823,562open jobs
53,068companies
134,459added this week
Browse all
Salary
≈ $119k – $237k per year (Estimated)
Location
Hybrid (Independence, United States)
Seniority
Senior · 8+ years exp

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Jul 27, 2026.

Overview
Company
Impact
Profile match
CBIZ is a national professional services firm built for the middle market that provides accounting, tax, advisory, benefits, insurance, and technology solutions to businesses and organizations. The company combines local relationships with national resources to deliver services including audit and attest (through its licensed CPA entity), tax planning and compliance, risk and advisory, HR and benefits administration, insurance solutions, investment and transaction advisory, and technology and cybersecurity services. CBIZ focuses on industry-specific guidance and data-driven insights to help clients grow, manage risk, and improve operations.

#LI-CR2 #LI-Hybrid

The Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Application Security function at CBIZ. As the first dedicated hire in this domain, this position serves as the single point of accountability for application security across the enterprise - defining strategy, building the program from the ground up, and operating as a trusted architect and advisor to development, engineering, platform, and AI teams.

Operating within a matrix organization, the role champions a security-first mindset across business groups, embeds secure-by-design principles into the Software Development Lifecycle (SDLC), and leads the transformation to a mature Secure SDLC with a DevSecOps focus. The engineer acts as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain integrity.

This role requires an experienced builder with a strong coding background, demonstrated AI security expertise, and the ability to influence without direct authority - operating as a credible technical peer to senior developers and AI engineers alike.

Essential Functions and Primary Duties

Application Security Strategy & Architecture

  • Define and own the enterprise Application Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.

  • Serve as the Application Security Architect for major initiatives, providing authoritative guidance on authentication, authorization, session management, encryption, key management, secrets handling, and API security.

  • Establish secure-by-design standards, control libraries, and engineering guardrails that scale across product lines and business units.

Secure SDLC & DevSecOps Enablement

  • Lead the transition from traditional SDLC to a mature Secure SDLC with embedded DevSecOps controls, integrating security gates into every phase including design, code, build, test, deploy, and operate.

  • Architect and operationalize security automation including SAST, DAST, SCA, container image scanning, and secrets detection.

  • Define vulnerability remediation of SLAs and drive measurable reduction in mean-time-to-remediate.

  • Build developer-friendly tooling, paved-road patterns, and self-service guardrails that enable engineering velocity without compromising security.

AI Security & AI Engineering Partnership

  • Act as the dedicated security partner to CBIZ's AI engineering team, reviewing AI/ML configurations, agent designs, model integrations, and deployment patterns to ensure they meet enterprise security and privacy standards.

  • Establish AI security best practices and guardrails for generative AI, agentic workflows, RAG pipelines, and LLM-powered applications, aligned to the OWASP Top 10 for LLM Applications including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, and model theft.

  • Review and harden AI model configurations, system prompts, tool and function calling permissions, content filters, rate limits, and identity boundaries for agents operating against enterprise data.

  • Establish controls for AI-generated code review to ensure AI-assisted development does not bypass secure SDLC checkpoints.

  • Define data protection and access controls for AI workloads including grounding data governance, vector database security, and PII handling prompts and responses.

  • Partner with AI engineers on model risk management, red-teaming, and adversarial testing.

  • Stay current with the evolving AI regulatory landscape (NIST AI RMF, EU AI Act, ISO/IEC 42001) and translate requirements into engineering controls.

Threat Modeling & Secure Design Reviews

  • Facilitate threat modeling sessions using STRIDE, PASTA, and MITRE ATLAS for AI/ML systems producing actionable mitigations and ranked risk registers.

  • Conduct architecture and design reviews to identify weaknesses before code is written, partnering with solution architects and engineering leads.

Code Review & Vulnerability Management

  • Perform manual and tool-assisted secure code reviews against OWASP Top 10, CWE Top 25, and SANS 25, providing remediation guidance with corrected code where appropriate.

  • Triage scanner findings and own application vulnerability management workflows, SLA tracking, and executive reporting on AppSec posture.

Software Supply Chain Security

  • Define and enforce controls for third-party and open-source components, dependency hygiene, SBOM generation, and signed artifacts, including AI model provenance and dataset integrity.

  • Harden source repositories, build systems, and deployment environments against supply chain compromise.

Matrix Leadership & Security Mindset Advocacy

  • Navigate CBIZ's matrix organization to influence development, engineering, AI, platform, and product teams.

  • Act as the visible, accessible point of contact for application security, embedding into engineering rituals such as design reviews, architecture councils, and sprint planning.

  • Lead developer enablement programs including secure coding training, threat modeling workshops, a security champions network, and lunch-and-learn sessions across business groups.

Incident Response & Executive Reporting

  • Serve as the AppSec and AI security subject matter expert during incident response, escalations, and post-incident reviews.

  • Produce board-ready and executive-level reporting on AppSec maturity, AI security posture, key risk indicators, and program outcomes.

Preferred Qualifications

  • 8+ years of progressive experience in software engineering, application development, or platform engineering, with at least 4 years focused on application security, DevSecOps, or security architecture.

  • Mandatory hands-on coding background with proficiency in one or more modern languages such as Python, Java, C#/.NET, JavaScript/TypeScript, or Go, and the demonstrated ability to read, write, and review production code as a peer to senior developers.

  • Mandatory experience working directly with development, engineering, and AI/ML teams within a matrix environment.

  • Mandatory hands-on AI security experience, including reviewing AI/ML system architectures, securing LLM integrations, evaluating model configurations, and applying frameworks such as OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI Risk Management Framework.

  • Deep expertise in Secure SDLC, OWASP Top 10, CWE Top 25, MITRE ATT&CK, and CVSS.

  • Hands-on experience with AppSec tooling such as SAST (Semgrep, CodeQL, SonarQube, Checkmarx, Veracode), DAST (Burp Suite, OWASP ZAP), SCA (Snyk, Black Duck), IaC scanning, and secrets detection.

  • Strong understanding of CI/CD platforms including GitHub Actions, GitLab CI, Azure DevOps, and Jenkins, with experience hardening pipeline security.

  • Cloud security expertise across Microsoft Azure and AWS, including IAM, container security (Kubernetes), workload protection, and CNAPP platforms.

  • Familiarity with API security (REST, GraphQL), authentication and authorization standards (OAuth 2.0, OIDC, SAML), and modern cryptography.

  • Demonstrated ability to influence without authority and navigate a matrix organization across multiple business groups.

Minimum Qualifications

  • College Degree or equivalent required
  • 8 years related experience
  • Expert technical knowledge
  • Knowledge of industry regulations
  • Ability to lead and coordinate the team activities of others
  • Ability to formulate, document and recommend new policies and procedures
  • Able to work in and lead a team
  • Demonstrated ability to communicate verbally and in writing throughout all levels of an organization, both internally and externally
  • Ability to travel as required by business and on-call availability
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
823,562 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Independence
≈ $20k – $45k per year (Estimated) • In office • Full-Time • Manila
AI/ML
Copilot
DevOps
Splunk
Azure
Cybersecurity
SIEM
Apply
Penetration Tester 2 days ago
≈ $17k – $45k per year (Estimated) • In office • Full-Time • Manila
AI/ML
Copilot
Red Teaming
DevOps
Windows Server
Windows
Cybersecurity
Metasploit
Nmap
Impacket
BloodHound
Mimikatz
Responder
Active Directory
OWASP
Apply
≈ $81k – $168k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Houston
DevOps
TCP/IP
Cybersecurity
Defense in Depth
SIEM
Apply
≈ $110k – $239k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Chicago
DevOps
GCP
Azure
CI/CD
AWS
IAM
Linux
Windows
Cybersecurity
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
Least Privilege
Microsoft Defender for Cloud
Microsoft Entra ID
Ping Identity
Active Directory
SIEM
DLP
OWASP
Apply
$50k – $59k per year • Remote (Portugal) • Full-Time • Lisbon
Python
DevOps
Splunk
Windows
Cybersecurity
IBM QRadar
SIEM
Apply
≈ $32k – $77k per year (Estimated) • In office • 5+ years exp • Moscow
Python
Databases
PostgreSQL
Redis
OpenSearch
AI/ML
Model Context Protocol
AI Agents
LLM
RAG
DevOps
Docker
Kubernetes
Apply
≈ $127k – $258k per year (Estimated) • In office • 12+ years exp • Houston
Databases
Snowflake
Amazon Redshift
AI/ML
Claude
dbt
LLM
RAG
DevOps
AWS
AWS Lambda
Amazon S3
Analytics
Informatica
Apply
≈ $141k – $303k per year (Estimated) • In office • New York
Python
AI/ML
LangGraph
LangChain
Model Context Protocol
Vertex AI
Prompt Engineering
Function Calling
AWS Bedrock
Gemini
RAG
OpenAI
Anthropic
Multi-Agent Systems
Tool Use
Machine Learning
DevOps
Rest API
Azure
CI/CD
AWS
Analytics
ETL/ELT
Apply
≈ $44k – $110k per year (Estimated) • In office • Ho Chi Minh City
Python
Go
Bash
Databases
ClickHouse
ElasticSearch
Apache Kafka
OpenSearch
AI/ML
llama.cpp
Ray Serve
vLLM
Quantization
AI Agents
SGLang
TensorRT
TensorRT-LLM
LLM
RAG
Ray
KServe
Triton
LLMOps
KV Cache
DevOps
Terraform
GCP
Helm
Loki
OpenTelemetry
Prometheus
Azure
CI/CD
GitOps
ArgoCD
AWS
Kubernetes
Grafana
SLI/SLO/SLA
Linux
Apply
$150k – $165k per year • Remote (United States) • Full-Time • 1+ year exp • Bachelor's Degree • United States
AI/ML
LLM
Apply
Security Engineer 8 days ago
≈ $86k – $176k per year (Estimated) • Hybrid • 3+ years exp • Bachelor's Degree • Independence
Python
PowerShell
Bash
DevOps
Azure
AWS
Linux
Cybersecurity
PKI
SIEM
DLP
Apply
≈ $119k – $237k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
$150k – $165k per year • Remote (United States) • Full-Time • 1+ year exp • Bachelor's Degree • United States
AI/ML
LLM
Apply
≈ $42k – $73k per year (Estimated) • In office • 2+ years exp • High School Diploma • Encino
Apply
Remote (United States) • 1+ year exp • High School Diploma
Apply
Security Engineer 8 days ago
≈ $86k – $176k per year (Estimated) • Hybrid • 3+ years exp • Bachelor's Degree • Independence
Python
PowerShell
Bash
DevOps
Azure
AWS
Linux
Cybersecurity
PKI
SIEM
DLP
Apply
≈ $119k – $237k per year (Estimated) • Hybrid • 8+ years exp • Bachelor's Degree • Independence
Python
Go
JavaScript
TypeScript
C#
AI/ML
Function Calling
LLM
RAG
LLM Guardrails
EU AI Act
NIST AI RMF
Agentic Workflows
Frontend
GraphQL
DevOps
Rest API
Azure DevOps
GitHub Actions
GitLab CI
Azure
CI/CD
Jenkins
AWS
Kubernetes
Platform Engineering
SLI/SLO/SLA
IAM
Cybersecurity
Burp Suite
Snyk
OWASP ZAP
SonarQube
Checkmarx
Semgrep
CodeQL
MITRE ATT&CK
OWASP Top 10
STRIDE
CWE
CVSS
Threat Modeling
SBOM
Veracode
Apply
Facility Coordinator 11 days ago
≈ $42k – $73k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • Independence
Apply
$210k – $271k per year • Hybrid • Full-Time • 1+ year exp • Independence
Apply
In office • High School Diploma • Independence
Apply
See all jobs
This is one of many
823,562 more open roles from verified company boards, updated every day.