Get the latest updates on AI-powered hiring, career growth, and technical deep-dives delivered to your inbox.
CBIZ
We are seeking a deeply technical, hands-on Senior Application Security Engineer to establish and lead our Application Security function at CBIZ. As the first dedicated hire in this domain, you will serve as the single point of accountability for application security across the enterprise—defining strategy, building the program from the ground up, and operating as a trusted architect and advisor to development, engineering, platform, and AI teams.
This is a hybrid role, integrating you into our matrix organization.
A college degree or equivalent is required, along with 8 years of related experience and expert technical knowledge. You must bring knowledge of industry regulations, the ability to lead and coordinate team activities, and the skill to formulate, document, and recommend new policies and procedures.
You should be comfortable working in and leading a team, and demonstrably capable of communicating verbally and in writing throughout all levels of an organization, both internally and externally. Travel as required by business and on-call availability is expected.
Operating within a matrix organization, you will champion a security-first mindset across business groups, embed secure-by-design principles into the Software Development Lifecycle (SDLC), and lead the transformation to a mature Secure SDLC with a DevSecOps focus. You will act as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain integrity.
This role requires an experienced builder with a strong coding background, demonstrated AI security expertise, and the ability to influence without direct authority—operating as a credible technical peer to senior developers and AI engineers alike.
Define and own the enterprise Application Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications. Serve as the Application Security Architect for major initiatives, providing authoritative guidance on authentication, authorization, session management, encryption, key management, secrets handling, and API security.
Establish secure-by-design standards, control libraries, and engineering guardrails that scale across product lines and business units.
Lead the transition from traditional SDLC to a mature Secure SDLC with embedded DevSecOps controls, integrating security gates into every phase including design, code, build, test, deploy, and operate. Architect and operationalize security automation including SAST, DAST, SCA, container image scanning, and secrets detection.
Define vulnerability remediation SLAs and drive measurable reduction in mean-time-to-remediate. Build developer-friendly tooling, paved-road patterns, and self-service guardrails that enable engineering velocity without compromising security.
Act as the dedicated security partner to CBIZ's AI engineering team, reviewing AI/ML configurations, agent designs, model integrations, and deployment patterns to ensure they meet enterprise security and privacy standards.
Establish AI security best practices and guardrails for generative AI, agentic workflows, RAG pipelines, and LLM-powered applications, aligned to the OWASP Top 10 for LLM Applications including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, and model theft.
Review and harden AI model configurations, system prompts, tool and function calling permissions, content filters, rate limits, and identity boundaries for agents operating against enterprise data. Establish controls for AI-generated code review to ensure AI-assisted development does not bypass secure SDLC checkpoints.
Define data protection and access controls for AI workloads including grounding data governance, vector database security, and PII handling in prompts and responses. Partner with AI engineers on model risk management, red-teaming, and adversarial testing. Stay current with the evolving AI regulatory landscape (NIST AI RMF, EU AI Act, ISO/IEC 42001) and translate requirements into engineering controls.
Facilitate threat modeling sessions using STRIDE, PASTA, and MITRE ATLAS for AI/ML systems, producing actionable mitigations and ranked risk registers. Conduct architecture and design reviews to identify weaknesses before code is written, partnering with solution architects and engineering leads.
Perform manual and tool-assisted secure code reviews against OWASP Top 10, CWE Top 25, and SANS 25, providing remediation guidance with corrected code where appropriate. Triage scanner findings and own application vulnerability management workflows, SLA tracking, and executive reporting on application security posture.
Define and enforce controls for third-party and open-source components, dependency hygiene, SBOM generation, and signed artifacts, including AI model provenance and dataset integrity. Harden source repositories, build systems, and deployment environments against supply chain compromise.
Navigate CBIZ's matrix organization to influence development, engineering, AI, platform, and product teams. Act as the visible, accessible point of contact for application security, embedding into engineering rituals such as design reviews, architecture councils, and sprint planning.
Lead developer enablement programs including secure coding training, threat modeling workshops, a security champions network, and lunch-and-learn sessions across business groups.
Serve as the application security and AI security subject matter expert during incident response, escalations, and post-incident reviews. Produce board-ready and executive-level reporting on application security maturity, AI security posture, key risk indicators, and program outcomes.
We are looking for 8+ years of progressive experience in software engineering, application development, or platform engineering, with at least 4 years focused on application security, DevSecOps, or security architecture.
A mandatory hands-on coding background is required, with proficiency in one or more modern languages such as Python, Java, C#/.NET, JavaScript/TypeScript, or Go, and the demonstrated ability to read, write, and review production code as a peer to senior developers.
You must have mandatory experience working directly with development, engineering, and AI/ML teams within a matrix environment, and mandatory hands-on AI security experience, including reviewing AI/ML system architectures, securing LLM integrations, evaluating model configurations, and applying frameworks such as OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI Risk Management Framework.
Deep expertise in Secure SDLC, OWASP Top 10, CWE Top 25, MITRE ATT&CK, and CVSS is expected. Hands-on experience with application security tooling such as SAST (Semgrep, CodeQL, SonarQube, Checkmarx, Veracode), DAST (Burp Suite, OWASP ZAP), SCA (Snyk, Black Duck), IaC scanning, and secrets detection is needed.
A strong understanding of CI/CD platforms including GitHub Actions, GitLab CI, Azure DevOps, and Jenkins, with experience hardening pipeline security, is important. Cloud security expertise across Microsoft Azure and AWS, including IAM, container security (Kubernetes), workload protection, and CNAPP platforms, is required.
Familiarity with API security (REST, GraphQL), authentication and authorization standards (OAuth 2.0, OIDC, SAML), and modern cryptography rounds out the technical profile. Finally, you must demonstrate the ability to influence without authority and navigate a matrix organization across multiple business groups.
CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.
We strive to be our team members' employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout
Most resumes get rejected by the ATS before a human sees them. Check yours free in 30 seconds.
Matched to your profile
We surface this role because it matches profiles like yours, not because we vet the employer. Always confirm the pay, location, and remote details on CBIZ's official site before you apply.
Most large employers screen resumes with software before a recruiter ever sees them. Check yours against this role in seconds. Free, no sign-up.
See the exact keywords from this posting your resume is missing, with an instant ATS score.
Open free toolUpload your CV for an instant 0-100 score and the fixes recruiters and ATS look for.
Open free toolGenerate a clean, single-column resume that parses correctly and gets past the filters.
Open free toolOther live openings in the same field. All are still accepting applications.
OpenAI
New York, NY
Figma
New York, NY
Arca
New York, United States
Medal
New York, NY
MUFG
Jersey City, NJ
Hampton North
New York, NY