Company Profile
Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, entertainment, material handling, aerospace, science, and renewable energy industries.
Position Summary
The Security SDLC Manager is responsible for leading the integration of security practices into the software development lifecycle (SDLC) across the organization. Reporting directly to the CISO, this role ensures that security is embedded from design through deployment, enabling secure-by-design principles and reducing application risk. The manager will lead a team of security professionals and collaborate closely with engineering, DevOps, and compliance teams.
Duties And Responsibilities
STRATEGIC PLANNING AND ALIGNMENT :
- Collaborate with the CISO and the IT leadership team to align technology initiatives with the overall business objectives.
- Identify emerging technologies and work with others on the IT leadership team to assess their impact to the organization.
- Makes decisions and recommendations clearly linked to the organization's strategy and financial goals, reflecting an awareness of external dynamics.
- Defines strategic imperatives in terms of the links between increased value, enterprise needs and technological solutions
- Measures the team's performance against the best-in-class peer group and sets a vision and plan to exceed those benchmarks.
- Oversee the selection, deployment, and management of application security tools.
- Drive automation of security testing and reporting within development workflows.
GOVERNANCE & POLICY :
Design process flows for daily activities to increase outcomes by eliminating nonvalue added tasks.Create, establish, and maintain policies related to the software development lifecycle and secure coding practices.Design, implement, and manage a comprehensive Secure SDLC framework.Define security requirements and controls for each phase of the development lifecycle.Establish and maintain secure coding standards and guidelinesMaintain the IT SharePoint site with accurate policies and updated information relevant to the SDLC function.Ensure alignment with internal policies, industry standards (e.g., OWASP, NIST), and regulatory requirements (e.g., SOX, HIPAA, GDPR).TEAM LEADERSHIP & DEVELOPMENT :
Build, lead, and mentor a high-performing team of security professionals.Foster a culture of security awareness and continuous improvement across development teams.Provide training and guidance on secure coding practices and tools to the business and IT groups.OVERSEE IT REPORTING :
Develop procedures and track compliance of important IT reporting and operational activities such as internal and external audit responses, mandatory training compliance.Work with the IT leadership team to develop reports that track important dates and initiatives.Develop, track, and report on key performance metrics related to application security posture and SDLC maturity.ESSENTIAL :
Strong leadership capability, executing as appropriate in the areas of responsibilityBroad knowledge of current and emerging technologies, technology directions, and strategic application to business needs, including the ability to differentiate between a relevant trend and hypeAbility to improve operational efficiency, service delivery and information management across the IT organizationExcellent oral and written communication skills, including the ability to explain technology solutions in business terms, establish rapport and persuade othersAbility to work with others to create new processes and procedures, and the reporting that is required to ensure compliance with the new processes.Ability to partner with business and IT representatives to improve processes and technology to increase the value of IT.Ability to communicate with a wide audience and to persuade / convince others to take actionAbility to stay organized and track many and concurrent initiatives.Ability to analyze data and determine where there are opportunities for improvement.Ability to create excellent presentations and written material that share information and captures imagination.Ability to track deadlines and proactively manage milestones.Ability to learn and understand financial and budgetary requirements of an IT departmentAbility to get along with others and mentor other aspiring leadersAbility to organize offsite meetings and extracurricular activities, such as volunteering initiatives.Ability to work with other teams and departments to resolve escalated issues.NON-ESSENTIAL :
Assist the CITO with ancillary tasks, such as travel, expense reporting, etc.Assist others in the IT department with administrative concerns as needed.Qualifications
REQUIRED :
Bachelor's degree in Computer Science, Cybersecurity, software development or related field is requiredStrong organizational skills requiredExcellent communication skills, written and verbal10 Years+ Experience in information security, SDLC security or similar roles5 Years+ in a leadership roleDeep understanding of SDLC, DevOps, and secure coding practices including cloud tools and multiple coding languages.Hands-on experience with security tools such as; Veracode, Fortify, Checkmarx, SonarQube, GitHub Advanced Security, jFrog.Familiarity with cloud-native development and container security (AWS, Azure, GCP).Experience working in a very large IT departmentExperience managing multiple stakeholdersRelevant certifications (e.g., CSSLP, CISSP, OSWE, GWAPT) are a plusKNOWLEDGE, SKILLS, ABILITIES, AND OTHER CHARACTERISTICS :
Ensures that important information from management is shared with the CITO and other IT leaders as appropriate.Creates new processes and procedures and effectively communicates them and ensures adoption.Gives and receives constructive feedback.Ensures that others involved in a project or effort are kept informed about developments and plans.Ensures that regular consistent communication takes place within area of responsibility.Additional Information
This position is Hybrid - Remote and will require commuting to a designated office. Hybrid work schedules are determined by the hiring manager based on business need.
PAY, BENEFITS AND WORK SCHEDULE :
We offer a comprehensive and competitive benefits package. Employee benefits vary by role, however, may include Health and Wellness, Mental Health, Retirement Savings, Life and Disability, Paid Maternity and Parental Leave, Paid Time Off, Tuition Reimbursement, and an Employee Assistance Program.
Equal Opportunity Employer
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity,national origin, veteran status,disability, genetic information, or other non-merit factors.
How To Apply
Regular full-time employees who apply will be considered along with external candidates. Employees with less than six months with their current position are not eligible to apply for job postings. Please discuss your interest in the position with your current manager / supervisor prior to submitting your completed application. It is highly recommended to apply through the PeopleSoft or Oceanet portals.