Application Security Architect
Listed on 2026-08-04
-
IT/Tech
Cybersecurity
Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.
Equal Opportunity
Employer:
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.
Our regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high‑quality support that ensures our operations run efficiently and safely. Having these teams based locally allow us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.
Job DescriptionThe Application Security Architect is responsible for building and operationalizing Oceaneering’s enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.
- Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
Functions
Define and govern application security requirements, controls, and assurance activities embedded within that model
Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards
Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement Dev Sec Ops practices, and enforce secure development standards aligned to Zero Trust principles
Application Security Program Leadership
Establish and lead an enterprise Application Security (App Sec) governance framework, including Secure SDLC and vulnerability management policies
Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams
Build a risk-based App Sec roadmap aligned to business criticality, “crown jewel” applications, and regulatory requirements
- Serve as the central authority for secure software supply chain controls and application risk posture.
Developer Security & Environment Strategy
Design and implement a secure developer program addressing:
Developer workstations vs business PCs
Removal of excessive local admin privileges
Elimination of unmanaged builds and compilers
Lead transformation to secure developer environments, including:
Virtualized or hybrid development models
Centralized build infrastructure
Controlled developer access aligned with Zero Trust
Reduce risk associated with:
Local code storage
Unvetted open‑source dependencies
Architect and implement a secure CI/CD pipeline with embedded controls:
SAST, SCA, DAST integration
Secrets scanning
Artifact integrity and provenance validation
Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified.
Partner with SCOE to standardize Dev Sec Ops tooling and pipeline templates enterprise-wide
Application Security Testing & Validation
Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)
Manual and automated penetration testing for critical applications
Expand testing beyond web applications into embedded, ICT, and custom software platforms.
Build structured pen testing program for crown jewel applications, including third‑party partnerships and remediation tracking.
Ensure security validation is…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).