Lead DevSecOps Engineer
Sign up free to see how well your resume matches this role.
What you'll do
- Lead the development, implementation, and continuous improvement of the organization's Secure Software Development Lifecycle (SSDLC) program, partnering with Information Security and Engineering leadership to establish enterprise-wide secure development standards and practices.
- Drive the integration of security-by-design principles and automated security controls across the software development lifecycle, ensuring consistent adoption across development, platform, and DevOps teams in collaboration with other engineers; lead security discussions with Engineering, DevOps, and Infrastructure teams to drive adoption of secure development practices.
- Lead the architecture, strategy, and continuous maturation of enterprise CI/CD security capabilities, establishing secure-by-design standards for software delivery pipelines, deployment platforms, and development ecosystems.
- Define and govern secure build processes, deployment workflows, container images, and third-party dependencies; drive and expand automation for security testing, validation, and policy enforcement; establish, integrate, and maintain security controls into build and deployment pipelines to support continuous compliance.
- Lead the architecture, implementation, and governance of enterprise application security tooling establishing standards for SAST, DAST, and other application security tools.
- Oversee the improvement of security visibility and monitoring across development environments; drive the configuration and maintenance alerts, notifications, and security monitoring capabilities.
- Lead enterprise application risk assessments and threat modeling exercises; establish and maintain the organization’s SDLC security requirements, procedures, and supporting documentation.
- Document and monitor that compliance efforts align with ISO 27001, SOC 2, NIST, and related frameworks.
- Perform secure code reviews and work with development teams to remediate vulnerabilities; manage vulnerability reporting, remediation tracking, and disclosure processes.
- Lead remediation efforts across engineering and development teams.
- Serve as the lead security advisor and strategic partner with Engineering, DevOps, Platform, Infrastructure, and GRC teams to advance security initiatives.
- Lead cross-functional security initiatives and provide practical security guidance throughout the design, development, and deployment lifecycle.
What they're looking for
- BA/BS Degree (4-year) (Advanced Degree Preferred) Computer Science, Cybersecurity, Engineering, Information Systems, or related field.
- 5+ years Experience in DevSecOps, Application Security, Security Engineering, or related cybersecurity roles.
- Proven experience integrating security throughout the software development lifecycle, including CI/CD pipelines and modern software delivery platforms.
- Hands-on experience with application security testing tools, including SAST, DAST, SCA, and container security solutions.
- Experience performing threat modeling, application risk assessments, vulnerability management, and remediation tracking.
- Experience implementing monitoring, alerting, and security controls across cloud, application, and infrastructure environments.
- Strong understanding of secure software development lifecycle (SSDLC) practices and secure coding principles.
- Familiarity with modern application development frameworks and technologies, including Laravel and other enterprise web application frameworks.
- Strong stakeholder management skills with the ability to build partnerships and align security objectives with business needs.
- Ability to collaborate effectively with globally distributed teams and accommodate occasional meetings across multiple time zones.
- Ability to manage multiple concurrent projects and adapt to changing priorities in a fast-paced environment.
- Experience with programming languages including JavaScript, Python, Ruby, PHP, or C#.
Nice to have
- Advanced Degree
- Master's degree or advanced certifications
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
Company Information
For more than 20 years, AEG has played a pivotal role in transforming sports and live entertainment. Annually, we host more than 160 million guests, promote more than 10,000 shows and present more than 22,000 events around the world. We are committed to innovation, artistry, and community, and leverage the power of our 300+ venues, leading sports franchises, marquee music brands, integrated entertainment districts, premier ticketing platform and global sponsorship activations, to create memorable moments that give the world reason to cheer.
Our business is interwoven with the human mind and heart, and we strive to build a diverse and inclusive company that reflects the artists, athletes, and fans that we host; reach beyond traditional boundaries to support the communities in which we operate; and minimize our impact on the environment by adopting sustainable practices throughout our business operations.
If you want to be challenged to up your game and make a difference, then join us in giving the world reason to cheer!
Job Summary
AEG is seeking a Lead DevSecOps Engineer to join its global Information Security organization. Reporting to the Vice President of Information Security, this role provides technical leadership for AEG's DevSecOps and Secure Software Development Lifecycle (SSDLC) programs, driving the integration of security throughout the software development lifecycle. The Lead DevSecOps Engineer partners closely with Engineering, DevOps, Platform Engineering, Infrastructure, and GRC teams to establish secure development standards, strengthen application and cloud security, secure CI/CD pipelines, and advance security automation and continuous compliance capabilities. Serving as a trusted advisor and subject matter expert, this role influences technology strategy, leads cross-functional security initiatives, and helps improve AEG's overall cybersecurity posture across its global technology environment. This position collaborates with teams across North America and Europe and may require flexibility to support initiatives across multiple time zones.
Essential Functions
- Secure Software Development Lifecycle (SSDLC) Enablement:
- Lead the development, implementation, and continuous improvement of the organization's Secure Software Development Lifecycle (SSDLC) program, partnering with Information Security and Engineering leadership to establish enterprise-wide secure development standards and practices.
- Drive the integration of security-by-design principles and automated security controls across the software development lifecycle, ensuring consistent adoption across development, platform, and DevOps teams in collaboration with other engineers; lead security discussions with Engineering, DevOps, and Infrastructure teams to drive adoption of secure development practices.
- CI/CD Pipeline Security:
- Lead the architecture, strategy, and continuous maturation of enterprise CI/CD security capabilities, establishing secure-by-design standards for software delivery pipelines, deployment platforms, and development ecosystems.
- Define and govern secure build processes, deployment workflows, container images, and third-party dependencies; drive and expand automation for security testing, validation, and policy enforcement; establish, integrate, and maintain security controls into build and deployment pipelines to support continuous compliance.
- Security Tooling and Monitoring:
- Lead the architecture, implementation, and governance of enterprise application security tooling establishing standards for SAST, DAST, and other application security tools.
- Oversee the improvement of security visibility and monitoring across development environments; drive the configuration and maintenance alerts, notifications, and security monitoring capabilities.
- Risk, Compliance, and Governance Support:
- Lead enterprise application risk assessments and threat modeling exercises; establish and maintain the organization’s SDLC security requirements, procedures, and supporting documentation.
- Document and monitor that compliance efforts align with ISO 27001, SOC 2, NIST, and related frameworks.
- Application Security and Vulnerability Management:
- Perform secure code reviews and work with development teams to remediate vulnerabilities; manage vulnerability reporting, remediation tracking, and disclosure processes.
- Lead remediation efforts across engineering and development teams.
- Security Consulting and Cross-Functional Partnership:
- Serve as the lead security advisor and strategic partner with Engineering, DevOps, Platform, Infrastructure, and GRC teams to advance security initiatives.
- Lead cross-functional security initiatives and provide practical security guidance throughout the design, development, and deployment lifecycle.
- Define and maintain secure development standards and best practices; serve as a trusted security advisor for application and development-related initiatives.
- Audit and Incident Response Support:
- Lead the development and execution of security audits and evidence collection related to SDLC and application security controls.
- Work with stakeholders on investigations and incident response activities involving applications and development environments.
- Participate in control testing, validation, and compliance assessments.
Required Qualifications
- BA/BS Degree (4-year) (Advanced Degree Preferred) Computer Science, Cybersecurity, Engineering, Information Systems, or related field. Master's degree or advanced certifications preferred.
- 5+ years Experience in DevSecOps, Application Security, Security Engineering, or related cybersecurity roles.
- Proven experience integrating security throughout the software development lifecycle, including CI/CD pipelines and modern software delivery platforms.
- Hands-on experience with application security testing tools, including SAST, DAST, SCA, and container security solutions.
- Experience performing threat modeling, application risk assessments, vulnerability management, and remediation tracking.
- Experience implementing monitoring, alerting, and security controls across cloud, application, and infrastructure environments.
- Strong understanding of secure software development lifecycle (SSDLC) practices and secure coding principles.
- Familiarity with modern application development frameworks and technologies, including Laravel and other enterprise web application frameworks.
- Strong stakeholder management skills with the ability to build partnerships and align security objectives with business needs.
- Ability to collaborate effectively with globally distributed teams and accommodate occasional meetings across multiple time zones.
- Ability to manage multiple concurrent projects and adapt to changing priorities in a fast-paced environment.
- Experience with programming languages including JavaScript, Python, Ruby, PHP, or C#.
- Experience with CI/CD platforms such as GitHub Actions, Jenkins, CircleCI, Azure DevOps, or similar technologies.
- Knowledge of application security testing methodologies including SAST, DAST, SCA, and container security scanning.
- Experience with OWASP Top 10, NIST Secure Software Development Framework (SSDF), and related security frameworks.
- Experience configuring application and infrastructure monitoring solutions, alerts, and notifications.
- Familiarity with container technologies and cloud-native application deployment models.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent verbal and written communication skills.
- Ability to work effectively within a highly collaborative global environment.
- Self-motivated with strong ownership, accountability, and attention to detail.
- Relevant certifications such as CISSP, CSSLP, GIAC Web Application Penetration Tester (GWAPT), GIAC Cloud Security Automation (GCSA), AWS Security Specialty, Microsoft Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), or equivalent certifications.
Pay Scale: $140,000.00 - $160,000.00
The pay scale shown above is for the LA Metro area. Actual pay scale may differ based on geographic region.
Bonus: This position is eligible for a bonus under the current bonus plan requirements.
Benefits: We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.
AEG reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. AEG may require an employee to perform duties outside their normal description.
AEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.
Employer does not offer work visa sponsorship for this position.
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.