Application Security Architect Job at Oceaneering International, Houston, TX

bE1QZkxhaEJ2RjJsVWtPNUEyb2Jtdnpxdnc9PQ==
  • Oceaneering International
  • Houston, TX

Job Description

The Application Security Architect is responsible for building and operationalizing Oceaneering’s enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries. Equal Opportunity Employer: All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor. Our regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high‑quality support that ensures our operations run efficiently and safely. Having these teams based locally allows us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.REQUIREDMinimum 8 years in cybersecurity, with strong focus on Application Security / DevSecOpsMinimum 8 years’ experience building enterprise AppSec programs and CI/CD security controlsMinimum 5 years’ experience with: SAST, DAST, SCA toolsGitHub / CI/CD pipelines / artifact repositoriesSecure SDLC frameworksExperience implementing Zero Trust principles in development environmentsStrong understanding of: Software supply chain risksSecure coding practicesCloud and hybrid development architecturesDESIREDExperience in OT/ICS or embedded software environmentsBackground working with software engineering or development teamsFamiliarity with: NIST, OWASP SAMM, BSIMMSecure SDLC governance frameworksExperience operating in a global, multi-business unit organization FunctionsDefine and govern application security requirements, controls, and assurance activities embedded within that model Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standardsPartner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement DevSecOps practices, and enforce secure development standards aligned to Zero Trust principlesApplication Security Program LeadershipEstablish and lead an enterprise Application Security (AppSec) governance framework, including Secure SDLC and vulnerability management policiesDrive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teamsBuild a risk-based AppSec roadmap aligned to business criticality, “crown jewel” applications, and regulatory requirementsServe as the central authority for secure software supply chain controls and application risk posture.Developer Security & Environment StrategyDesign and implement a secure developer program addressing: Developer workstations vs business PCsRemoval of excessive local admin privilegesElimination of unmanaged builds and compilersLead transformation to secure developer environments, including: Virtualized or hybrid development modelsCentralized build infrastructureControlled developer access aligned with Zero TrustReduce risk associated with: Local code storageUnvetted open-source dependenciesDeveloper endpoint compromiseDevSecOps & CI/CD Pipeline SecurityArchitect and implement a secure CI/CD pipeline with embedded controls: SAST, SCA, DAST integrationSecrets scanningArtifact integrity and provenance validationPipeline enforcement (GitHub CI Artifact Repository Test Environments)Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified. Partner with SCOE to standardize DevSecOps tooling and pipeline templates enterprise-wideApplication Security Testing & ValidationEstablish enterprise-wide application testing program, including: Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)Manual and automated penetration testing for critical applicationsExpand testing beyond web applications into embedded, ICS, and custom software platforms.Build structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking. Ensure security validation is embedded in CI/CD gates before production deployment.Threat Modeling & Secure ArchitectureLead implementation of threat modeling capabilities for critical applications to identify design flaws early in SDLC. Define and enforce secure-by-design principles across engineering teams.Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns. Security Defect Management & Risk VisibilityImplement centralized tooling to: Aggregate SAST, SCA, DAST, and pen test findingsProvide a single pane of glass for application riskDrive prioritization and remediation of vulnerabilities based on business risk and technical severity. Establish KPIs such as: Mean time to remediate (MTTR)% of critical vulnerabilities fixed before releaseCoverage of testing across applicationsDeveloper Enablement & TrainingBuild and lead a role-based application security training program for developers, architects, and QAProvide: Secure coding guidance (language-specific)Secure development playbooks and reference architecturesPartner with SCOE to embed security practices into daily developer workflows and pipelines. Integration with Software Center of Excellence (SCOE)Expand the SCOE charter to include DevSecOps governance and enforcement.Drive: Adoption of enterprise CI/CD standardsSecure pipeline templatesStandardized DevSecOps toolchainImprove visibility and enforcement of security policies across all development teams. Full timePosting Date: 2026-07-31

Job Tags

Work at office, Local area

Similar Jobs

MacARTHUR Place

Spa Massage Therapist Job at MacARTHUR Place

 ...Job Description Job Description Description: Job Summary: The Hotel Spa Massage Therapist is responsible for delivering professional, high-quality massage and body treatments to guests in a luxury spa setting. This role involves evaluating guests' needs, designing... 

ADDISON KENWAY & ASSOCIATES LLC

Nurse Midwife Job at ADDISON KENWAY & ASSOCIATES LLC

 ...Nurse Midwife - Dover, New Jersey A women's health outpatient clinic located in northern New Jersey provides comprehensive, evidence-based prenatal and gynecologic care focused on accessible services for diverse community populations. The Nurse Midwife will deliver... 

Addison Group

Part-Time Bookkeeper Job at Addison Group

 ...Accounting Specialist who thrives in a fast-paced environment and enjoys managing accounting activities across multiple business entities. This...  ...accurate financial records, assist with reporting, and support cash management efforts. This position requires someone who can... 

Black Briar

Steward/Dishwasher Job at Black Briar

 ...City of Chicago and State of Illinois health and sanitation standards at all times What Were Looking For Prior stewarding or dishwashing experience in a restaurant environment preferred we will train the right person Ability to work efficiently in a fast-paced,... 

Afs Limited

Host an International High School Exchange Student Job at Afs Limited

 ...Open Your Heart & Home with AFS-USA Welcome the world into your home by hosting a high school exchange student with AFS-USA ! Families of all kinds are needed to host students from over 80 countries for a semester or school year. AFS students are 15-18 years...