Senior Application Security Engineer

CBIZ

Cleveland (OH)

On-site

USD 140,000 - 210,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CBIZ seeks a Senior Application Security Engineer to establish and lead the AppSec program as the enterprise’s first dedicated hire in this domain.

You will define strategy, design secure architectures, and partner with development, platform, and AI teams to embed secure-by-design principles throughout the SDLC and DevSecOps lifecycle.

Qualifications

  • 8+ years in software engineering, application development, or platform engineering with at least 4 years in app security

Responsibilities

  • Define and own enterprise Application Security strategy, roadmap, and reference architectures
  • Lead Secure SDLC transformation with embedded DevSecOps controls across design, code, build, test, deploy, and operate
  • Architect and operationalize security automation: SAST, DAST, SCA, image scanning, and secrets detection
  • Partner with CBIZ AI engineering teams to ensure AI/ML security and governance
  • Facilitate threat modeling sessions (STRIDE, PASTA, MITRE ATLAS) for AI/ML systems
  • Perform secure code reviews and manage vulnerability workflows with executive reporting
  • Define and enforce software supply chain controls, SBOMs, and component hygiene
  • Influence across a matrix organization and drive secure coding training and security champions programs
  • Contribute to incident response and executive-level AppSec posture reporting

Skills

Coding in Python
Java
C#/.NET
JavaScript/TypeScript
Go
AppSec tooling

Education

College Degree or equivalent required

Tools

SAST
DAST
SCA
IaC scanning
Secrets detection
Semgrep
CodeQL
SonarQube
Burp Suite
OWASP ZAP

Job description

The Senior Application Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Application Security function at CBIZ. As the first dedicated hire in this domain, this position serves as the single point of accountability for application security across the enterprise - defining strategy, building the program from the ground up, and operating as a trusted architect and advisor to development, engineering, platform, and AI teams. Operating within a matrix organization, the role champions a security-first mindset across business groups, embeds secure-by-design principles into the Software Development Lifecycle (SDLC), and leads the transformation to a mature Secure SDLC with a DevSecOps focus. The engineer acts as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain integrity. This role requires an experienced builder with a strong coding background, demonstrated AI security expertise, and the ability to influence without direct authority - operating as a credible technical peer to senior developers and AI engineers alike.

Essential Functions and Primary Duties
  • Application Security Strategy & ArchitectureDefine and own the enterprise Application Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.Serve as the Application Security Architect for major initiatives, providing authoritative guidance on authentication, authorization, session management, encryption, key management, secrets handling, and API security.
  • Secure SDLC & DevSecOps EnablementLead the transition from traditional SDLC to a mature Secure SDLC with embedded DevSecOps controls, integrating security gates into every phase including design, code, build, test, deploy, and operate.Architect and operationalize security automation including SAST, DAST, SCA, container image scanning, and secrets detection.Define vulnerability remediation of SLAs and drive measurable reduction in mean-time-to-remediate.Build developer-friendly tooling, paved-road patterns, and self-service guardrails that enable engineering velocity without compromising security.
  • AI Security & AI Engineering PartnershipAct as the dedicated security partner to CBIZ's AI engineering team, reviewing AI/ML configurations, agent designs, model integrations, and deployment patterns to ensure they meet enterprise security and privacy standards.Establish AI security best practices and guardrails for generative AI, agentic workflows, RAG pipelines, and LLM-powered applications, aligned to the OWASP Top 10 for LLM Applications including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, and model theft.Review and harden AI model configurations, system prompts, tool and function calling permissions, content filters, rate limits, and identity boundaries for agents operating against enterprise data.Establish controls for AI-generated code review to ensure AI-assisted development does not bypass secure SDLC checkpoints.Define data protection and access controls for AI workloads including grounding data governance, vector database security, and PII handling prompts and responses.Partner with AI engineers on model risk management, red-teaming, and adversarial testing.Stay current with the evolving AI regulatory landscape (NIST AI RMF, EU AI Act, ISO/IEC 42001) and translate requirements into engineering controls.
  • Threat Modeling & Secure Design ReviewsFacilitate threat modeling sessions using STRIDE, PASTA, and MITRE ATLAS for AI/ML systems producing actionable mitigations and ranked risk registers.Conduct architecture and design reviews to identify weaknesses before code is written, partnering with solution architects and engineering leads.
  • Code Review & Vulnerability ManagementPerform manual and tool-assisted secure code reviews against OWASP Top 10, CWE Top 25, and SANS 25, providing remediation guidance with corrected code where appropriate.Triage scanner findings and own application vulnerability management workflows, SLA tracking, and executive reporting on AppSec posture.
  • Software Supply Chain SecurityDefine and enforce controls for third-party and open-source components, dependency hygiene, SBOM generation, and signed artifacts, including AI model provenance and dataset integrity.Harden source repositories, build systems, and deployment environments against supply chain compromise.
  • Matrix Leadership & Security Mindset AdvocacyNavigate CBIZ's matrix organization to influence development, engineering, AI, platform, and product teams.Act as the visible, accessible point of contact for application security, embedding into engineering rituals such as design reviews, architecture councils, and sprint planning.Lead developer enablement programs including secure coding training, threat modeling workshops, a security champions network, and lunch-and-learn sessions across business groups.
  • Incident Response & Executive ReportingServe as the AppSec and AI security subject matter expert during incident response, escalations, and post-incident reviews.Produce board-ready and executive-level reporting on AppSec maturity, AI security posture, key risk indicators, and program outcomes.
Preferred Qualifications
  • 8+ years of progressive experience in software engineering, application development, or platform engineering, with at least 4 years focused on application security, DevSecOps, or security architecture.
  • Mandatory hands-on coding background with proficiency in one or more modern languages such as Python, Java, C#/.NET, JavaScript/TypeScript, or Go, and the demonstrated ability to read, write, and review production code as a peer to senior developers.
  • Mandatory experience working directly with development, engineering, and AI/ML teams within a matrix environment.
  • Mandatory hands-on AI security experience, including reviewing AI/ML system architectures, securing LLM integrations, evaluating model configurations, and applying frameworks such as OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Deep expertise in Secure SDLC, OWASP Top 10, CWE Top 25, MITRE ATT&CK, and CVSS.
  • Hands-on experience with AppSec tooling such as SAST (Semgrep, CodeQL, SonarQube, Checkmarx, Veracode), DAST (Burp Suite, OWASP ZAP), SCA (Snyk, Black Duck), IaC scanning, and secrets detection.
  • Strong understanding of CI/CD platforms including GitHub Actions, GitLab CI, Azure DevOps, and Jenkins, with experience hardening pipeline security.
  • Cloud security expertise across Microsoft Azure and AWS, including IAM, container security (Kubernetes), workload protection, and CNAPP platforms.
  • Familiarity with API security (REST, GraphQL), authentication and authorization standards (OAuth 2.0, OIDC, SAML), and modern cryptography.
  • Demonstrated ability to influence without authority and navigate a matrix organization across multiple business groups.

#LI-CR2 #LI-Hybrid

Minimum Qualifications

College Degree or equivalent required8 years related experienceExpert technical knowledgeKnowledge of industry regulationsAbility to lead and coordinate the team activities of othersAbility to formulate, document and recommend new policies and proceduresAble to work in and lead a teamDemonstrated ability to communicate verbally and in writing throughout all levels of an organization, both internally and externallyAbility to travel as required by business and on-call availability

ABOUT US

CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast. CBIZ strives to be our team members' employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers. Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

CBIZ • Cleveland (OH)

Hybrid
USD 150,000 - 185,000
Senior Product Security Engineer
Senior Product Security Engineer

CBIZ • Independence Township (OH)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

CBIZ • Independence Township (OH)

On-site
USD 110,000 - 170,000
AI Solution Architect
AI Solution Architect

CBIZ • Washington

Remote
USD 140,000 - 170,000
Principal, Delivery Lead | Artificial Intelligence
Principal, Delivery Lead | Artificial Intelligence

CBIZ • United States

On-site
USD 140,000 - 190,000
Cybersecurity Sr Engineer
Cybersecurity Sr Engineer

CBRE • Richardson (TX)

On-site
USD 120,000 - 190,000
Senior Analyst | Business Transformation
Senior Analyst | Business Transformation

CBIZ • Atlanta (GA)

Hybrid
USD 85,000 - 120,000
Technical & Transactional Accounting Senior Manager
Technical & Transactional Accounting Senior Manager

CBIZ Employee Services Organization • Los Angeles (CA)

On-site
USD 175,000 - 250,000
Comprehensive medical and dental insurance
Retirement savings
Education assistance
AI Solution Architect
AI Solution Architect

CBIZ, Inc. • Washington, Northern (KY)

On-site
USD 180,000 - 220,000
Cybersecurity Sr Engineer
Cybersecurity Sr Engineer

CBRE Group, Inc. • Richardson (TX)

On-site
USD 140,000 - 180,000