Application Security Architect
Oceaneering International, Inc.
Houston, TX, United States
8 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Software System Penetration Testing
Application Testing
Microsoft Azure
Software Bug Management
Cloud Computing Security
Compilers
Cyber Security
Continuous Integration
Custom Software
Linux
Github
+24 more
Information Systems Security Architecture Professional
Python (Programming Language)
Open Source Technology
Windows PowerShell
Systems Development Life Cycle
Zero Trust Network Access
Secure Coding
Security Information and Event Management
Software Deployment
Syslog
Software Vulnerability Management
Web Applications
Data Logging
Enterprise Software Applications
Data Ingestion
Software Security
Mttr
Information Technology
Process Control Systems
Operational Systems
Splunk
Devsecops
Static Application Security Testing
Dynamic Application Security Testing
Job description
- Define and govern application security requirements, controls, and assurance activities embedded within that model
- Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards
- Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement DevSecOps practices, and enforce secure development standards aligned to Zero Trust principles
Application Security Program Leadership
- Establish and lead an enterprise Application Security (AppSec) governance framework, including Secure SDLC and vulnerability management policies
- Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams
- Build a risk-based AppSec roadmap aligned to business criticality, âcrown jewelâ applications, and regulatory requirements Serve as the central authority for secure software supply chain controls and application risk posture.
Developer Security & Environment Strategy
- Design and implement a secure developer program addressing:
- Developer workstations vs business PCs
- Removal of excessive local admin privileges
- Elimination of unmanaged builds and compilers
- Lead transformation to secure developer environments, including:
- Virtualized or hybrid development models
- Centralized build infrastructure
- Controlled developer access aligned with Zero Trust
- Reduce risk associated with:
- Local code storage
- Unvetted open-source dependencies
- Developer endpoint compromise
DevSecOps & CI/CD Pipeline Security
- Architect and implement a secure CI/CD pipeline with embedded controls:
- SAST, SCA, DAST integration
- Secrets scanning
- Artifact integrity and provenance validation
- Pipeline enforcement (GitHub CI Artifact Repository Test Environments)
- Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified.
- Partner with SCOE to standardize DevSecOps tooling and pipeline templates enterprise-wide
Application Security Testing & Validation
- Establish enterprise-wide application testing program, including:
- Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)
- Manual and automated penetration testing for critical applications
- Expand testing beyond web applications into embedded, ICS, and custom software platforms.
- Build structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking.
- Ensure security validation is embedded in CI/CD gates before production deployment .
Threat Modeling & Secure Architecture
- Lead implementation of threat modeling capabilities for critical applications to identify design flaws early in SDLC.
- Define and enforce secure-by-design principles across engineering teams.
- Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns.
Security Defect Management & Risk Visibility
- Implement centralized tooling to:
- Aggregate SAST, SCA, DAST, and pen test findings
- Provide a single pane of glass for application risk
- Drive prioritization and remediation of vulnerabilities based on business risk and technical severity.
- Establish KPIs such as:
- Mean time to remediate (MTTR)
- % of critical vulnerabilities fixed before release
- Coverage of testing across applications
Developer Enablement & Training
- Build and lead a role-based application security training program for developers, architects, and QA
- Provide:
- Secure coding guidance (language-specific)
- Secure development playbooks and reference architectures
- Partner with SCOE to embed security practices into daily developer workflows and pipelines.
Integration with Software Center of Excellence (SCOE)
- Expand the SCOE charter to include DevSecOps governance and enforcement.
- Drive:
- Adoption of enterprise CI/CD standards
- Secure pipeline templates
- Standardized DevSecOps toolchain
- Improve visibility and enforcement of security policies across all development teams.
Requirements
- Bachelorâs degree in Information Technology, Cybersecurity, Computer Science, Engineering, or related field, or equivalent experience.
- Minimum 3 years of experience supporting security monitoring, SIEM, or security engineering platforms.
- Minimum 1 yearsâ experience administering Splunk Enterprise.
- Minimum 1 yearsâ experience supporting Cribl or similar log management technologies.
- Minimum 1 yearsâ experience with Syslog architecture and log ingestion technologies.
- Minimum 1 yearsâ experience supporting Managed Detection and Response (MDR) services or Security Operations Centers.
- Minimum 1 yearsâ experience working with Windows, Linux, network, and cloud log sources.
- Familiarity with Operational Technology (OT) and Industrial Control System (ICS) environments.
DESIRED
- Splunk Certified Administrator or Splunk Certified Architect certification.
- Experience with industrial networking and OT/ICS environments.
- Experience integrating enterprise logging platforms with MDR providers.
- Knowledge of NIST Cybersecurity Framework, IEC 62443, or ISA/IEC industrial security standards.
- Experience with scripting and automation using PowerShell, Python, or similar tools.
- Familiarity with Microsoft Azure and cloud security monitoring.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
Top-Paying Tech Jobs (with Salaries)
over 2 years ago