×
Register Here to Apply for Jobs or Post Jobs. X

Hybrid AppSec Architect — Lead Secure SDLC & DevSecOps

Job in Houston, Harris County, Texas, 77246, USA
Listing for: Oceaneering
Full Time position
Listed on 2026-09-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 190000 USD Yearly USD 140000.00 190000.00 YEAR
Job Description & How to Apply Below



Job Description

The Application Security Architect is responsible for building and operationalizing Oceaneering’s enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.

  • Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.


Job Description

The Application Security Architect is responsible for building and operationalizing Oceaneering’s enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.
  • Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.
Functions

RESPONSIBILITIES

  • Define and govern application security requirements, controls, and assurance activities embedded within that model
  • Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards
  • Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement Dev Sec Ops  practices, and enforce secure development standards aligned to Zero Trust principles
Application Security Program Leadership

  • Establish and lead an enterprise Application Security (App Sec) governance framework, including Secure SDLC and vulnerability management policies
  • Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams
  • Build a risk-based App Sec roadmap aligned to business criticality, “crown jewel” applications, and regulatory requirements
  • Serve as the central authority for secure software supply chain controls and application risk posture.
Developer Security & Environment Strategy

  • Design and implement a secure developer program addressing:
  • Developer workstations vs business PCs
  • Removal of excessive local admin privileges
  • Elimination of unmanaged builds and compilers
  • Lead transformation to secure developer environments, including:
  • Virtualized or hybrid development models
  • Centralized build infrastructure
  • Controlled developer access aligned with Zero Trust
  • Reduce risk associated with:
  • Local code storage
  • Unvetted open-source dependencies
  • Developer endpoint compromise
Dev Sec Ops  & CI/CD Pipeline Security

  • Architect and implement a secure CI/CD pipeline with embedded controls:
  • SAST, SCA, DAST integration
  • Secrets scanning
  • Artifact integrity and provenance validation
  • Pipeline enforcement (Git Hub → CI → Artifact Repository → Test Environments)
  • Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified.
  • Partner with SCOE to standardize Dev Sec Ops  tooling and pipeline templates enterprise-wide
Application Security Testing & Validation

  • Establish enterprise-wide application testing program, including:
  • Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)
  • Manual and automated penetration testing for critical applications
  • Expand testing beyond web applications into embedded, ICS, and custom software platforms.
  • Build structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking.
  • Ensure security validation is embedded in CI/CD gates before production deployment .
Threat Modeling & Secure Architecture

  • Lead implementation of threat modeling capabilities for critical applications to identify design flaws early in SDLC.
  • Define and enforce secure-by-design principles across engineering teams.
  • Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns.
Security Defect Management & Risk Visibility

  • Implement centralized tooling to:
    • Aggregate SAST, SCA, DAST, and pen test findings
    • Provide a single pane of glass for application risk
    • Drive prioritization and remediation of vulnerabilities based on business risk and technical severity.
  • Establish KPIs such as:
    • Mean time to remediate (MTTR)
    • % of critical vulnerabilities fixed before release
    • Coverage of testing across applications
Developer Enablement &…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary