Lead DevSecOps Engineer

Jobs in JS

Los Angeles (CA)

On-site

USD 140,000 - 160,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

401k Plan with match
Medical, dental, vision
Paid time off

Job summary

AEG is seeking a Lead DevSecOps Engineer to bolster its SSDLC program and secure software delivery across North America and Europe. You will partner with Engineering, DevOps, Platform Engineering, and GRC to build secure development standards, automate security controls, and advance security posture.

Responsibilities include driving secure CI/CD pipelines, implementing SAST/DAST tooling, and leading cross-functional security initiatives while aligning with global teams across time zones.

Qualifications

  • Bachelor's degree in a related field; advanced degree/certs preferred.
  • 5+ years in DevSecOps, App Security, or similar roles.
  • Experience embedding security across SSDLC and CI/CD pipelines.
  • Hands-on with SAST/DAST, SCA, and container security tooling.
  • Ability to model threats and manage vulnerabilities end-to-end.

Responsibilities

  • Lead SSDLC enablement and secure development standards across teams.
  • Own secure CI/CD architecture, pipelines, and policy enforcement.
  • Oversee security tooling, monitoring, alerts, and visibility.
  • Guide risk assessments, threat modeling, and compliance mapping (NIST/ISO SOC2).
  • Perform secure code reviews and remediation tracking with teams.
  • Partner with Engineering, DevOps, Platform, and GRC to drive initiatives.

Skills

SSDLC
CI/CD security
Threat modeling
Vulnerability management
Security automation
SAST/DAST tooling
Cloud security
Security governance
OSS monitoring

Education

BA/BS in CS/Cybersecurity/Engineering
Advanced degree or certs

Tools

GitHub Actions
Jenkins
Azure DevOps
SAST tools
DAST tools
Container security tools

Job description

Company Information

For more than 20 years, AEG has played a pivotal role in transforming sports and live entertainment. Annually, we host more than 160 million guests, promote more than 10,000 shows and present more than 22,000 events around the world. We are committed to innovation, artistry, and community, and leverage the power of our 300+ venues, leading sports franchises, marquee music brands, integrated entertainment districts, premier ticketing platform and global sponsorship activations, to create memorable moments that give the world reason to cheer. Our business is interwoven with the human mind and heart, and we strive to build a diverse and inclusive company that reflects the artists, athletes, and fans that we host; reach beyond traditional boundaries to support the communities in which we operate; and minimize our impact on the environment by adopting sustainable practices throughout our business operations. If you want to be challenged to up your game and make a difference, then join us in giving the world reason to cheer!

Job Summary

AEG is seeking a Lead DevSecOps Engineer to join its global Information Security organization. Reporting to the Vice President of Information Security, this role provides technical leadership for AEG's DevSecOps and Secure Software Development Lifecycle (SSDLC) programs, driving the integration of security throughout the software development lifecycle. The Lead DevSecOps Engineer partners closely with Engineering, DevOps, Platform Engineering, Infrastructure, and GRC teams to establish secure development standards, strengthen application and cloud security, secure CI/CD pipelines, and advance security automation and continuous compliance capabilities. Serving as a trusted advisor and subject matter expert, this role influences technology strategy, leads cross-functional security initiatives, and helps improve AEG's overall cybersecurity posture across its global technology environment. This position collaborates with teams across North America and Europe and may require flexibility to support initiatives across multiple time zones.

Essential Functions
  • Secure Software Development Lifecycle (SSDLC) Enablement:
    • Lead the development, implementation, and continuous improvement of the organization's Secure Software Development Lifecycle (SSDLC) program, partnering with Information Security and Engineering leadership to establish enterprise-wide secure development standards and practices.
    • Drive the integration of security-by-design principles and automated security controls across the software development lifecycle, ensuring consistent adoption across development, platform, and DevOps teams in collaboration with other engineers; lead security discussions with Engineering, DevOps, and Infrastructure teams to drive adoption of secure development practices.
  • CI/CD Pipeline Security:
    • Lead the architecture, strategy, and continuous maturation of enterprise CI/CD security capabilities, establishing secure-by-design standards for software delivery pipelines, deployment platforms, and development ecosystems.
    • Define and govern secure build processes, deployment workflows, container images, and third-party dependencies; drive and expand automation for security testing, validation, and policy enforcement; establish, integrate, and maintain security controls into build and deployment pipelines to support continuous compliance.
  • Security Tooling and Monitoring:
    • Lead the architecture, implementation, and governance of enterprise application security tooling establishing standards for SAST, DAST, and other application security tools.
    • Oversee the improvement of security visibility and monitoring across development environments; drive the configuration and maintenance alerts, notifications, and security monitoring capabilities.
  • Risk, Compliance, and Governance Support:
    • Lead enterprise application risk assessments and threat modeling exercises; establish and maintain the organization’s SDLC security requirements, procedures, and supporting documentation.
    • Document and monitor that compliance efforts align with ISO 27001, SOC 2, NIST, and related frameworks.
  • Application Security and Vulnerability Management:
    • Perform secure code reviews and work with development teams to remediate vulnerabilities; manage vulnerability reporting, remediation tracking, and disclosure processes.
    • Lead remediation efforts across engineering and development teams.
  • Security Consulting and Cross-Functional Partnership:
    • Serve as the lead security advisor and strategic partner with Engineering, DevOps, Platform, Infrastructure, and GRC teams to advance security initiatives.
    • Lead cross-functional security initiatives and provide practical security guidance throughout the design, development, and deployment lifecycle.
    • Define and maintain secure development standards and best practices; serve as a trusted security advisor for application and development-related initiatives.
  • Audit and Incident Response Support:
    • Lead the development and execution of security audits and evidence collection related to SDLC and application security controls.
    • Work with stakeholders on investigations and incident response activities involving applications and development environments.
    • Participate in control testing, validation, and compliance assessments.
Required Qualifications
  • BA/BS Degree (4-year) (Advanced Degree Preferred) Computer Science, Cybersecurity, Engineering, Information Systems, or related field. Master's degree or advanced certifications preferred.
  • 5+ years Experience in DevSecOps, Application Security, Security Engineering, or related cybersecurity roles.
  • Proven experience integrating security throughout the software development lifecycle, including CI/CD pipelines and modern software delivery platforms.
  • Hands-on experience with application security testing tools, including SAST, DAST, SCA, and container security solutions.
  • Experience performing threat modeling, application risk assessments, vulnerability management, and remediation tracking.
  • Experience implementing monitoring, alerting, and security controls across cloud, application, and infrastructure environments.
  • Strong understanding of secure software development lifecycle (SSDLC) practices and secure coding principles.
  • Familiarity with modern application development frameworks and technologies, including Laravel and other enterprise web application frameworks.
  • Strong stakeholder management skills with the ability to build partnerships and align security objectives with business needs.
  • Ability to collaborate effectively with globally distributed teams and accommodate occasional meetings across multiple time zones.
  • Ability to manage multiple concurrent projects and adapt to changing priorities in a fast-paced environment.
  • Experience with programming languages including JavaScript, Python, Ruby, PHP, or C#.
  • Experience with CI/CD platforms such as GitHub Actions, Jenkins, CircleCI, Azure DevOps, or similar technologies.
  • Knowledge of application security testing methodologies including SAST, DAST, SCA, and container security scanning.
  • Experience with OWASP Top 10, NIST Secure Software Development Framework (SSDF), and related security frameworks.
  • Experience configuring application and infrastructure monitoring solutions, alerts, and notifications.
  • Familiarity with container technologies and cloud-native application deployment models.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent verbal and written communication skills.
  • Ability to work effectively within a highly collaborative global environment.
  • Self-motivated with strong ownership, accountability, and attention to detail.
  • Relevant certifications such as CISSP, CSSLP, GIAC Web Application Penetration Tester (GWAPT), GIAC Cloud Security Automation (GCSA), AWS Security Specialty, Microsoft Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), or equivalent certifications.
Pay Scale

$140,000.00 - $160,000.00

The pay scale shown above is for the LA Metro area. Actual pay scale may differ based on geographic region.

Bonus

This position is eligible for a bonus under the current bonus plan requirements.

Benefits

We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.

AEG reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. AEG may require an employee to perform duties outside their normal description.

AEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.

Employer does not offer work visa sponsorship for this position.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead DevSecOps Engineer
Lead DevSecOps Engineer

Global Partnerships • Los Angeles (CA)

On-site
USD 140,000 - 160,000
Medical, dental and vision insurance
Paid holidays
Vacation and sick time
+6
Lead DevSecOps Engineer
Lead DevSecOps Engineer

Aeg-Worldwide • Los Angeles (CA)

On-site
USD 140,000 - 160,000
Medical insurance
Dental and vision insurance
401k Plan with match
+5
Lead DevSecOps Engineer
Lead DevSecOps Engineer

AEG • Los Angeles (CA)

On-site
USD 140,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+3
Manager Information Security Programs
Manager Information Security Programs

AEG • Los Angeles (CA)

On-site
USD 160,000 - 175,000
Medical, dental, and vision insurance
Paid holidays, vacation and sick time
401(k) plan with employer match
+2
Sr Technical Project Manager - Information Security (Temp)
Sr Technical Project Manager - Information Security (Temp)

AEG • Los Angeles (CA)

On-site
USD 150,000 - 170,000
VP Engineering
VP Engineering

AEG WORLDWIDE • Los Angeles (CA)

On-site
USD 217,119 - 300,000
Medical, dental and vision insurance
401k Plan with employer match
Parental leave
+1
Principal DevOps Engineer
Principal DevOps Engineer

AEG • Los Angeles (CA)

On-site
USD 144,487 - 210,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Sr Technical Project Manager - Information Security (Temp)
Sr Technical Project Manager - Information Security (Temp)

Aeg-Worldwide • Los Angeles (CA)

On-site
USD 150,000 - 170,000
Medical insurance
VP of Engineering & Digital Platforms
VP of Engineering & Digital Platforms

AEG WORLDWIDE • Los Angeles (CA)

On-site
USD 217,119 - 300,000
Medical, dental and vision insurance
401k Plan with employer match
Parental leave
+1
Principal DevOps Engineer
Principal DevOps Engineer

AEG Presents • Los Angeles (CA)

On-site
USD 130,038 - 158,935
Medical, dental, vision insurance
401k with employer match
Paid holidays and vacation
+2