Application Security Engineer (senior - principal) Landmark
Calgary, AB, CA, T2P 3V4
We are looking for the right people — people who want to innovate, achieve, grow and lead. We attract and retain the best talent by investing in our employees and empowering them to develop themselves and their careers. Experience the challenges, rewards and opportunity of working for one of the world’s largest providers of products and services to the global energy industry.
About Landmark
Landmark, a Halliburton business line, provides the industry’s most comprehensive suite of digital solutions for exploration, drilling, and production optimization. Its software and data platforms empower customers to model subsurface assets, manage drilling risk, and accelerate decision-making through cloud, AI, and advanced analytics.
About the Role
As an Application Security Engineer at Landmark, you will help identify and reduce security risk in the software products and digital platforms used by the energy industry. Working under general direction, you will perform and support application security assessments, analyze security-testing results, investigate vulnerabilities, and partner with engineering teams to move findings through remediation.
You will work across application security, secure software development, DevSecOps, cloud security, and software supply chain security. The role requires someone who can examine technical use cases, identify realistic attack paths, distinguish meaningful risks from tool-generated noise, and provide practical guidance that helps development teams build and deliver more secure software.
Key Responsibilities
- Perform application security assessments and analyze potential vulnerabilities across web applications, APIs, cloud services, and enterprise software.
- Review results from static application security testing, dynamic application security testing, software composition analysis, and related security tools.
- Validate findings, assess exploitability and business impact, identify potential attack paths, and help prioritize remediation.
- Work directly with software engineers to explain identified risks, recommend practical corrective actions, and track vulnerabilities through resolution.
- Support the integration and operation of security controls within CI/CD pipelines and software development workflows.
- Contribute application security requirements and guidance throughout the software development lifecycle.
- Review application architectures, designs, features, and technical changes for common security weaknesses and potential misuse scenarios.
- Retest remediated vulnerabilities and document whether corrective actions adequately address the identified risk.
- Support secure cloud application deployments by reviewing relevant identity, access, logging, networking, configuration, and data-protection controls.
- Help identify risks in open-source components, third-party dependencies, build artifacts, and other parts of the software supply chain.
- Document assessment results, remediation guidance, risk decisions, and security metrics clearly for technical and business stakeholders.
Qualifications
Required
- Undergraduate degree in Computer Science or a related field.
- A minimum of three years of experience in software development, Application Security, Cybersecurity, DevSecOps, Cloud Security, or a related technical discipline.
- Working knowledge of the software development lifecycle and secure software development practices.
- Experience identifying, evaluating, or remediating security vulnerabilities in software applications.
- Understanding of common application attack vectors, security weaknesses, and software security controls.
- Ability to communicate technical security risks and remediation guidance clearly to software engineering and product delivery teams.
Preferred
- Experience with SAST, DAST, SCA, vulnerability-management platforms, penetration-testing tools, or comparable application security technologies.
- Familiarity with OWASP guidance, threat modeling, API security, authentication, authorization, session management, encryption, and secure coding practices.
- Experience with GitLab or another source-code repository and CI/CD platform.
- Familiarity with Microsoft Azure, Amazon Web Services, or comparable cloud platforms, including identity and access management, logging, networking, and secure deployment concepts.
- Experience with Terraform, pipeline automation, infrastructure as code, or scripting using languages such as Python, PowerShell, or Bash.
- Familiarity with software supply chain security, including third-party dependency risk, software composition analysis, software bills of materials, artifact integrity, or CI/CD security controls.
- Awareness of emerging security considerations associated with AI-enabled applications, machine learning services, or AI-assisted software development.
Candidates who possess qualifications exceeding the minimum job requirements may be considered for higher-level positions based on experience, additional qualifications, demonstrated capabilities, and current business needs. Depending on education, experience, and skill level, candidates may be eligible for roles ranging from Application Security Engineer to Application Security Engineer Sr or Application Security Engineer Principal.
Core Competencies
Halliburton is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.
Location
700 9th Ave SW Suite 2000, Calgary, Alberta, T2P 3V4, Canada
Job Details
Requisition Number: 212115
Experience Level: Experienced Hire
Job Family: Engineering/Science/Technology
Product Service Line: Landmark Software & Services
Full Time / Part Time: Full Time
Additional Locations for this position:
Compensation Information
Compensation is competitive and commensurate with experience.
Job Segment:
Cloud, Testing, Supply Chain, Computer Science, Open Source, Technology, Operations