1

Security Program Manager Jobs in Katy, TX (NOW HIRING)

Sr. Public Sector Program Manager

Spring, TX

$103K - $103K/yr

Responsibilities The primary purpose of this senior program manager role is to help define the work plan and lead the ongoing execution of a central pillar, Public Sector Security, of our overall HP ...

... safety, security, and contractual requirements. * Establish program governance, operating ... Direct program financial management, including revenue and cost forecasting, backlog review, margin ...

Sr. IT Program Manager

Houston, TX · On-site

$140 - $190/hr

The position provides leadership for our IT Infrastructure, Security and Acquisition Integration programs, including the Project Managers and Project Coordinators that support these areas. The ...

YC Foundation is seeking a highly motivated Grant Writer & Program Manager to lead fundraising ... Food Security * Holistic Healing Retreat * Health & Financial Literacy * Veterans & Senior ...

Bachelor's degree from an accredited institution in Information Security, Risk Management ... Program/project management certification - PMP, PgMP, Scrum Master, or Product Owner. Compliance ...

Showing results 41-60

Security Program Manager information

See Katy, TX salary details

$50K

$136.7K

$153.2K

How much do security program manager jobs pay per year?

As of Sep 5, 2026, the average yearly pay for security program manager in Katy, TX is $136,717.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,400.00 and $144,000.00 per year, depending on experience, location, and employer.

What is a security program manager?

A Security Program Manager (SPM) oversees an organization's security initiatives, ensuring they align with business objectives and compliance requirements. They coordinate security programs, manage risks, and implement policies to protect assets, data, and infrastructure. SPMs work closely with cross-functional teams, including IT, legal, and leadership, to enhance security posture. Their role involves assessing threats, driving security awareness, and managing security projects efficiently.

What are the key skills and qualifications needed to thrive as a security program manager?

To thrive as a Security Program Manager, you need a solid background in information security, risk management, and project management, typically bolstered by a relevant degree and experience in security operations. Experience with security frameworks (like NIST or ISO 27001), tools such as SIEM platforms, and certifications like CISSP or PMP are highly valued. Excellent cross-functional communication, leadership, and problem-solving abilities help you coordinate teams and drive initiatives forward. These capabilities are crucial to effectively lead security programs, mitigate risks, and ensure organizational compliance in a dynamic threat landscape.

What are some typical challenges faced by security program managers, and how are they addressed?

Security Program Managers often face challenges such as balancing evolving cybersecurity threats with business objectives, managing cross-departmental initiatives, and ensuring ongoing compliance with industry standards. Success in this role typically involves continuous learning to stay ahead of threat trends, fostering collaboration among IT, compliance, and executive stakeholders, and implementing clear processes for incident response and policy enforcement. Program Managers regularly review and adjust security strategies, conduct gap analyses, and ensure team alignment through effective communication and stakeholder engagement. Proactively addressing these challenges helps maintain robust security postures while enabling organizations to achieve their goals.

What are popular job titles related to Security Program Manager jobs in Katy, TX?

For Security Program Manager jobs in Katy, TX, the most frequently searched job titles are:

What job categories do people searching Security Program Manager jobs in Katy, TX look for?

The top searched job categories for Security Program Manager jobs in Katy, TX are:

What cities near Katy, TX are hiring for Security Program Manager jobs?

Cities near Katy, TX with the most Security Program Manager job openings:

Infographic showing various Security Program Manager job openings in Katy, TX as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $136,717 per year, or $65.7 per hour.

Application Security Architect

Oceaneering International, Inc.

Houston, TX • On-site

Full-time

Re-posted 5 days ago


Oceaneering rating

6.8

Company rating: 6.8 out of 10

Based on 22 frontline employees who took The Breakroom Quiz

378th of 499 rated machine equipment manufacturers


Job description


The Application Security Architect is responsible for building and operationalizing Oceaneering's enterprise application security program, embedding security into the software development lifecycle (SDLC), CI/CD pipelines, and developer ecosystem.
  • Role provides the opportunity to work in a hybrid environment, working both virtually and in the Houston office when required.

Responsibilities
Functions
  • Define and govern application security requirements, controls, and assurance activities embedded within that model
  • Partner with SCOE to ensure security is integrated without duplicating ownership of engineering platforms, tooling, or development standards
  • Partner with Engineering, the Software Center of Excellence (SCOE), and Cybersecurity leadership to reduce software supply chain risk, implement DevSecOps practices, and enforce secure development standards aligned to Zero Trust principles

Application Security Program Leadership
  • Establish and lead an enterprise Application Security (AppSec) governance framework, including Secure SDLC and vulnerability management policies
  • Drive adoption and enforcement of secure coding standards, security testing requirements, and remediation SLAs across all application teams
  • Build a risk-based AppSec roadmap aligned to business criticality, "crown jewel" applications, and regulatory requirements
  • Serve as the central authority for secure software supply chain controls and application risk posture.

Developer Security & Environment Strategy
  • Design and implement a secure developer program addressing:
  • Developer workstations vs business PCs
  • Removal of excessive local admin privileges
  • Elimination of unmanaged builds and compilers
  • Lead transformation to secure developer environments, including:
  • Virtualized or hybrid development models
  • Centralized build infrastructure
  • Controlled developer access aligned with Zero Trust
  • Reduce risk associated with:
  • Local code storage
  • Unvetted open-source dependencies
  • Developer endpoint compromise

DevSecOps & CI/CD Pipeline Security
  • Architect and implement a secure CI/CD pipeline with embedded controls:
  • SAST, SCA, DAST integration
  • Secrets scanning
  • Artifact integrity and provenance validation
  • Pipeline enforcement (GitHub → CI → Artifact Repository → Test Environments)
  • Ensure no production artifacts bypass secure pipelines and all builds are traceable and verified.
  • Partner with SCOE to standardize DevSecOps tooling and pipeline templates enterprise-wide

Application Security Testing & Validation
  • Establish enterprise-wide application testing program, including:
  • Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA)
  • Manual and automated penetration testing for critical applications
  • Expand testing beyond web applications into embedded, ICS, and custom software platforms.
  • Build structured pen testing program for crown jewel applications, including third-party partnerships and remediation tracking.
  • Ensure security validation is embedded in CI/CD gates before production deployment.

Threat Modeling & Secure Architecture
  • Lead implementation of threat modeling capabilities for critical applications to identify design flaws early in SDLC.
  • Define and enforce secure-by-design principles across engineering teams.
  • Collaborate with architects and engineering to integrate Zero Trust architecture, segmentation, and secure design patterns.

Security Defect Management & Risk Visibility
  • Implement centralized tooling to:
    • Aggregate SAST, SCA, DAST, and pen test findings
    • Provide a single pane of glass for application risk
    • Drive prioritization and remediation of vulnerabilities based on business risk and technical severity.
  • Establish KPIs such as:
    • Mean time to remediate (MTTR)
    • % of critical vulnerabilities fixed before release
    • Coverage of testing across applications

Developer Enablement & Training
  • Build and lead a role-based application security training program for developers, architects, and QA
  • Provide:
    • Secure coding guidance (language-specific)
    • Secure development playbooks and reference architectures
  • Partner with SCOE to embed security practices into daily developer workflows and pipelines.

Integration with Software Center of Excellence (SCOE)
  • Expand the SCOE charter to include DevSecOps governance and enforcement.
  • Drive:
    • Adoption of enterprise CI/CD standards
    • Secure pipeline templates
    • Standardized DevSecOps toolchain
  • Improve visibility and enforcement of security policies across all development teams.

Qualifications
REQUIRED
  • Minimum 8 years in cybersecurity, with strong focus on Application Security / DevSecOps
  • Minimum 8 years' experience building enterprise AppSec programs and CI/CD security controls
  • Due to ITAR work requirements, Permanent Resident or US Citizen is required
  • Minimum 5 years' experience with:
    • SAST, DAST, SCA tools
    • GitHub / CI/CD pipelines / artifact repositories
    • Secure SDLC frameworks
    • Experience implementing Zero Trust principles in development environments
  • Strong understanding of:
    • Software supply chain risks
    • Secure coding practices
    • Cloud and hybrid development architectures

DESIRED
  • Experience in OT/ICS or embedded software environments
  • Background working with software engineering or development teams
  • Familiarity with:
    • NIST, OWASP SAMM, BSIMM
    • Secure SDLC governance frameworks
  • Experience operating in a global, multi-business unit organization

About Us
Oceaneering is a global provider of engineered services and products, primarily to the offshore energy industry. We develop products and services for use throughout the lifecycle of an offshore oilfield, from drilling to decommissioning. We operate the world's premier fleet of work class ROVs. Additionally, we are a leader in offshore oilfield maintenance services, umbilicals, subsea hardware, and tooling. We also use applied technology expertise to serve the defense, material handling, aerospace, science, and renewable energy industries.
Equal Opportunity Employer:
All qualified candidates will receive consideration for all positions without regard to race, color, age, religion, sex (including pregnancy), sexual orientation, gender identity, national origin, veteran status, disability, genetic information, or other non-merit factor.
About the Team
Our regional support functions play a critical role in enabling the success of all Oceaneering business units. These teams include disciplines such as Finance, HR, Recruitment, IT, HSE, Supply Chain, Quality, and Administration. Operating collaboratively across multiple departments and geographic locations, they provide responsive, high-quality support that ensures our operations run efficiently and safely. Having these teams based locally allows us to make timely decisions, respond quickly to operational needs, and maintain strong alignment with our business units and workforce.

What Oceaneering employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom