Application Security Engineer (senior - principal) Landmark
HalliburtonWe are looking for the right people — people who want to innovate, achieve, grow and lead. We attract and retain the best talent by investing in our employees and empowering them to develop themselves and their careers. Experience the challenges, rewards and opportunity of working for one of the world’s largest providers of products and services to the global energy industry. About Landmark Landmark, a Halliburton business line, provides the industry’s most comprehensive suite of digital solutions for exploration, drilling, and production optimization. Its software and data platforms empower customers to model subsurface assets, manage drilling risk, and accelerate decision-making through cloud, AI, and advanced analytics. About the Role As an Application Security Engineer at Landmark, you will help identify and reduce security risk in the software products and digital platforms used by the energy industry. Working under general direction, you will perform and support application security assessments, analyze security-testing results, investigate vulnerabilities, and partner with engineering teams to move findings through remediation. You will work across application security, secure software development, DevSecOps, cloud security, and software supply chain security. The role requires someone who can examine technical use cases, identify realistic attack paths, distinguish meaningful risks from tool-generated noise, and provide practical guidance that helps development teams build and deliver more secure software. Key Responsibilities Perform application security assessments and analyze potential vulnerabilities across web applications, APIs, cloud services, and enterprise software. Review results from static application security testing, dynamic application security testing, software composition analysis, and related security tools. Validate findings, assess exploitability and business impact, identify potential attack paths, and help prioritize remediation. Work directly with software engineers to explain identified risks, recommend practical corrective actions, and track vulnerabilities through resolution. Support the integration and operation of security controls within CI/CD pipelines and software development workflows. Contribute application security requirements and guidance throughout the software development lifecycle. Review application architectures, designs, features, and technical changes for common security weaknesses and potential misuse scenarios. Retest remediated vulnerabilities and document whether corrective actions adequately address the identified risk. Support secure cloud application deployments by reviewing relevant identity, access, logging, networking, configuration, and data-protection controls. Help identify risks in open-source components, third-party dependencies, build artifacts, and other parts of the software supply chain. Document assessment results, remediation guidance, risk decisions, and security metrics clearly for technical and business stakeholders. Qualifications Required Undergraduate degree in Computer Science or a related field. A minimum of three years of experience in software development, Application Security, Cybersecurity, DevSecOps, Cloud Security, or a related technical discipline. Working knowledge of the software development lifecycle and secure software development practices. Experience identifying, evaluating, or remediating security vulnerabilities in software applications. Understanding of common application attack vectors, security weaknesses, and software security controls. Ability to communicate technical security risks and remediation guidance clearly to software engineering and product delivery teams. Preferred Experience with SAST, DAST, SCA, vulnerability-management platforms, penetration-testing tools, or comparable application security technologies. Familiarity with OWASP guidance, threat modeling, API security, authentication, authorization,…