- Career Center Home
- Search Jobs
- Lead DevSecOps Engineer
Results
Job Details
Explore Location
AEG WORLDWIDE
Los Angeles, California, United States
(on-site)
Posted
6 days ago
AEG WORLDWIDE
Los Angeles, California, United States
(on-site)
Job Function
Other Profession
Lead DevSecOps Engineer
The insights provided are generated by AI and may contain inaccuracies. Please independently verify any critical information before relying on it.
Lead DevSecOps Engineer
The insights provided are generated by AI and may contain inaccuracies. Please independently verify any critical information before relying on it.
Description
\u003cp\u003e\u003cstrong\u003eCompany Information\u003c/strong\u003e\u003cbr\u003eFor more than 20 years, AEG has played a pivotal role in transforming sports and live entertainment. Annually, we host more than 160 million guests, promote more than 10,000 shows and present more than 22,000 events around the world. We are committed to innovation, artistry, and community, and leverage the power of our 300+ venues, leading sports franchises, marquee music brands, integrated entertainment districts, premier ticketing platform and global sponsorship activations, to create memorable moments that give the world reason to cheer.\u003cbr\u003e\u003cbr\u003eOur business is interwoven with the human mind and heart, and we strive to build a diverse and inclusive company that reflects the artists, athletes, and fans that we host; reach beyond traditional boundaries to support the communities in which we operate; and minimize our impact on the environment by adopting sustainable practices throughout our business operations.\u003cbr\u003e\u003cbr\u003eIf you want to be challenged to up your game and make a difference, then join us in giving the world reason to cheer!\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eJob Summary\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAEG is seeking a Lead DevSecOps Engineer to join its global Information Security organization. Reporting to the Vice President of Information Security, this role provides technical leadership for AEG's DevSecOps and Secure Software Development Lifecycle (SSDLC) programs, driving the integration of security throughout the software development lifecycle. The Lead DevSecOps Engineer partners closely with Engineering, DevOps, Platform Engineering, Infrastructure, and GRC teams to establish secure development standards, strengthen application and cloud security, secure CI/CD pipelines, and advance security automation and continuous compliance capabilities. Serving as a trusted advisor and subject matter expert, this role influences technology strategy, leads cross-functional security initiatives, and helps improve AEG's overall cybersecurity posture across its global technology environment. This position collaborates with teams across North America and Europe and may require flexibility to support initiatives across multiple time zones.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eEssential Functions\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSecure Software Development Lifecycle (SSDLC) Enablement:\n\u003cul\u003e\n\u003cli\u003eLead the development, implementation, and continuous improvement of the organization's Secure Software Development Lifecycle (SSDLC) program, partnering with Information Security and Engineering leadership to establish enterprise-wide secure development standards and practices.\u003c/li\u003e\n\u003cli\u003eDrive the integration of security-by-design principles and automated security controls across the software development lifecycle, ensuring consistent adoption across development, platform, and DevOps teams in collaboration with other engineers; lead security discussions with Engineering, DevOps, and Infrastructure teams to drive adoption of secure development practices.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCI/CD Pipeline Security:\n\u003cul\u003e\n\u003cli\u003eLead the architecture, strategy, and continuous maturation of enterprise CI/CD security capabilities, establishing secure-by-design standards for software delivery pipelines, deployment platforms, and development ecosystems.\u003c/li\u003e\n\u003cli\u003eDefine and govern secure build processes, deployment workflows, container images, and third-party dependencies; drive and expand automation for security testing, validation, and policy enforcement; establish, integrate, and maintain security controls into build and deployment pipelines to support continuous compliance.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSecurity Tooling and Monitoring:\n\u003cul\u003e\n\u003cli\u003eLead the architecture, implementation, and governance of enterprise application security tooling establishing standards for SAST, DAST, and other application security tools.\u003c/li\u003e\n\u003cli\u003eOversee the improvement of security visibility and monitoring across development environments; drive the configuration and maintenance alerts, notifications, and security monitoring capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eRisk, Compliance, and Governance Support:\n\u003cul\u003e\n\u003cli\u003eLead enterprise application risk assessments and threat modeling exercises; establish and maintain the organization's SDLC security requirements, procedures, and supporting documentation.\u003c/li\u003e\n\u003cli\u003eDocument and monitor that compliance efforts align with ISO 27001, SOC 2, NIST, and related frameworks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eApplication Security and Vulnerability Management:\n\u003cul\u003e\n\u003cli\u003ePerform secure code reviews and work with development teams to remediate vulnerabilities; manage vulnerability reporting, remediation tracking, and disclosure processes.\u003c/li\u003e\n\u003cli\u003eLead remediation efforts across engineering and development teams.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSecurity Consulting and Cross-Functional Partnership:\n\u003cul\u003e\n\u003cli\u003eServe as the lead security advisor and strategic partner with Engineering, DevOps, Platform, Infrastructure, and GRC teams to advance security initiatives.\u003c/li\u003e\n\u003cli\u003eLead cross-functional security initiatives and provide practical security guidance throughout the design, development, and deployment lifecycle.\u003c/li\u003e\n\u003cli\u003eDefine and maintain secure development standards and best practices; serve as a trusted security advisor for application and development-related initiatives.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAudit and Incident Response Support:\n\u003cul\u003e\n\u003cli\u003eLead the development and execution of security audits and evidence collection related to SDLC and application security controls.\u003c/li\u003e\n\u003cli\u003eWork with stakeholders on investigations and incident response activities involving applications and development environments.\u003c/li\u003e\n\u003cli\u003eParticipate in control testing, validation, and compliance assessments.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eRequired Qualifications\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBA/BS Degree (4-year) (Advanced Degree Preferred) Computer Science, Cybersecurity, Engineering, Information Systems, or related field. Master's degree or advanced certifications preferred.\u003c/li\u003e\n\u003cli\u003e5+ years Experience in DevSecOps, Application Security, Security Engineering, or related cybersecurity roles.\u003c/li\u003e\n\u003cli\u003eProven experience integrating security throughout the software development lifecycle, including CI/CD pipelines and modern software delivery platforms.\u003c/li\u003e\n\u003cli\u003eHands-on experience with application security testing tools, including SAST, DAST, SCA, and container security solutions.\u003c/li\u003e\n\u003cli\u003eExperience performing threat modeling, application risk assessments, vulnerability management, and remediation tracking.\u003c/li\u003e\n\u003cli\u003eExperience implementing monitoring, alerting, and security controls across cloud, application, and infrastructure environments.\u003c/li\u003e\n\u003cli\u003eStrong understanding of secure software development lifecycle (SSDLC) practices and secure coding principles.\u003c/li\u003e\n\u003cli\u003eFamiliarity with modern application development frameworks and technologies, including Laravel and other enterprise web application frameworks.\u003c/li\u003e\n\u003cli\u003eStrong stakeholder management skills with the ability to build partnerships and align security objectives with business needs.\u003c/li\u003e\n\u003cli\u003eAbility to collaborate effectively with globally distributed teams and accommodate occasional meetings across multiple time zones.\u003c/li\u003e\n\u003cli\u003eAbility to manage multiple concurrent projects and adapt to changing priorities in a fast-paced environment.\u003c/li\u003e\n\u003cli\u003eExperience with programming languages including JavaScript, Python, Ruby, PHP, or C#.\u003c/li\u003e\n\u003cli\u003eExperience with CI/CD platforms such as GitHub Actions, Jenkins, CircleCI, Azure DevOps, or similar technologies.\u003c/li\u003e\n\u003cli\u003eKnowledge of application security testing methodologies including SAST, DAST, SCA, and container security scanning.\u003c/li\u003e\n\u003cli\u003eExperience with OWASP Top 10, NIST Secure Software Development Framework (SSDF), and related security frameworks.\u003c/li\u003e\n\u003cli\u003eExperience configuring application and infrastructure monitoring solutions, alerts, and notifications.\u003c/li\u003e\n\u003cli\u003eFamiliarity with container technologies and cloud-native application deployment models.\u003c/li\u003e\n\u003cli\u003eStrong analytical, troubleshooting, and problem-solving skills.\u003c/li\u003e\n\u003cli\u003eExcellent verbal and written communication skills.\u003c/li\u003e\n\u003cli\u003eAbility to work effectively within a highly collaborative global environment.\u003c/li\u003e\n\u003cli\u003eSelf-motivated with strong ownership, accountability, and attention to detail.\u003c/li\u003e\n\u003cli\u003eRelevant certifications such as CISSP, CSSLP, GIAC Web Application Penetration Tester (GWAPT), GIAC Cloud Security Automation (GCSA), AWS Security Specialty, Microsoft Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), or equivalent certifications.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003ePay Scale:\u0026nbsp;\u003c/strong\u003e$140,000.00 - $160,000.00\u003c/p\u003e\n\u003cp\u003eThe pay scale shown above is for the LA Metro area. Actual pay scale may differ based on geographic region.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eBonus:\u0026nbsp;\u003c/strong\u003eThis position is eligible for a bonus under the current bonus plan requirements.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eBenefits:\u003c/strong\u003e\u003cem\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003eWe offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eAEG reserves the right to change or modify the employee's job description whether orally or in writing, at any time during the employment relationship.\u0026nbsp; AEG may require an employee to perform duties outside their normal description.\u003c/p\u003e\n\u003cp\u003eAEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. \u0026nbsp;We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.\u003c/p\u003e\n\u003cp\u003eEmployer does not offer work visa sponsorship for this position.\u003c/p\u003e
Job ID: 86123396

AEG WORLDWIDE
Entertainment / Sports
Los Angeles
,
CA
,
US
From epic concerts to premier music festivals to heart-stopping sporting events, AEG has been giving the world reason to cheer for more than 20 years.
Headquartered in Los Angeles, CA, we are the world’s leading sports and live entertainment company and operate on five continents, entertaining over 160 million guests annually through our worldwide network of more than 300 venues, powerful sports franchises and music brands, integrated entertainment districts and global sponsorship activations.
We strive to form a per...
View Full Profile
More Jobs from AEG WORLDWIDE
Account Executive - Partner Activation
Los Angeles, California, United States
3 days ago
LA Galaxy, Manager, Ticket Sales and Service
Carson, California, United States
4 days ago
VP Partnership Sales
Los Angeles, California, United States
5 days ago
Jobs You May Like
Median Salary
Net Salary per month
$3,847
Cost of Living Index
81/100
81
Median Apartment Rent in City Center
(1-3 Bedroom)
$2,752
-
$5,943
$4,348
Safety Index
46/100
46
Utilities
Basic
(Electricity, heating, cooling, water, garbage for 915 sq ft apartment)
$140
-
$400
$245
High-Speed Internet
$60
-
$100
$80
Transportation
Gasoline
(1 gallon)
$5.00
Taxi Ride
(1 mile)
$2.98
Data is collected and updated regularly using reputable sources, including corporate websites and governmental reporting institutions.
Loading...