{"id":1321719,"url":"https://alion.io/job/cbiz-senior-product-security-engineer","title":"Senior Product Security Engineer","company":{"id":1781854,"name":"CBIZ","domain":"cbiz.com","url":"https://alion.io/company/cbiz-com","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":80,"open_postings":92,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":15,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Independence, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":121000,"max_usd":238000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":775},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"CWE","optional":false},{"name":"EU AI Act","optional":false},{"name":"Function Calling","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"NIST AI RMF","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"RAG","optional":false},{"name":"SBOM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"STRIDE","optional":false},{"name":"Threat Modeling","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"Azure DevOps","optional":true},{"name":"Burp Suite","optional":true},{"name":"C#","optional":true},{"name":"Checkmarx","optional":true},{"name":"CI/CD","optional":true},{"name":"CodeQL","optional":true},{"name":"CVSS","optional":true},{"name":"GitHub Actions","optional":true},{"name":"GitLab CI","optional":true},{"name":"Go","optional":true},{"name":"GraphQL","optional":true},{"name":"IAM","optional":true},{"name":"JavaScript","optional":true},{"name":"Jenkins","optional":true},{"name":"Kubernetes","optional":true},{"name":"MITRE ATT&CK","optional":true},{"name":"OWASP ZAP","optional":true},{"name":"Platform Engineering","optional":true},{"name":"Python","optional":true},{"name":"Rest API","optional":true},{"name":"Semgrep","optional":true},{"name":"Snyk","optional":true},{"name":"SonarQube","optional":true},{"name":"TypeScript","optional":true},{"name":"Veracode","optional":true}],"status":"live","first_seen_at":"2026-07-27T20:52:21Z","employer_posted_date":"2026-07-27","last_verified_at":"2026-09-30T12:48:25Z","board_verified":true,"closed_at":null,"days_open":65,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":65},"description":"#LI-CR2 #LI-Hybrid\n The Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Product Security function at CBIZ. As the first dedicated hire in this domain, this position serves as the single point of accountability for product security across the enterprise - defining strategy, building the program from the ground up, and operating as a trusted architect and advisor to development, engineering, platform, and AI teams.\nOperating within a matrix organization, the role champions a security-first mindset across business groups, embeds secure-by-design principles into the Software Development Lifecycle (SDLC), and leads the transformation to a mature Secure SDLC with a DevSecOps focus. The engineer acts as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain integrity.\nThis role requires an experienced builder with a strong coding background, demonstrated AI security expertise, and the ability to influence without direct authority - operating as a credible technical peer to senior developers and AI engineers alike.\nEssential Functions and Primary Duties\nProduct Security Strategy & Architecture\nDefine and own the enterprise Product Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.\n\nServe as the Product Security Architect for major initiatives, providing authoritative guidance on authentication, authorization, session management, encryption, key management, secrets handling, and API security.\n\nEstablish secure-by-design standards, control libraries, and engineering guardrails that scale across product lines and business units.\n\nSecure SDLC & DevSecOps Enablement\nLead the transition from traditional SDLC to a mature Secure SDLC with embedded DevSecOps controls, integrating security gates into every phase including design, code, build, test, deploy, and operate.\n\nArchitect and operationalize security automation including SAST, DAST, SCA, container image scanning, and secrets detection.\n\nDefine vulnerability remediation of SLAs and drive measurable reduction in mean-time-to-remediate.\n\nBuild developer-friendly tooling, paved-road patterns, and self-service guardrails that enable engineering velocity without compromising security.\n\nAI Security & AI Engineering Partnership\nAct as the dedicated security partner to CBIZ's AI engineering team, reviewing AI/ML configurations, agent designs, model integrations, and deployment patterns to ensure they meet enterprise security and privacy standards.\n\nEstablish AI security best practices and guardrails for generative AI, agentic workflows, RAG pipelines, and LLM-powered applications, aligned to the OWASP Top 10 for LLM Applications including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, and model theft.\n\nReview and harden AI model configurations, system prompts, tool and function calling permissions, content filters, rate limits, and identity boundaries for agents operating against enterprise data.\n\nEstablish controls for AI-generated code review to ensure AI-assisted development does not bypass secure SDLC checkpoints.\n\nDefine data protection and access controls for AI workloads including grounding data governance, vector database security, and PII handling prompts and responses.\n\nPartner with AI engineers on model risk management, red-teaming, and adversarial testing.\n\nStay current with the evolving AI regulatory landscape (NIST AI RMF, EU AI Act, ISO/IEC 42001) and translate requirements into engineering controls.\n\nThreat Modeling & Secure Design Reviews\nFacilitate threat modeling sessions using STRIDE, PASTA, and MITRE ATLAS for AI/ML systems producing actionable mitigations and ranked risk registers.\n\nConduct architecture and design reviews to identify weaknesses before code is written, partnering with solution architects and engineering leads.\n\nCode Review & Vulnerability Management\nPerform manual and tool-assisted secure code reviews against OWASP Top 10, CWE Top 25, and SANS 25, providing remediation guidance with corrected code where appropriate.\n\nTriage scanner findings and own application vulnerability management workflows, SLA tracking, and executive reporting on AppSec posture.\n\nSoftware Supply Chain Security\nDefine and enforce controls for third-party and open-source components, dependency hygiene, SBOM generation, and signed artifacts, including AI model provenance and dataset integrity.\n\nHarden source repositories, build systems, and deployment environments against supply chain compromise.\n\nMatrix Leadership & Security Mindset Advocacy\nNavigate CBIZ's matrix organization to influence development, engineering, AI, platform, and product teams.\n\nAct as the visible, accessible point of contact for application security, embedding into engineering rituals such as design reviews, architecture councils, and sprint planning.\n\nLead developer enablement programs including secure coding training, threat modeling workshops, a security champions network, and lunch-and-learn sessions across business groups.\n\nIncident Response & Executive Reporting\nServe as the AppSec and AI security subject matter expert during incident response, escalations, and post-incident reviews.\n\nProduce board-ready and executive-level reporting on AppSec maturity, AI security posture, key risk indicators, and program outcomes.\n\nPreferred Qualifications\n8+ years of progressive experience in software engineering, application development, or platform engineering, with at least 4 years focused on product security, DevSecOps, or security architecture.\n\nMandatory hands-on coding background with proficiency in one or more modern languages such as Python, Java, C#/.NET, JavaScript/TypeScript, or Go, and the demonstrated ability to read, write, and review production code as a peer to senior developers.\n\nMandatory experience working directly with development, engineering, and AI/ML teams within a matrix environment.\n\nMandatory hands-on AI security experience, including reviewing AI/ML system architectures, securing LLM integrations, evaluating model configurations, and applying frameworks such as OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI Risk Management Framework.\n\nDeep expertise in Secure SDLC, OWASP Top 10, CWE Top 25, MITRE ATT&CK, and CVSS.\n\nHands-on experience with AppSec tooling such as SAST (Semgrep, CodeQL, SonarQube, Checkmarx, Veracode), DAST (Burp Suite, OWASP ZAP), SCA (Snyk, Black Duck), IaC scanning, and secrets detection.\n\nStrong understanding of CI/CD platforms including GitHub Actions, GitLab CI, Azure DevOps, and Jenkins, with experience hardening pipeline security.\n\nCloud security expertise across Microsoft Azure and AWS, including IAM, container security (Kubernetes), workload protection, and CNAPP platforms.\n\nFamiliarity with API security (REST, GraphQL), authentication and authorization standards (OAuth 2.0, OIDC, SAML), and modern cryptography.\n\nDemonstrated ability to influence without authority and navigate a matrix organization across multiple business groups.\n\nMinimum Qualifications\nCollege Degree or equivalent required\n8 years related experience\nExpert technical knowledge\nKnowledge of industry regulations\nAbility to lead and coordinate the team activities of others\nAbility to formulate, document and recommend new policies and procedures\nAble to work in and lead a team\nDemonstrated ability to communicate verbally and in writing throughout all levels of an organization, both internally and externally\nAbility to travel as required by business and on-call availability","description_format":"text","description_chars":7815,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":[],"lifecycle":[{"event":"open","at":"2026-09-26T21:51:57Z"}],"liveness":{"score":9,"band":"cold","label":"Long shot","p_open":1,"p_active":0.315,"p_room":0.28,"age_days":64,"expected_fill_days":15,"reasons":["conf:2","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/cbiz-senior-product-security-engineer","json_url":"https://alion.io/job/cbiz-senior-product-security-engineer.json","meta":{"generated_at":"2026-10-01T05:01:49Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4675,"day_limit":5000,"remaining_today":325,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}