Luxury presence

Staff Security Engineer - US (Remote)

United States Full Time
Luxury Presence is the leading digital platform revolutionizing the real estate industry for agents, teams, and brokerages. Our award-winning websites, cutting-edge marketing solutions, and AI-powered mobile platform empower real estate professionals to grow their business, operate more efficiently, and deliver exceptional service to their clients. Trusted by over 80,000 real estate professionals, including 31 of the nation’s 100 top-performing agents as published in the Wall Street Journal, Luxury Presence continues to set the standard for innovation and excellence in real estate technology.

We’re seeking our first Staff Security Engineer to lead the charge in securing our product platform — spanning web, mobile, and AI-driven services. This role is ideal for someone who combines deep technical expertise with a proactive, automation-first mindset. You’ll ensure our systems, data, and AI agents are protected by best-in-class practices and tooling, while fostering a culture of security awareness across the company.

You’ll partner closely with engineering, infrastructure, DevOps, and product teams to design, implement, and maintain automated security mechanisms that scale — from continuous monitoring and vulnerability management to defending against new classes of threats emerging in the AI era (such as prompt injection and data exfiltration via LLMs).

Responsibilities

Security Foundations & Automation

Design and implement automated systems to monitor, detect, and mitigate security risks across infrastructure, application, and AI layers.
Lead efforts to integrate continuous security testing into CI/CD pipelines (SAST, DAST, dependency scanning, container scanning, etc.).
Build and maintain automated alerting and remediation workflows for security events.
Architect and implement robust authentication and authorization frameworks for end users, ensuring secure, scalable access control across web, mobile, and API surfaces (e.g., OAuth 2.0, SSO, role-based and attribute-based access models).

Application & Cloud Security

Harden cloud environments (AWS, GCP) and enforce least-privilege IAM, network segmentation, and encryption standards.
Conduct architecture reviews, threat modeling, and code audits to ensure secure design across all services.
Collaborate with engineering teams to define secure coding standards and best practices.

AI & LLM Security

Develop security frameworks and tooling to detect and prevent LLM-specific vulnerabilities (e.g., prompt injection, data leakage, malicious model responses).
Implement guardrails for AI systems, including content filtering, input validation, and output sanitization.
Partner with our AI engineering team to design safe orchestration between models, APIs, and user data.

Incident Response & Compliance

Own and continuously improve our incident detection, response, and recovery processes.
Collaborate on internal audits and compliance efforts.
Serve as a key advisor on emerging threats, vulnerabilities, and evolving best practices.


Qualifications