Description
Recognized as the No. 1 site trusted by real estate professionals, Realtor.com® has been at the forefront of online real estate for over 25 years, connecting buyers, sellers, and renters with trusted insights and expert guidance to find their perfect home. Through its robust suite of tools, Realtor.com® not only makes a significant impact on the real estate industry at large, but for consumers, navigating the biggest purchase they will make in their life, by providing a user experience that is easy to use, easy to understand, and most of all, easy to make decisions.
Join us on our mission to empower more people to find their way home by breaking barriers to entry, making the right connections, and building confidence through expert guidance.
Realtor.com is growing how it uses AI, from internal tools and coding assistants to fleets of autonomous agents. We need a security engineer whose core skill is cybersecurity and whose focus is AI. Recent incidents, like an AI model under test breaking into another company's infrastructure, show the new kinds of risk: agents acting outside their intended scope, models and tools pulled from public hubs, and normal automation becoming an attack path. You'll make sure our systems are built to contain all of that, and that the secure option is also the easy one. You'll work closely with News Corp's global cybersecurity team, bringing AI security depth to Realtor.com while aligning with group-wide standards.
We are looking for a rigorous practitioner who advocates for software engineering excellence across the full Product Development Life Cycle (PDLC). You will leverage AI through spec-driven design, automation-driven provisioning, and robust platform maintenance, eliminating ad hoc ownership and freeing solution builders to focus on workflow design and delivery.
What You'll Do:
Secure the AI platform (AWS and GCP)
- Design and enforce guardrails for AI workloads on AWS (Bedrock, Lambda, IAM, KMS, SCPs, GuardDuty, Security Hub) and GCP (Vertex AI, IAM, VPC Service Controls, Org Policies, Security Command Center, Cloud KMS).
- Define how agents and other non-human accounts are identified and authorized: short-lived, narrowly scoped credentials, delegated user permissions, and a per-agent audit trail, so a misbehaving agent can only do limited damage.
- Build containment for agents: separate read and write permissions, network egress controls, sandboxed execution, approval gates for high-risk actions, and kill switches.
- Design an agent gateway or control plane that keeps agents and their tool calls within approved limits.
- Secure the AI supply chain: where models come from and how they're scanned (including unsafe formats like pickle), vetting of models and datasets from public hubs such as Hugging Face, an approval process for new MCP servers and agent tools, and an inventory of the models, data, and tools each system uses (an AI-BOM).
- Defend against prompt injection, tool poisoning, poisoned retrieval data (RAG poisoning), and sensitive data leakage.
- Put detection and logging in place for agent and model activity, and own the incident response playbooks for AI-specific events.
Review and guide what gets built
- Lead threat modeling for new products, features, and internal solutions, from consumer-facing experiences to internal tools and agent workflows. Use frameworks like STRIDE, the OWASP LLM/GenAI Top 10, MITRE ATLAS, and OWASP ASVS. Turn the findings into clear design requirements and release criteria.
- Review pull requests, architecture designs, and release-readiness for everything from apps to agent fleets, and make concrete suggestions that move work forward instead of blocking it.
Build paved-road frameworks, reference architectures, and secure-by-default templates that rule out whole categories of risk, instead of catching them one PR at a time. - Build security into CI/CD: secrets scanning, SAST/SCA, GitHub Actions hardening, and policy-as-code in Terraform.
- Build an ongoing red-team and evaluation program for our models, agents, and LLM apps, and test new AI features before launch.
Partner with News Corp cybersecurity
- Work with News Corp's global cybersecurity team to align Realtor.com's AI and cloud security with group-wide standards, policies, and risk frameworks.
- Coordinate on incident response, threat intelligence, and vulnerability disclosure across News Corp businesses.
- Share AI security patterns, threat models, and lessons learned with other News Corp businesses, and bring their insights back to Realtor.com.
Use AI to do security work
- Build agents that help do the security work: triage findings, investigate alerts, audit IAM for least privilege, and open tested, secure-by-default fix PRs.
- Use Claude Code, Devin, and MCP to make the security team faster, and share those patterns with other engineering teams.
Stay ahead of the field
- Track new AI threats, incidents, research, and vendor capabilities as they emerge, and turn them into concrete actions for our platform. That includes new attack techniques, model and agent releases, and changes to OWASP, MITRE ATLAS, and other frameworks.
- When a major industry incident happens, quickly assess whether we're exposed and lead the response.
- Prototype new approaches when existing tools and best practices don't fit yet. Run small experiments, measure the results, and turn what works into platform standards.
- Share what you learn: write short internal briefings on major developments and recommend when to adopt, pilot, or skip a new tool or practice.
Educate and lead
- Create and run AI security training for engineers, product teams, and the wider company: prompt injection, data leakage, excessive agency, and secure use of tools like Claude, Glean, Devin, and Gemini.
- Act as the security voice in AI platform strategy: evaluate vendors and models, set the bar for what's production-ready, and help shape AI governance across the whole AI lifecycle.
- Brief leadership on AI risk and where to invest.
- Represent Realtor.com externally through conference talks, open-source work, or industry working groups.
What You'll Bring:
- 5+ years in cybersecurity, cloud security, AppSec/product security, or security platform engineering.
- Hands-on depth in AWS security, plus real experience in GCP (or a strong multi-cloud background).
- You know that telling an AI not to do something isn't security. You think in permissions, scopes, logs, approval gates, data boundaries, and rollback.
- Experience securing LLM or agentic systems, including prompt injection defenses, retrieval and data-boundary risks, agent identity, and model or tool supply-chain integrity.
- Experience doing threat modeling for products and platforms, not just infrastructure. You can lead a session with engineers and product managers and turn it into requirements they'll actually follow.
- Hands-on experience building with agents, tool calling, or MCP, and with AI coding tools.
Strong code-review skills in at least one of Python, TypeScript, or Go, and comfort with Terraform/IaC. - Experience with zero trust, least privilege, SSO/OIDC/OAuth, secrets management, and vulnerability management.
- Experience working within a larger security organization, such as a parent company, central security team, or federated model. You can balance local speed with alignment to enterprise standards.
- Follow AI security research, incident write-ups, and the security community, and you can point to something recent you learned and acted on.
- A builder's mindset. You'd rather prototype a new control than wait for a vendor to ship one, and you're comfortable working where the playbook doesn't exist yet.
- Explain risk clearly to any audience, from a PR comment to an executive briefing to a training session for the whole company.
Nice to have:
- AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, CISSP, OSCP, or GIAC (GCSA/GWEB).
- Experience red-teaming or evaluating AI models or agents.
- Familiarity with NIST AI RMF, ISO 42001, Google SAIF, CoSAI, NIST SSDF, or the EU AI Act.
- Experience securing Snowflake (RBAC, masking, network policy).
- Conference talks, published research, or open-source security contributions.
How We Work:
We balance creativity and innovation on a foundation of in-person collaboration. For most roles, our employees work four or more days in our offices, where they have the opportunity to collaborate in-person, adding richness to our culture and knitting us closer together.
How We Reward You:
Realtor.com is committed to investing in the health and wellbeing of our employees and their families. Our benefits programs include, but are not limited to:
- Inclusive and Competitive medical, Rx, dental, and vision coverage
- Family forming benefits
- 13 Paid Holidays
- Flexible Time Off
- 8 hours of paid Volunteer Time off
- Immediate eligibility into Company 401(k) plan with 3.5% company match
- Tuition Reimbursement program for degreed and non-degreed programs
- 1:1 personalized Financial Planning Sessions
- Student Debt Retirement Savings Match program
- Free snacks and refreshments in each office location
Do the best work of your life at Realtor.com®
Here, you’ll partner with a diverse team of experts as you use leading-edge tech to empower everyone to meet a crucial goal: finding their way home. And you’ll find your way home too. At Realtor.com®, you’ll bring your full self to work as you innovate with speed, serve our consumers, and champion your teammates. In return, we’ll provide you with a warm, welcoming, and inclusive culture; intellectual challenges; and the development opportunities you need to grow.
Diversity is important to us, therefore, Realtor.com® is an Equal Opportunity Employer regardless of age, color, national origin, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, marital status, status as a disabled veteran and/or veteran of the Vietnam Era or any other characteristic protected by federal, state or local law. In addition, Realtor.com® will provide reasonable accommodations for otherwise qualified disabled individuals.
Skills Required
- 5+ years of experience in cybersecurity, cloud security, AppSec, product security, or security platform engineering
- Hands-on AWS security experience
- Real experience with GCP or a strong multi-cloud background
- Experience securing LLM or agentic systems, including prompt injection defenses, retrieval and data-boundary risks, agent identity, and model or tool supply-chain integrity
- Experience threat modeling products and platforms
- Hands-on experience with agents, tool calling, or MCP, and AI coding tools
- Strong code-review skills in Python, TypeScript, or Go
- Comfort with Terraform and infrastructure as code
- Experience with zero trust, least privilege, SSO, OIDC, OAuth, secrets management, and vulnerability management
- Experience working within a larger or federated security organization
- Ability to communicate risk through code reviews, executive briefings, and training
- AWS Security Specialty, Google Professional Cloud Security Engineer, CCSP, CISSP, OSCP, or GIAC certification
- Experience red-teaming or evaluating AI models or agents
- Familiarity with NIST AI RMF, ISO 42001, Google SAIF, CoSAI, NIST SSDF, or the EU AI Act
- Experience securing Snowflake
- Conference talks, published research, or open-source security contributions
Realtor.com Compensation & Benefits Highlights
-
Healthcare Strength — Healthcare is described as comprehensive, including medical, dental, and vision coverage alongside mental-health resources, telemedicine, reproductive care, and gender-affirming and fertility/family-building benefits. This breadth is consistently positioned as a core strength of the package.
-
Parental & Family Support — Policies include up to 20 weeks of paid parental leave for primary caregivers, plus backup child and adult care, lactation support, adoption assistance, and family-support tools. These offerings are presented as a standout element of the total rewards.
-
Leave & Time Off Breadth — Paid time off is portrayed as generous or flexible, with paid holidays and sick leave noted across materials. This flexibility is highlighted as contributing to better work-life balance.
Realtor.com Insights
What We Do
For years, millions of home shoppers have turned to realtor.com® to find their dream home. Operated by Move, Inc., realtor.com® offers a comprehensive list of for-sale properties, as well as the information and tools to make informed real estate decisions. Today, more than ever, realtor.com® is The Home of Home Search℠. Realtor.com® also offers homeowners a bevy of useful tools and resources through the My Home℠ dashboard. My Home℠ dashboard allows property owners to manage their home like the important investment it is by tracking their home’s value over time, researching and managing home improvements, and scouting other similar properties in the neighborhood.
Why Work With Us
The way home begins with you. With a diverse team of experts alongside you, you’ll help us reach new heights at the forefront of the digital real estate space. Bring your extensive knowledge and deep expertise and collaborate with other passionate visionaries to lead our industry and revolutionize the way people find home, in every form.
Gallery
Realtor.com Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Enjoy the flexibility of our hybrid policy—simply choose whichever three days a week work best for you to come into any of our offices.


