{"id":1296663,"url":"https://alion.io/job/xtium-security-engineer-secure-development","title":"Security Engineer - Secure Development","company":{"id":2771594,"name":"XTIUM","domain":"xtium.com","url":"https://alion.io/company/xtium","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":5,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["India","Pakistan"],"countries":["IN","PK"],"hiring_countries":["IN"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":17000,"max_usd":38000,"period":"year","method":"role_seniority_country_cell","sample_n":13},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"C#","optional":false},{"name":"CI/CD","optional":false},{"name":"Go","optional":false},{"name":"ISO 27001","optional":false},{"name":"JavaScript","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true}],"status":"live","first_seen_at":"2026-09-22T00:00:00Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-30T02:33:50Z","board_verified":true,"closed_at":null,"days_open":8,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":8},"description":"The XTIUM global team is made up of a group of diverse and talented professionals who are all driven by the same goal: excellence and continuous improvement. We are all about embracing challenges, keeping the lines of communication open and working together. We take ownership of our work, focus on learning and growing and hold ourselves accountable to our colleagues and customers. Together, we strive to push boundaries, make an impact and inspire each other to reach our full potential.\nJob Description:\nAbout the Role\nThe Security Engineer, Secure Development is responsible for establishing, leading, and enforcing security standards for all internally developed software, automation, and AI-enabled solutions prior to customer delivery or internal production use. This role serves as the primary technical lead and designated expert to ensure that applications, APIs, infrastructure-as-code, and AI models meet security, privacy, and compliance requirements before release. This is an individual contributor role within the security organization, focused on hands-on execution, technical depth, and influence through standards, tooling, and partnership with development teams.\nAs a Managed Services Provider with proprietary platforms and customer-facing systems, XTIUM requires strong governance over secure development practices. This role works closely with engineering, platform, infrastructure, and compliance teams to embed security into the software development lifecycle while maintaining delivery velocity.\nWhat You Will Do\nApplication & Code Security Governance\nOwn and enforce secure development standards for all internally built applications, platforms, automation, and tooling.\nPerform and oversee manual and automated code reviews (static, dynamic, dependency, and supply-chain analysis).\nEstablish clear release gates requiring security approval before software or AI systems are delivered to customers or promoted internally.\nDefine remediation standards and risk acceptance criteria for security findings.\nConduct secure design reviews and application threat modeling during early development phases to identify and mitigate risk before implementation.\nAI & Emerging Technology Security\nReview internally developed AI models, agents, prompts, integrations, and data pipelines for security, privacy, and misuse risk.\nEnsure AI systems comply with internal governance, customer contractual obligations, and emerging regulatory expectations.\nPartner with engineering and data teams to implement secure AI development patterns, including data protection, access controls, and auditability.\nDevSecOps Enablement\nIntegrate security tooling into CI/CD pipelines (e.g., SAST, DAST, dependency scanning, container scanning, secrets detection).\nPromote “shift -left ” security practices and reduce late-stage security blockers through developer enablement.\nCollaborate with DevOps and Platform teams on secure delivery pipelines and runtime controls.\nRisk, Compliance & IP Protection\nProtect XTIUM’s intellectual property by ensuring secure design, code custody, and controlled access to source repositories.\nSupport compliance efforts across frameworks such as SOC 2, ISO 27001, and customer-specific security requirements.\nProduce audit-ready artifacts including risk assessments, code review records, and security sign-offs.\nLeadership & Collaboration\nAct as the primary application security escalation point for engineering and leadership.\nMentor developers and engineers on secure coding practices and threat modeling.\nProvide executive-level reporting on application and AI security posture, trends, and risk exposure.\nWhat Qualifies You\nRequired Qualifications:\n8+ years of experience in application security, DevSecOps, or secure software development.\nStrong hands-on experience reviewing code in one or more modern languages (e.g., Python, JavaScript/TypeScript, C#, Java, Go).\nProven experience securing APIs, web applications, microservices, and cloud-native platforms.\nExperience integrating security controls into CI/CD pipelines and modern DevOps workflows.\nDeep understanding of common vulnerabilities and attack patterns (OWASP Top 10, API security risks, supply chain threats).\nAbility to balance security rigor with delivery velocity in a customer-facing MSP environment.\nPreferred Qualifications:\nExperience securing AI/ML systems, automation platforms, or data-driven applications.\nFamiliarity with cloud platforms (Azure, AWS) and containerized environments.\nExperience in a Managed Services Provider (MSP) or SaaS organization with external customer delivery obligations.\nKnowledge of regulatory and compliance frameworks impacting software and data security.\nKey Competencies\nSecure Software Architecture\nApplication & API Security\nAI Security & Governance\nDevSecOps Tooling & Automation","description_format":"text","description_chars":4825,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Cybersecurity","Information Technology"],"lifecycle":[{"event":"open","at":"2026-09-26T09:32:10Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":7,"expected_fill_days":42,"reasons":["conf:9","velocity","win:early"],"computed_at":"2026-09-29T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/xtium-security-engineer-secure-development","json_url":"https://alion.io/job/xtium-security-engineer-secure-development.json","meta":{"generated_at":"2026-09-30T03:32:20Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2503,"day_limit":5000,"remaining_today":2497,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}