Development Security Specialist (Industrial Oil & Gas Applications) (Calgary)

Development Security Specialist (Industrial Oil & Gas Applications) (Calgary)

04 Aug
|
Pengcorp
|
Calgary

04 Aug

Pengcorp

Calgary

Role: Development Security Specialist (DevSecOps) -Industrial Oil & Gas Applications

Reports To: Manager, Application & Software Development

Department: Digitization

Position Type: Full Term

Location: Calgary, Alberta (Hybrid)

About the Company

Pengcorp is a consortium of highly dedicated and talented engineers providing specialized services to industrial enterprises throughout North and South America. Our expertise has been embedded in mid- to large-scale projects across Western Canada and around the world. We are recognized for delivering innovative solutions that optimize industrial processes while meeting the needs of all stakeholders.

Our services span multiple industrial technology disciplines, including Electrical & Instrumentation, Industrial Ethernet, Cybersecurity, Automation Integration, Data Visualization & Analytics, and Field Maintenance Support. As we continue to grow, we are seeking experienced professionals who are passionate about advancing secure and reliable industrial operations.

What You Will Do

We are seeking a highly skilled DevSecOps Engineer to support the secure design, development, deployment, and operation of industrial software applications used within the Oil & Gas sector. This role combines software engineering, cybersecurity, DevOps, and industrial control system (ICS) security to ensure that mission-critical applications are protected against cyber threats while maintaining operational reliability, safety, and regulatory compliance.

The ideal candidate will have experience implementing secure software development practices, cloud and on-premises infrastructure security, industrial cybersecurity standards, and automated security controls throughout the software development lifecycle (SDLC).

Key Responsibilities

DevSecOps & Application Security

- Integrate security controls into all phases of the Software Development Lifecycle (SDLC).
- Design, implement, and maintain secure CI/CD pipelines.
- Automate security testing, code scanning, vulnerability management, and compliance checks.
- Conduct secure code reviews and identify security vulnerabilities in application code.
- Implement Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Infrastructure as Code (IaC) scanning.
- Develop secure deployment standards for cloud, on-premise, and hybrid environments.
- Manage secrets, encryption keys, certificates, and privileged access controls.
- Ensure secure integration between industrial applications, enterprise systems, and operational technology (OT) environments.

Penetration Testing

Conduct and coordinate

- Web application and API security testing to identify and remediate vulnerabilities.
- Cloud, container, and Kubernetes security assessments to evaluate risks and security controls.
- Annual third-party penetration testing, including remediation tracking and validation of findings.

Tools:





o Burp Suite Pro o OWASP ZAP o Nmap o Metasploit o Postman Security Tests o Kali Linux

Industrial Cybersecurity Responsibilities

- Design and maintain cybersecurity controls protecting Oil & Gas operational applications.
- Implement security architectures aligned with:

IEC 62443

NIST Cybersecurity Framework (CSF)

NIST SP 800-82

ISA/IEC Industrial Automation Security Standards

ISO 27001

- Support cybersecurity risk assessments for industrial applications and supporting infrastructure.
- Develop secure interfaces between SCADA systems, historians, PLCs, RTUs, IIoT devices, and enterprise applications.
- Identify and mitigate cybersecurity threats affecting industrial operations.
- Implement segmentation strategies between IT and OT environments.
- Assist in the deployment and maintenance of Zero Trust security principles across industrial systems.
- Conduct threat modeling for critical operational applications.

Vulnerability Management & Security Monitoring

- Perform regular vulnerability assessments and remediation tracking.
- Analyze application and infrastructure security findings.
- Coordinate security patch management activities.
- Monitor security events using SIEM and security monitoring platforms.
- Investigate cybersecurity incidents affecting development environments and industrial applications.
- Participate in incident response exercises and post-incident reviews.
- Develop automated security alerting and compliance reporting.
- Cloud & Infrastructure Security
- Secure AWS, Azure, or private cloud infrastructures hosting industrial applications.
- Implement infrastructure hardening standards.
- Manage container security for Docker and Kubernetes environments.
- Establish secure network architectures including firewalls, VPNs, reverse proxies, and micro-segmentation.
- Secure APIs and application integrations.

Governance, Risk & Compliance

- Support audits and compliance activities.
- Maintain cybersecurity policies, standards, and procedures.
- Document security architectures, risk assessments, and remediation plans.
- Ensure compliance with customer, industry, and regulatory cybersecurity requirements.
- Track cybersecurity KPIs and risk metrics.

Required Qualifications

Education

Bachelor's Degree in:

- Computer Science
- Software Engineering
- Cybersecurity
- Computer Engineering
- Related Technical Field

Experience

- 5+ years of software development, DevOps, cybersecurity, or DevSecOps experience.
- 3+ years securing industrial, operational technology (OT), or critical infrastructure systems.
- Experience supporting Oil & Gas, Energy, Utilities, Manufacturing, or Industrial Automation environments.





Technical Skills

CI/CD Platforms:

- Azure DevOps
- GitHub Actions
- Jenkins
- GitLab CI/CD

Programming & Scripting:

- Python
- PowerShell
- Bash
- C#
- JavaScript

Cloud Platforms:

- Microsoft Azure
- AWS
- Google Cloud Platform (GCP)
- Security Tools:
- Microsoft Defender Suite
- Microsoft Sentinel
- Splunk
- Qradar
- Securonix
- CrowdStrike
- Qualys
- Tenable
- SonarQube
- Checkmarx
- Veracode
- Snyk

Containers & Infrastructure:

- Docker
- Kubernetes
- Terraform
- Ansible

OT Technologies:

- SCADA Systems
- PLCs
- Historians
- OPC UA
- Modbus
- DNP3
- Industrial Networks

Preferred Certifications

- CISSP (Certified Information Systems Security Professional)
- GICSP (Global Industrial Cyber Security Professional)
- CSSLP (Certified Secure Software Lifecycle Skilled)
- CISM (Certified Information Security Manager)
- Certified Kubernetes Security Specialist (CKS)
- Microsoft Cybersecurity Architect Expert
- AWS Certified DevOps Engineer-Professional
- AWS Certified Security - Specialty
- Azure Security Engineer Associate
- GIAC Industrial Cyber Security Certifications
- ISA/IEC 62443 Cybersecurity Certificate

Key Competencies

- Secure Software Development
- Industrial Cybersecurity
- DevSecOps Automation
- Risk Management
- Threat Modeling
- Incident Response
- Vulnerability Management
- Cloud Security
- OT/IT Convergence Security
- Analytical Problem Solving
- Communication and Collaboration

Success Measures The successful candidate will:

- Reduce application security vulnerabilities and remediation times.
- Improve security automation coverage across CI/CD pipelines.
- Maintain compliance with industrial cybersecurity standards.
- Successfully secure critical Oil & Gas operational applications.
- Minimize cybersecurity risk to production and operational environments.
- Enhance resilience against cyber threats targeting industrial operations.

Typical Applications Protected

- Production Management Systems
- Pipeline Monitoring Applications
- Asset Integrity Platforms
- Predictive Maintenance Systems
- SCADA and HMI Interfaces
- Digital Oilfield Applications
- Field Data Collection Systems
- Emissions Monitoring Applications
- Industrial IoT Platforms
- Operational Analytics and Reporting Systems

This role is critical to ensuring that industrial software applications remain secure, reliable, and resilient while supporting protected and efficient Oil & Gas operations.

Why Join Us?

- Work on mission-critical OT and cybersecurity projects supporting industrial operations across North and South America.
- Join a team of highly skilled engineers delivering innovative solutions to complex industrial challenges.
- Competitive compensation and comprehensive perks package.
- Hybrid work setting with flexibility and autonomy.
- Opportunities for career growth, technical leadership, and professional development.
- Exposure to leading OT networking, cybersecurity, and industrial automation technologies.

📌 Development Security Specialist (Industrial Oil & Gas Applications) (Calgary)
🏢 Pengcorp
📍 Calgary

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: development security specialist (industrial oil & gas applications) (calgary) / calgary