1

Director Devsecops Jobs in Ohio (NOW HIRING)

Senior Product Security Engineer

Cleveland, OH · On-site

$112K - $154K/yr

... direct authority - operating as a credible technical peer to senior developers and AI engineers ... Secure SDLC & DevSecOps Enablement * Lead the transition from traditional SDLC to a mature Secure ...

Senior Application Security Engineer

Independence, OH · Hybrid

$111K - $153K/yr

... direct authority - operating as a credible technical peer to senior developers and AI engineers ... Secure SDLC & DevSecOps Enablement * Lead the transition from traditional SDLC to a mature Secure ...

Senior Application Security Engineer

Cleveland, OH · On-site

$57.50 - $77/hr

... direct authority - operating as a credible technical peer to senior developers and AI engineers ... Secure SDLC & DevSecOps Enablement * Lead the transition from traditional SDLC to a mature Secure ...

DevOps Engineer, Lead

Beavercreek, OH · On-site

$77.50 - $176/hr

... have a direct impact in the defense industry? As a DevSecOps Engineer, you'll lead end-to-end platform design-from build systems to deployment frameworks-for software operating inside ATO'd ...

New

Senior Cybersecurity Engineer

Columbus, OH · On-site

$110K - $151K/yr

Support application security and DevSecOps practices across the development and deployment ... Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future ...

Senior Cybersecurity Engineer

Columbus, OH · On-site

$107K - $146K/yr

Support application security and DevSecOps practices across the development and deployment ... Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future ...

Avionics Engineer

Dayton, OH · On-site

$150K - $180K/yr

Mentor junior and mid-level engineers on open-architecture avionics and secure DevSecOps practices ... Direct Reports: No * New Position: Yes

Senior Cybersecurity Engineer

Columbus, OH

$110K - $151K/yr

Support application security and DevSecOps practices across the development and deployment ... Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future ...

Support application security and DevSecOps practices across the development and deployment ... Direct experience with Cloudflare, CrowdStrike, Halcyon, Google SecOps, NodeZero, Recorded Future ...

Workflow Architect

Cincinnati, OH · On-site

$68 - $87.50/hr

Director, Product Development & Delivery (KPI Solutions). Location: On-shore (US-based ... Platform architects, Product Owners, DevSecOps, and project delivery leads. Key Responsibilities ...

Lead Devops Engineer

Cincinnati, OH · On-site

$98K - $129K/yr

Direct Hire Compensation: $150,000 Range (based on experience) We're seeking an experienced Lead ... Support DevSecOps initiatives, including secure practices, backup strategy, and disaster recovery ...

Lead Devops Engineer

Sharonville, OH · On-site

$94K - $124K/yr

Direct Hire Compensation: $150,000 Range (based on experience) We're seeking an experienced Lead ... Support DevSecOps initiatives, including secure practices, backup strategy, and disaster recovery ...

Mentors and supports the Junior AWS Engineer; conducts code reviews and champions DevSecOps culture ... Direct experience supporting at least one FedRAMP Moderate (or higher) authorized system, including ...

Sr. Site Reliability Engineer

Cincinnati, OH · On-site

$54.75 - $72.75/hr

Direct Hire Compensation: $140,000 Range (based on experience) We're seeking an experienced Senior ... Support DevSecOps initiatives, including secure practices, backup strategy, and disaster recovery ...

Showing results 21-40

Director Devsecops information

What does a director of DevSecOps do?

A Director of DevSecOps leads and oversees the integration of security practices into the DevOps process within an organization. They are responsible for developing strategies, managing teams, and implementing tools to ensure applications and infrastructure are secure throughout the software development lifecycle. This role collaborates with development, operations, and security teams to automate security controls, monitor threats, and ensure compliance with industry standards. Ultimately, the Director of DevSecOps works to minimize risks while enabling efficient and secure software delivery.

What is the difference between Director Devsecops vs Security Manager?

AspectDirector DevsecopsSecurity Manager
Primary FocusIntegrating security into development and operations processesManaging overall security policies and team oversight
ResponsibilitiesAutomating security, CI/CD pipelines, DevSecOps practicesSecurity policy enforcement, incident response, risk management
Required SkillsDevOps, security tools, scripting, cloud platformsSecurity frameworks, leadership, compliance, risk assessment
Work EnvironmentCollaborative with development and operations teamsSecurity teams, executive management, compliance departments

The main difference is that the Director Devsecops focuses on embedding security into development and operational workflows, while the Security Manager oversees overall security policies and team management. Both roles require security expertise, but the Director Devsecops emphasizes automation and integration within tech processes, whereas the Security Manager concentrates on policy, compliance, and strategic security planning.

How does a director of DevSecOps typically collaborate with development and security teams to foster a culture of shared responsibility?

A Director of DevSecOps works closely with both development and security teams to integrate security practices seamlessly into the software development lifecycle. They facilitate regular cross-team meetings, establish clear communication channels, and advocate for security as a shared responsibility rather than a separate function. By implementing automated security tools and continuous feedback loops, they help teams proactively identify and address vulnerabilities, ensuring that security is considered at every stage of development. This collaborative approach not only enhances product security but also fosters a culture of trust and accountability across the organization.

What are the key skills and qualifications needed to thrive as a director of DevSecOps?

To thrive as a Director of DevSecOps, you need deep expertise in cybersecurity, software development, and IT infrastructure, often supported by a degree in computer science or related field and significant leadership experience. Familiarity with CI/CD pipelines, cloud platforms (e.g., AWS, Azure), containerization tools (e.g., Docker, Kubernetes), and certifications like CISSP or CISM are typically required. Strong leadership, strategic thinking, and excellent communication skills help drive cross-functional collaboration and promote a security-first mindset. These skills and qualities are crucial for effectively integrating security into development processes, managing risk, and ensuring organizational resilience.

What are the most commonly searched types of Devsecops jobs in Ohio?

The most popular types of Devsecops jobs in Ohio are:

What are popular job titles related to Director Devsecops jobs in Ohio?

For Director Devsecops jobs in Ohio, the most frequently searched job titles are:

What cities in Ohio are hiring for Director Devsecops jobs?

Cities in Ohio with the most Director Devsecops job openings:

Senior Product Security Engineer

CBIZ, Inc.

Cleveland, OH • On-site

$112K - $154K/yr

Full-time

Posted 20 days ago


CBIZ rating

8.0

Company rating: 8.0 out of 10

Based on 57 frontline employees who took The Breakroom Quiz

12th of 22 rated bookkeepers and accountants


Job description


#LI-CR2 #LI-Hybrid
Responsibilities
The Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Product Security function at CBIZ. As the first dedicated hire in this domain, this position serves as the single point of accountability for product security across the enterprise - defining strategy, building the program from the ground up, and operating as a trusted architect and advisor to development, engineering, platform, and AI teams.
Operating within a matrix organization, the role champions a security-first mindset across business groups, embeds secure-by-design principles into the Software Development Lifecycle (SDLC), and leads the transformation to a mature Secure SDLC with a DevSecOps focus. The engineer acts as a guiding authority on secure coding, threat modeling, application architecture, AI/LLM security, and software supply chain integrity.
This role requires an experienced builder with a strong coding background, demonstrated AI security expertise, and the ability to influence without direct authority - operating as a credible technical peer to senior developers and AI engineers alike.
Essential Functions and Primary Duties
Product Security Strategy & Architecture
  • Define and own the enterprise Product Security strategy, roadmap, reference architectures, and secure design patterns for web, mobile, API, microservices, serverless, and AI-enabled applications.
  • Serve as the Product Security Architect for major initiatives, providing authoritative guidance on authentication, authorization, session management, encryption, key management, secrets handling, and API security.
  • Establish secure-by-design standards, control libraries, and engineering guardrails that scale across product lines and business units.

Secure SDLC & DevSecOps Enablement
  • Lead the transition from traditional SDLC to a mature Secure SDLC with embedded DevSecOps controls, integrating security gates into every phase including design, code, build, test, deploy, and operate.
  • Architect and operationalize security automation including SAST, DAST, SCA, container image scanning, and secrets detection.
  • Define vulnerability remediation of SLAs and drive measurable reduction in mean-time-to-remediate.
  • Build developer-friendly tooling, paved-road patterns, and self-service guardrails that enable engineering velocity without compromising security.

AI Security & AI Engineering Partnership
  • Act as the dedicated security partner to CBIZ's AI engineering team, reviewing AI/ML configurations, agent designs, model integrations, and deployment patterns to ensure they meet enterprise security and privacy standards.
  • Establish AI security best practices and guardrails for generative AI, agentic workflows, RAG pipelines, and LLM-powered applications, aligned to the OWASP Top 10 for LLM Applications including prompt injection, insecure output handling, training data poisoning, supply chain vulnerabilities, sensitive information disclosure, excessive agency, and model theft.
  • Review and harden AI model configurations, system prompts, tool and function calling permissions, content filters, rate limits, and identity boundaries for agents operating against enterprise data.
  • Establish controls for AI-generated code review to ensure AI-assisted development does not bypass secure SDLC checkpoints.
  • Define data protection and access controls for AI workloads including grounding data governance, vector database security, and PII handling prompts and responses.
  • Partner with AI engineers on model risk management, red-teaming, and adversarial testing.
  • Stay current with the evolving AI regulatory landscape (NIST AI RMF, EU AI Act, ISO/IEC 42001) and translate requirements into engineering controls.

Threat Modeling & Secure Design Reviews
  • Facilitate threat modeling sessions using STRIDE, PASTA, and MITRE ATLAS for AI/ML systems producing actionable mitigations and ranked risk registers.
  • Conduct architecture and design reviews to identify weaknesses before code is written, partnering with solution architects and engineering leads.

Code Review & Vulnerability Management
  • Perform manual and tool-assisted secure code reviews against OWASP Top 10, CWE Top 25, and SANS 25, providing remediation guidance with corrected code where appropriate.
  • Triage scanner findings and own application vulnerability management workflows, SLA tracking, and executive reporting on AppSec posture.

Software Supply Chain Security
  • Define and enforce controls for third-party and open-source components, dependency hygiene, SBOM generation, and signed artifacts, including AI model provenance and dataset integrity.
  • Harden source repositories, build systems, and deployment environments against supply chain compromise.

Matrix Leadership & Security Mindset Advocacy
  • Navigate CBIZ's matrix organization to influence development, engineering, AI, platform, and product teams.
  • Act as the visible, accessible point of contact for application security, embedding into engineering rituals such as design reviews, architecture councils, and sprint planning.
  • Lead developer enablement programs including secure coding training, threat modeling workshops, a security champions network, and lunch-and-learn sessions across business groups.

Incident Response & Executive Reporting
  • Serve as the AppSec and AI security subject matter expert during incident response, escalations, and post-incident reviews.
  • Produce board-ready and executive-level reporting on AppSec maturity, AI security posture, key risk indicators, and program outcomes.

Preferred Qualifications
  • 8+ years of progressive experience in software engineering, application development, or platform engineering, with at least 4 years focused on product security, DevSecOps, or security architecture.
  • Mandatory hands-on coding background with proficiency in one or more modern languages such as Python, Java, C#/.NET, JavaScript/TypeScript, or Go, and the demonstrated ability to read, write, and review production code as a peer to senior developers.
  • Mandatory experience working directly with development, engineering, and AI/ML teams within a matrix environment.
  • Mandatory hands-on AI security experience, including reviewing AI/ML system architectures, securing LLM integrations, evaluating model configurations, and applying frameworks such as OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Deep expertise in Secure SDLC, OWASP Top 10, CWE Top 25, MITRE ATT&CK, and CVSS.
  • Hands-on experience with AppSec tooling such as SAST (Semgrep, CodeQL, SonarQube, Checkmarx, Veracode), DAST (Burp Suite, OWASP ZAP), SCA (Snyk, Black Duck), IaC scanning, and secrets detection.
  • Strong understanding of CI/CD platforms including GitHub Actions, GitLab CI, Azure DevOps, and Jenkins, with experience hardening pipeline security.
  • Cloud security expertise across Microsoft Azure and AWS, including IAM, container security (Kubernetes), workload protection, and CNAPP platforms.
  • Familiarity with API security (REST, GraphQL), authentication and authorization standards (OAuth 2.0, OIDC, SAML), and modern cryptography.
  • Demonstrated ability to influence without authority and navigate a matrix organization across multiple business groups.

Qualifications
Minimum Qualifications
  • College Degree or equivalent required
  • 8 years related experience
  • Expert technical knowledge
  • Knowledge of industry regulations
  • Ability to lead and coordinate the team activities of others
  • Ability to formulate, document and recommend new policies and procedures
  • Able to work in and lead a team
  • Demonstrated ability to communicate verbally and in writing throughout all levels of an organization, both internally and externally
  • Ability to travel as required by business and on-call availability

About Us
CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.
CBIZ strives to be our team members' employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers.
Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.

What CBIZ employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


CBIZ logo

About CBIZ

Sourced by ZipRecruiter

With over 100 offices and nearly 6,000 associates in major metropolitan areas and suburban cities throughout the U.S. CBIZ (NYSE: CBZ) delivers top-level financial and employee business services to organizations of all sizes, as well as individual clients, by providing national-caliber expertise combined with highly personalized service delivered at the local level.

Industry

Business management consulting

Company size

5,001 - 10,000 Employees

Headquarters location

Cleveland, OH, US

Year founded

1987