Application Security Architect

Posted 3 Days Ago
Be an Early Applicant
Houston, TX, USA
In-Office
Senior level
Automotive • Information Technology • Other • Transportation • Energy
The Role
Lead and operationalize an enterprise application security program: define AppSec governance, embed security into SDLC/CI-CD, implement DevSecOps controls (SAST/DAST/SCA, secrets scanning, artifact validation), drive secure developer environments, threat modeling, testing, centralized defect management, and developer training aligned to Zero Trust.
Summary Generated by Built In

The Application Security Architect is responsible for building and operationalizing Oceaneering’s enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.

  • Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
Responsibilities

Functions

  • Define and govern application security requirements, controls, and assurance activities embedded within that model 

  • Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards

  • Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement DevSecOps practices, and enforce secure development standards aligned to Zero Trust principles

 

Application Security Program Leadership

  • Establish and lead an enterprise Application Security (AppSec) governance framework, including Secure SDLC and vulnerability management policies

  • Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams

  • Build a risk-based AppSec roadmap aligned to business criticality, “crown jewel” applications, and regulatory requirements

  • Serve as the central authority for secure software supply chain controls and application risk posture.

 

Developer Security & Environment Strategy

  • Design and implement a secure developer program addressing: 

  • Developer workstations vs business PCs

  • Removal of excessive local admin privileges

  • Elimination of unmanaged builds and compilers

  • Lead transformation to secure developer environments, including: 

  • Virtualized or hybrid development models

  • Centralized build infrastructure

  • Controlled developer access aligned with Zero Trust

  • Reduce risk associated with: 

  • Local code storage

  • Unvetted open-source dependencies

  • Developer endpoint compromise

     

DevSecOps & CI/CD Pipeline Security

  • Architect and implement a secure CI/CD pipeline with embedded controls: 

  • SAST, SCA, DAST integration

  • Secrets scanning

  • Artifact integrity and provenance validation

  • Pipeline enforcement (GitHub → CI → Artifact Repository → Test Environments)

  • Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified. 

  • Partner with SCOE to standardize DevSecOps tooling and pipeline templates enterprise-wide

 

Application Security Testing & Validation

  • Establish enterprise-wide application testing program, including: 

  • Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)

  • Manual and automated penetration testing for critical applications

  • Expand testing beyond web applications into embedded, ICS, and custom software platforms.

  • Build structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking. 

  • Ensure security validation is embedded in CI/CD gates before production deployment.

 

Threat Modeling & Secure Architecture

  • Lead implementation of threat modeling capabilities for critical applications to identify design flaws early in SDLC. 

  • Define and enforce secure-by-design principles across engineering teams.

  • Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns. 

 

Security Defect Management & Risk Visibility

  • Implement centralized tooling to: 

    • Aggregate SAST, SCA, DAST, and pen test findings

    • Provide a single pane of glass for application risk

    • Drive prioritization and remediation of vulnerabilities based on business risk and technical severity. 

  • Establish KPIs such as: 

    • Mean time to remediate (MTTR)

    • % of critical vulnerabilities fixed before release

    • Coverage of testing across applications

 

Developer Enablement & Training

  • Build and lead a role-based application security training program for developers, architects, and QA

  • Provide: 

    • Secure coding guidance (language-specific)

    • Secure development playbooks and reference architectures

  • Partner with SCOE to embed security practices into daily developer workflows and pipelines. 

 

Integration with Software Center of Excellence (SCOE)

  • Expand the SCOE charter to include DevSecOps governance and enforcement.

  • Drive: 

    • Adoption of enterprise CI/CD standards

    • Secure pipeline templates

    • Standardized DevSecOps toolchain

  • Improve visibility and enforcement of security policies across all development teams. 

Qualifications

REQUIRED

  • Minimum 8 years in cybersecurity, with strong focus on Application Security / DevSecOps

  • Minimum 8 years’ experience building enterprise AppSec programs and CI/CD security controls

  • Due to ITAR work requirements, Permanent Resident or US Citizen is required

  • Minimum 5 years’ experience with: 

    • SAST, DAST, SCA tools

    • GitHub / CI/CD pipelines / artifact repositories

    • Secure SDLC frameworks

    • Experience implementing Zero Trust principles in development environments

  • Strong understanding of: 

    • Software supply chain risks

    • Secure coding practices

    • Cloud and hybrid development architectures

 

DESIRED

  • Experience in OT/ICS or embedded software environments

  • Background working with software engineering or development teams

  • Familiarity with: 

    • NIST, OWASP SAMM, BSIMM

    • Secure SDLC governance frameworks

  • Experience operating in a global, multi-business unit organization   
About UsOceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.

Equal Opportunity Employer: 
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.
About the TeamOur regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high‑quality support that ensures our operations run efficiently and safely. Having these teams based locally allows us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.

Skills Required

  • Minimum 8 years in cybersecurity with strong focus on Application Security / DevSecOps
  • Minimum 8 years experience building enterprise AppSec programs and CI/CD security controls
  • Minimum 5 years experience with SAST, DAST, SCA tools
  • Experience with GitHub, CI/CD pipelines, and artifact repositories
  • Experience with Secure SDLC frameworks
  • Experience implementing Zero Trust principles in development environments
  • Strong understanding of software supply chain risks
  • Strong understanding of secure coding practices
  • Strong understanding of cloud and hybrid development architectures
  • Experience in OT/ICS or embedded software environments
  • Background working with software engineering or development teams
  • Familiarity with NIST, OWASP SAMM, BSIMM
  • Experience operating in a global, multi-business unit organization

Oceaneering Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Oceaneering and has not been reviewed or approved by Oceaneering.

  • Healthcare Strength Healthcare offerings are portrayed as comprehensive, including private medical insurance and broad medical, dental, and vision coverage tailored to local markets. In several contexts, coverage is characterized as good to outstanding.
  • Retirement Support Retirement programs include pension/retirement plans and a U.S. 401(k), which are consistently highlighted as part of a competitive package. These elements are described as contributing meaningful value to overall compensation.
  • Leave & Time Off Breadth Leave programs include PTO/vacation, paid holidays, and paid sick leave, with annual leave emphasized globally. Time-off provisions are noted as a steady component of total rewards even when salary opinions differ.

Oceaneering Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
11,000 Employees
Year Founded: 1964

What We Do

Oceaneering pushes the frontiers of deep water, space and motion entertainment environments to execute with new, leading-edge connections to solve tomorrow’s challenges, today. As the trusted subsea connection specialist, our experience combined with the depth and breadth of our portfolio of technologies allows us to engineer solutions for the most complex subsea challenges. From routine to extreme, our integrated products, services, and innovative solutions safely de-risk operational systems, increase reliability, and enable a lower total cost of ownership. We are connecting what’s needed with what’s next as the world’s largest ROV operator and the leading ROV provider to the oil and gas industry with over 300 systems operating worldwide. With our safety-focused and innovative approach, we responsively and decisively react to subsea challenges while providing solutions swiftly and efficiently.

Similar Jobs

Wells Fargo Logo Wells Fargo

Architect

Fintech • Financial Services
Hybrid
Irving, TX, USA
205000 Employees
119K-206K Annually
Hybrid
2 Locations
4900 Employees
In-Office
6 Locations
8926 Employees
153K-256K Annually

AbbVie Logo AbbVie

Architect

Healthtech • Pharmaceutical
In-Office or Remote
Waco, TX, USA
50000 Employees
142K-269K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account