> Markdown version of [/jobs/ext/2257073-senior-cybersecurity-architect-application-security](https://www.wearedevelopers.com/jobs/ext/2257073-senior-cybersecurity-architect-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Architect - Application Security - **Company:** American Bureau of Shipping - **Location:** Houston, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Computing Platforms, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, DevOps, Digital Assets, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Key Management, Network Security, Open Source Technology, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Delivery Pipeline, Software Security, Togaf, Information Technology, CIS Benchmarks, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 26, 2026 - **Apply:** https://www.disabledperson.com/jobs/74545460-senior-cybersecurity-architect-application-security ## About the Role The role has a strong focus on application security and secure software development, including code security, software development security practices, and DevSecOps integration across the software development lifecycle (SDLC). The ideal candidate will bring deep technical expertise, business acumen, and a collaborative approach to partner with IT, business leaders, architects, engineers, and development teams in building a resilient and future-ready security posture., * 8+ years of progressive experience in cybersecurity, with at least 3 years in an architecture or senior security engineering role, including meaningful experience in application security, secure software development, or DevSecOps. * Minimum: Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related field, or equivalent experience. * Preferred: Master's degree in Cybersecurity, Information Technology, Software Engineering, or related discipline. * Experience in regulated industries such as maritime, energy, or financial services. * Familiarity with Zero Trust architecture, advanced threat detection, software supply chain security, and emerging technologies including AI/ML in security and OT/ICS security. * Demonstrated leadership in cross-functional teams and global, multicultural environments. * Strong communication skills with the ability to influence technical and non-technical stakeholders. * Experience collaborating directly with software developers, platform engineers, and product teams to improve security maturity across application development and delivery processes. Knowledge, Skills, and Abilities * Strong knowledge of security frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, OWASP, and secure software development practices. * Proven track record in designing and implementing enterprise security architectures across cloud, on-premise, hybrid, and application environments. * Deep expertise in application security, including secure architecture, threat modeling, secure coding principles, API security, and vulnerability management. * Hands-on experience with code security tools and practices, including SAST, DAST, SCA, container security scanning, secrets management, and code review processes. * Strong knowledge of software development, security and integrating security requirements into Agile, DevOps, and CI/CD workflows. * Demonstrated experience implementing and scaling DevSecOps practices in enterprise environments. * Working knowledge of cloud security, IAM, encryption, endpoint protection, network security, and modern development platforms. * Professional certifications such as CISSP, CSSLP, SABSA, TOGAF, CCSP, or other relevant cybersecurity/security architecture certifications are preferred. * Working knowledge of the ABS Health, Safety, Quality, and Environmental Management System.m. ## Description The Cybersecurity Architect is a senior member of the ABS IT Cyber Security Team responsible for designing, implementing, and evolving enterprise-wide security architectures that safeguard ABS's digital assets, data, systems, and applications. This role serves as a strategic advisor and technical leader, ensuring that security solutions are aligned with ABS's business objectives, regulatory requirements, and risk management practices., Code Security Oversight: Provide guidance on code security practices, including static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), secrets detection, and remediation of vulnerabilities in source code and open-source dependencies. Strategic Alignment: Partner with IT and business leaders to embed security into technology roadmaps, digital transformation initiatives, and software product delivery. * Risk Management: Identify, assess, and mitigate cybersecurity risks associated with applications, APIs, cloud platforms, development pipelines, and business processes. * Governance & Compliance: Ensure alignment with regulatory frameworks, industry standards, secure development requirements, and ABS security policies. Technology Leadership: Evaluate, recommend, and implement emerging security technologies and practices related to application security, cloud security, and software assurance. * Collaboration & Influence: Provide guidance to engineering, operations, platform, and development teams to integrate security into solution design, development, deployment, and ongoing support. * Incident Preparedness: Contribute to security incident response planning and support investigations involving application-layer threats, software vulnerabilities, and code-related security issues. * Thought Leadership: Serve as a subject matter expert, mentor team members, and represent ABS in internal and external cybersecurity forums as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)