build and operate Compa’s security-first enterprise environment. This is a senior individual contributor role reporting directly to the Head of Security & IT. You'll own the systems that define how employees access, use, and interact with technology at Compa — identity, access, endpoints, and enterprise SaaS — and treat them as core security infrastructure, not traditional IT. This role sits on the Security team and partners closely with the rest of the business to help Compa move fast, securely, all while delivering a world-class employee experience. We're open to candidates earlier in their career who demonstrate strong systems thinking, sound judgment, and the ability to design for scale. We care more about what you can do than how many years you have been doing it. In this role you will - Design, build, and operate Compa’s enterprise security systems, including identity, access control, endpoint management, and enterprise SaaS administration. - Own end-to-end identity and access workflows, including role-based access models, access packages, provisioning, deprovisioning, and ongoing access hygiene. - Support employees by ensuring reliable, secure access to the tools they need, resolving access and device issues with a strong bias toward durable, system-level fixes. - Implement security-first onboarding, offboarding, and access change processes that scale smoothly as the company grows. - Design and maintain integrations across enterprise security systems (identity, devices, SaaS, and supporting tooling) to ensure consistency, reliability, and scalability. - Automate wherever possible, reducing manual work and operational risk while improving reliability, auditability, and employee experience. - Operate and continuously improve endpoint and device management systems (for example: Jamf, Intune), balancing security requirements with usability. - Own the accuracy and consistency of enterprise security sources of truth, including users, devices, and applications. - Collaborate with the Security team on shared security operations responsibilities, helping improve detection, response, and investigation through better system design, signals, and operational readiness. - Continuously raise Compa’s defensive posture by evolving enterprise security controls such as just-in-time access, trusted devices, and zero trust, and by contributing to a strong internal security culture. - Support the security team with access reviews, audits, and investigations by providing high-quality system design, evidence, and operational context. - Maintain clear documentation, runbooks, and operational processes that enable resilience, self-service, and predictable failure modes. - Act as a force multiplier for the Security team by translating security intent into durable, well-designed enterprise systems that allow Compa to move fast, securely. What success looks like - Employees have fast, secure access to the tools they need, with minimal friction and a consistently strong user experience. - Access is clean, role-based, least-privilege, continuously reviewed, and auditable. - Enterprise security systems scale smoothly as the company grows and evolve as new risks emerge. - Manual work is continuously reduced through automation, better system design, and clear sources of truth. - Enterprise systems provide reliable signals that support detection, response, and investigation. - Security, compliance, and operational needs reinforce each other rather than compete, enabling Compa to move fast, securely. Minimum Qualifications - Demonstrated experience owning and operating enterprise systems such as identity providers, access management, endpoint management, or enterprise SaaS platforms. - Strong systems thinking: ability to reason about workflows, failure modes, scale, and operational risk. - Comfort designing access models and operational processes, not just executing tickets. - Ability to automate or significantly reduce manual operational work, and to improve systems over time. - Ability to support users effectively by diagnosing and resolving system issues with a bias toward durable fixes. - Clear written and verbal communication, especially around systems, trade-offs, and security implications. - Low ego, strong ownership mindset, and good judgment in ambiguous environments. - Gumption — experience working in high-growth or resource-constrained environments. Preferred Qualifications - Experience operating identity and access management systems (for example: Microsoft Entra). - Experience designing role-based access control, access reviews, and provisioning workflows. - Familiarity with compliance frameworks such as SOC 2 and supporting audits through system evidence. - Experience contributing to detection, response, or investigation through identity, device, or access signals. - Experience supporting organizations with high security and privacy expectations. - Interest in continuously improving defensive posture through controls such as just-in-time access, trusted devices, or identity-driven security. - Interest in growing into broader ownership over Enterprise Security or IT as the company scales.

Related Categories

Related Job Pages

More Security Engineer Jobs

Netflix logo

Security Software Engineer 5

Netflix

Described as the world's top internet television network, Netflix is a publicly-traded entertainment company offering video-on-demand and streaming media. As an

Role Description This role focuses on building the access experience layer at Netflix — designing, building, and operating the services that make access control safe and straightforward for hundreds of internal engineering teams. You will be part of the Access Experience Engineering (AXE) team in Warsaw, Poland, focusing on the integration and experience layer that sits on top of Netflix's core access control infrastructure. You will partner closely with ACE and the Security Services Engineering organization, both primarily based in UCAN, as part of a follow-the-sun, async-first model. - Ownership of system design, implementation, partner integration, rollout strategy, and maintenance of access tooling and integration services. - Work on the adoption layer for Turnstile, Netflix's next-generation access management platform. - Develop APIs, SDKs, and self-service workflows that enable internal teams to implement access securely and consistently. - One engineer on this team will serve as an in-time-zone security anchor — a technical lead who brings a pragmatic, risk-aware lens to AXE's designs and implementations. This role is based in Poland and can be performed remotely within the country. Qualifications - Ability to work collaboratively to solve problems, navigate ambiguity, make and communicate self-directed decisions, and weigh trade-offs. - Experience building scalable, reliable, high-availability, and low-latency services. - Proficiency in modern languages (Java preferred, or Kotlin, Go, Python) and an openness to work across the tech stack as needed. - Experience designing and building developer-facing APIs, SDKs, and integration patterns that make complex systems straightforward for other teams to adopt. - Familiarity with access control and IAM concepts — identity, authentication, authorization, roles, groups, attributes, and resource models. - Experience with auth protocols, including OpenID Connect, OAuth, SAML, and SCIM. - Strong software engineering fundamentals with an interest in the domain. - Experience with GraphQL, gRPC, REST, or similar technologies. - Effective written communication skills and a product-focused mindset, with a security-first approach. Requirements - Experience designing complex access control models using industry standards like RBAC, ABAC, or ReBAC. - Experience with continuous integration and continuous deployment in a cloud platform. - Experience with NoSQL technologies such as Hive, Presto, Spark, or Cassandra. - Experience with graph databases. - Experience with React or another modern frontend framework for full-stack work. Inclusion Inclusion is a Netflix value and we strive to host a meaningful interview experience for all candidates. If you want an accommodation/adjustment for a disability or any other reason during the hiring process, please send a request to your recruiting partner. We are an equal-opportunity employer and celebrate diversity, recognizing that diversity builds stronger teams. We approach diversity and inclusion seriously and thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.

Poland

Role Description We are excited to be a sponsor of Hiring our Heroes and proud to offer transitioning service members a unique opportunity to gain valuable professional experience through our 12-week fellowship program. During your fellowship with our company, you will have the chance to collaborate with our Veterans Leadership Network and receive support from various stakeholders within the organization. To ensure your success, each fellow is paired with a buddy who will provide guidance, mentorship, and different perspectives. Additionally, you will have access to a career development advisor who will offer support and guidance in managing your career. As a fellow, you will be part of a Cohort consisting of other transitioning service members. This will enable you to engage in weekly touchpoints, attend educational sessions, and receive direction from our Veteran Talent Program Lead throughout the Fellowship. Our primary objective is to provide you with mentoring, networking opportunities, and exposure to help facilitate a successful transition into a full-time position within our company. Offensive Security Operations (OSO) is a global function responsible for validating the effectiveness of enterprise security controls through adversary emulation and red team engagements. The team focuses on identifying real-world attack paths across enterprise, cloud, and operational environments to measure risk exposure and strengthen defensive capabilities. Fellows will work alongside OSO team members to support the planning and coordination of red team and adversary emulation activities. This includes: - Tracking engagement timelines - Supporting execution logistics - Helping develop reporting outputs that clearly communicate risk to stakeholders Fellows will participate in team meetings and complete internal training to build an understanding of how offensive security assessments are planned, executed, and delivered. The role involves working across multiple teams, including cybersecurity, infrastructure, cloud, and operational technology groups, to support engagement objectives. Fellows may interact with both internal stakeholders and partner teams to help coordinate activities and ensure successful execution of engagements. They will gain exposure to project management tools and processes used to track activities, manage dependencies, and deliver outcomes in a fast-paced, results-driven environment. You will be part of a diverse, cross-functional team focused on identifying and validating enterprise risk through real-world attack simulation. The fellowship includes progressive, hands-on training and project-based assignments under the direction of red team leadership, providing practical experience in both offensive security operations and program execution. Your Fellowship Project You will partner with Offensive Security Operations (OSO) team members to learn core tools, processes, and methodologies used to plan, execute, and deliver adversary emulation and red team engagements. You will support project execution activities that are critical to validating enterprise security controls and identifying real-world risk exposure. The fellowship intends to: - Develop an understanding of adversary emulation and red team methodologies - Develop an understanding of attack frameworks (e.g., MITRE ATT&CK) and how they are applied to simulate real-world threats - Develop an understanding of tools, platforms, and environments used to conduct offensive security operations - Participate in project planning, execution tracking, and reporting activities to support red team engagements - Engage with cross-functional teams (security, infrastructure, cloud, OT, and application teams) to understand enterprise attack surfaces and risk Benefits - Mentoring and networking opportunities within Offensive Security Operations and broader cybersecurity teams - Exposure to senior leadership across cybersecurity, risk management, and enterprise technology - Hands-on experience supporting red team and adversary emulation engagements - Development of project management, risk analysis, and communication skills in a high-impact security environment Qualifications - Bachelor’s degree or equivalent practical experience (military, technical, or professional background strongly valued) - Strong communication skills (written, verbal, and interpersonal) - Project management, organization, and coordination skills - Ability to work independently, prioritize tasks, and manage multiple deliverables - Experience working in a results-driven environment - Strategic and critical thinking capabilities - Experience working across cross-functional teams - Interest in cybersecurity, technology, or offensive security operations - Working knowledge of Microsoft Office tools (Word, Excel, PowerPoint, SharePoint) Requirements - This posting is for the Hiring Our Heroes, Corporate Fellowship 2026 - Cohort 3. Candidates must be transitioning service member fellows who will complete the program within the last 180 days of transition from military service. - The fellowship will be 12 weeks long. Primary Work Site/Schedule - On-site work locations: Remote - Monday-Friday (Core hours: 8:30am – 4:00 pm, flexible start and stop)

United States
Full TimeRemoteTeam 1,001-5,000Since 30+ yearsH1B Sponsor

Role Description Responsible for providing direction and planning to implement and maintain information security controls, coordinate the evaluation, deployment and management of current and future security technologies, and communicating operating effectiveness to leadership. - Develop and maintain assigned information security program that implements processes and controls to protect business interests. - Provide direction and planning to implement and maintain information security controls, coordinate the evaluation, deployment and management of current and future security technologies, communicate operating effectiveness to leadership. - Remain current in federal/state laws and regulations, industry standards and best practices. - Responsible for defining and communicating corporate plans, procedures policies and standards for the organization regarding systems, equipment, software and other technologies. - Ensure security requirements are included in the evaluation, selection, implementation and configuration of information technology (hardware, software, applications). - Responsible for administering security including software and tools. - Recommend changes or modify solutions as necessary to implement enhancements, resolve issues, or improve operating efficiency/security posture. - Responsible for the security awareness and training program to meet compliance requirements and reduce risk in assigned areas (i.e. Cyber Security, Identity and Access Management, etc). - Coordinate and manage vendor relationships and accountability on project involvement and deliverables. - Manage IT security threats and vulnerabilities to acceptable risk levels. - Assist in developing remediation plans for newly discovered threats and vulnerabilities. - Manage communication and reporting of new threats and vulnerability and oversee remediation. - Publish metrics regarding the operating effectiveness of information security controls. - Responsible for leading, developing, coaching direct reports; in collaboration with HR, conduct performance reviews, and disciplinary action. - Hire and train new staff, conduct performance reviews, disciplinary actions, and provide leadership and coaching for direct reports including technical and personal development. - Foster relationship management through communication to key stakeholders. - Maintain positive relationships with internal and external customers. - Perform any other job duties as requested. Qualifications - Bachelor of Science/Arts degree or equivalent work experience is required. Master’s or JD is preferred. - Ten (10) years of IT related experience preferably in a medium to large technical operating environment, to include five (5) years of experience in assigned specialty (i.e. Cyber Security, Identity and Access Management, etc). - Five (5) years leadership experience in information security or IT risk management is required. Requirements - Effective oral and written communication skills. - Effective problem solving skills. - Substantial exposure to data processing, hardware platforms, enterprise software applications, and outsourced systems. - Experience with systems design and development from business requirements analysis through to day-to-day management. - Experience in planning, organizing, and developing IT security and facility security system technologies. - Experience in planning and executing security policies and standards development. - Excellent knowledge of technology environments, including information security, building security, and defense solutions. - In-depth knowledge of applicable laws and regulations as they relate to security. - Ability to set and manage priorities judiciously. - Ability to present ideas in business-friendly and user-friendly language. - Exceptionally self-motivated and directed. - Superior analytical, evaluative, and problem-solving abilities. - Exceptional service orientation. - Ability to motivate in a team-oriented, collaborative environment. Licensure and Certification - Certifications in Information Security Management, such as CISSP, CRISC, CISA, CISM preferred. Working Conditions - General office environment; may be required to sit or stand for extended periods of time. Compensation Range $135,600.00 - $237,400.00 CareSource takes into consideration a combination of a candidate’s education, training, and experience as well as the position’s scope and complexity, the discretion and latitude required for the role, and other external and internal data when establishing a salary level. In addition to base compensation, you may qualify for a bonus tied to company and individual performance. We are highly invested in every employee’s total well-being and offer a substantial and comprehensive total rewards package. Compensation Type Salary Organization Level Competencies - Fostering a Collaborative Workplace Culture - Cultivate Partnerships - Develop Self and Others - Drive Execution - Influence Others - Pursue Personal Excellence - Understand the Business This job description is not all inclusive. CareSource reserves the right to amend this job description at any time. CareSource is an Equal Opportunity Employer. We are dedicated to fostering an environment of belonging that welcomes and supports individuals of all backgrounds.

United States
$135.6K - $237.4K / year
Full TimeRemoteTeam 10,001+H1B Sponsor

• Provide a direct positive influence on the security posture of the world's most prestigious organizations by leading Unit 42's elite group of cybersecurity professionals in a variety of assessments for our top-tier clientele. • Orchestrate and manage a dynamic schedule for a large team of elite offensive security specialists, ensuring optimal alignment of skill sets to meet client needs and maximize usage of available billable hours. • Serve as a mentor to a team of offensive security personnel, maximizing professional development by providing ad hoc technical guidance and aligning employees with appropriate industry-standard training courses. • Craft policies governing offensive security practices which reflect cutting-edge capabilities of advanced persistent threat actors and enforce security best practices that ensure the safety of our client's environments. • Fulfill a customer-facing case leadership role for multiple concurrent events, guiding a technically diverse team of personnel through the complex challenges posed by some of the world's largest networks. • Ensure high quality engagement outcomes and deliverables by providing quality assurance and technical oversight during engagements. • Provide hands-on support for highly complex offensive security operations, utilizing cutting-edge techniques in technically challenging environments. • Provide front-line support to the sales team by meeting with clients to clearly articulate various penetration approaches and methodologies to both technical and executive audiences. • Transform customer requirements into executable statements of work, including a work breakdown structure with accurate estimates of billable hours for each discrete phase of testing. • Develop scripts, tools, and methodologies to automate and streamline internal processes and engagements. • Assist in the development of security standards and best practices for the organization and recommend security enhancements as needed. • Assist with the development and maturity of both new and existing Unit 42 offensive security offerings.

California
$236K - $275K / year