CybersecurityJobs.io
← Back to all jobs

Job Description

Oceaneering, a Houston-based company, seeks an Application Security Architect to shape and govern its enterprise security program. The role sits at the crossroads of development, security, and operations, embedding security into the software development lifecycle, CI/CD pipelines, and the broader developer ecosystem. You will collaborate with the Software Center of Excellence, Engineering leadership, and Cybersecurity leadership to curb software supply chain risk and enforce secure development standards in a hybrid work environment.

Responsibilities

  • Define and govern application security requirements, controls, and assurance activities embedded within the security model.
  • Collaborate with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards.
  • Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement DevSecOps practices, and enforce secure development standards aligned to Zero Trust principles.
  • Establish and lead an enterprise AppSec governance framework, including Secure SDLC and vulnerability management policies.
  • Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams.
  • Build a risk-based AppSec roadmap aligned to business criticality, crown jewel applications, and regulatory requirements.
  • Design and implement a secure developer program addressing:
    • Developer workstations vs business PCs
    • Removal of excessive local admin privileges
    • Elimination of unmanaged builds and compilers
  • Lead transformation to secure developer environments, including:
    • Virtualized or hybrid development models
    • Centralized build infrastructure
    • Controlled developer access aligned with Zero Trust
  • Reduce risk associated with local code storage, unvetted open-source dependencies, and developer endpoint compromise.
  • Architect and implement a secure CI/CD pipeline with embedded controls:
    • SAST, SCA, DAST integration
    • Secrets scanning
    • Artifact integrity and provenance validation
    • Pipeline enforcement (GitHub CI Artifact Repository Test Environments)
  • Ensure no production artifacts bypass secure pipelines and that all builds are traceable and verified.
  • Partner with SCOE to standardize DevSecOps tooling and pipeline templates enterprise-wide.
  • Establish an enterprise-wide application testing program, including:
    • Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)
    • Manual and automated penetration testing for critical applications
    • Expansion of testing beyond web applications into embedded, ICS, and custom software platforms
  • Build a structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking.
  • Ensure security validation is embedded in CI/CD gates before production deployment.
  • Lead the implementation of threat modeling capabilities for critical applications to identify design flaws early in the SDLC.
  • Define and enforce secure-by-design principles across engineering teams.
  • Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns.
  • Implement centralized tooling to:
    • Aggregate SAST, SCA, DAST, and pen test findings
    • Provide a single pane of glass for application risk
    • Drive prioritization and remediation of vulnerabilities based on business risk and technical severity
  • Establish KPIs such as MTTR, percentage of critical vulnerabilities fixed before release, and coverage of testing across applications.
  • Build and lead a role-based application security training program for developers, architects, and QA, offering:
    • Secure coding guidance (language-specific)
    • Secure development playbooks and reference architectures
    • Partnership with SCOE to embed security practices into daily developer workflows and pipelines
  • Expand the SCOE charter to include DevSecOps governance and enforcement.
  • Drive adoption of enterprise CI/CD standards, secure pipeline templates, and a standardized DevSecOps toolchain, improving visibility and enforcement of security policies across all development teams.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
  • Minimum 3 years of experience supporting security monitoring, SIEM, or security engineering platforms.
  • Minimum 1 year of experience administering Splunk Enterprise.
  • Minimum 1 year of experience supporting Cribl or similar log management technologies.
  • Minimum 1 year of experience with Syslog architecture and log ingestion technologies.
  • Minimum 1 year of experience supporting Managed Detection and Response (MDR) services or Security Operations Centers.
  • Minimum 1 year of experience working with Windows, Linux, network, and cloud log sources.
  • Familiarity with Operational Technology (OT) and Industrial Control System (ICS) environments.

Technologies

  • Splunk Enterprise
  • Cribl
  • Syslog
  • PowerShell
  • Python
  • GitHub CI
  • SAST
  • SCA
  • DAST
  • Microsoft Azure

Similar Jobs