{"id":1133554,"url":"https://alion.io/job/anschutz-entertainment-group-lead-devsecops-engineer","title":"Lead DevSecOps Engineer","company":{"id":5598,"name":"Anschutz Entertainment Group","domain":"aegworldwide.com","url":"https://alion.io/company/aegworldwide","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":76,"open_postings":38,"ghost_share":0,"stale_share":0.947,"repost_share":0,"time_to_fill_p50_days":43,"computed_at":"2026-09-23T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":["Los Angeles, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":88000,"max_usd":228000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":15},"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"C#","optional":false},{"name":"CI/CD","optional":false},{"name":"CircleCI","optional":false},{"name":"GitHub Actions","optional":false},{"name":"ISO 27001","optional":false},{"name":"JavaScript","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"Laravel","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"PHP","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Python","optional":false},{"name":"Ruby","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-09-23T04:14:06Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-24T00:33:59Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"Company Information\nFor more than 20 years, AEG has played a pivotal role in transforming sports and live entertainment. Annually, we host more than 160 million guests, promote more than 10,000 shows and present more than 22,000 events around the world. We are committed to innovation, artistry, and community, and leverage the power of our 300+ venues, leading sports franchises, marquee music brands, integrated entertainment districts, premier ticketing platform and global sponsorship activations, to create memorable moments that give the world reason to cheer.\nOur business is interwoven with the human mind and heart, and we strive to build a diverse and inclusive company that reflects the artists, athletes, and fans that we host; reach beyond traditional boundaries to support the communities in which we operate; and minimize our impact on the environment by adopting sustainable practices throughout our business operations.\nIf you want to be challenged to up your game and make a difference, then join us in giving the world reason to cheer!\nJob Summary\nAEG is seeking a Lead DevSecOps Engineer to join its global Information Security organization. Reporting to the Vice President of Information Security, this role provides technical leadership for AEG's DevSecOps and Secure Software Development Lifecycle (SSDLC) programs, driving the integration of security throughout the software development lifecycle. The Lead DevSecOps Engineer partners closely with Engineering, DevOps, Platform Engineering, Infrastructure, and GRC teams to establish secure development standards, strengthen application and cloud security, secure CI/CD pipelines, and advance security automation and continuous compliance capabilities. Serving as a trusted advisor and subject matter expert, this role influences technology strategy, leads cross-functional security initiatives, and helps improve AEG's overall cybersecurity posture across its global technology environment. This position collaborates with teams across North America and Europe and may require flexibility to support initiatives across multiple time zones.\nEssential Functions\nSecure Software Development Lifecycle (SSDLC) Enablement:Lead the development, implementation, and continuous improvement of the organization's Secure Software Development Lifecycle (SSDLC) program, partnering with Information Security and Engineering leadership to establish enterprise-wide secure development standards and practices.\nDrive the integration of security-by-design principles and automated security controls across the software development lifecycle, ensuring consistent adoption across development, platform, and DevOps teams in collaboration with other engineers; lead security discussions with Engineering, DevOps, and Infrastructure teams to drive adoption of secure development practices.\n\nCI/CD Pipeline Security:Lead the architecture, strategy, and continuous maturation of enterprise CI/CD security capabilities, establishing secure-by-design standards for software delivery pipelines, deployment platforms, and development ecosystems.\nDefine and govern secure build processes, deployment workflows, container images, and third-party dependencies; drive and expand automation for security testing, validation, and policy enforcement; establish, integrate, and maintain security controls into build and deployment pipelines to support continuous compliance.\n\nSecurity Tooling and Monitoring:Lead the architecture, implementation, and governance of enterprise application security tooling establishing standards for SAST, DAST, and other application security tools.\nOversee the improvement of security visibility and monitoring across development environments; drive the configuration and maintenance alerts, notifications, and security monitoring capabilities.\n\nRisk, Compliance, and Governance Support:Lead enterprise application risk assessments and threat modeling exercises; establish and maintain the organization’s SDLC security requirements, procedures, and supporting documentation.\nDocument and monitor that compliance efforts align with ISO 27001, SOC 2, NIST, and related frameworks.\n\nApplication Security and Vulnerability Management:Perform secure code reviews and work with development teams to remediate vulnerabilities; manage vulnerability reporting, remediation tracking, and disclosure processes.\nLead remediation efforts across engineering and development teams.\n\nSecurity Consulting and Cross-Functional Partnership:Serve as the lead security advisor and strategic partner with Engineering, DevOps, Platform, Infrastructure, and GRC teams to advance security initiatives.\nLead cross-functional security initiatives and provide practical security guidance throughout the design, development, and deployment lifecycle.\nDefine and maintain secure development standards and best practices; serve as a trusted security advisor for application and development-related initiatives.\n\nAudit and Incident Response Support:Lead the development and execution of security audits and evidence collection related to SDLC and application security controls.\nWork with stakeholders on investigations and incident response activities involving applications and development environments.\nParticipate in control testing, validation, and compliance assessments.\n\nRequired Qualifications\nBA/BS Degree (4-year) (Advanced Degree Preferred) Computer Science, Cybersecurity, Engineering, Information Systems, or related field. Master's degree or advanced certifications preferred.\n5+ years Experience in DevSecOps, Application Security, Security Engineering, or related cybersecurity roles.\nProven experience integrating security throughout the software development lifecycle, including CI/CD pipelines and modern software delivery platforms.\nHands-on experience with application security testing tools, including SAST, DAST, SCA, and container security solutions.\nExperience performing threat modeling, application risk assessments, vulnerability management, and remediation tracking.\nExperience implementing monitoring, alerting, and security controls across cloud, application, and infrastructure environments.\nStrong understanding of secure software development lifecycle (SSDLC) practices and secure coding principles.\nFamiliarity with modern application development frameworks and technologies, including Laravel and other enterprise web application frameworks.\nStrong stakeholder management skills with the ability to build partnerships and align security objectives with business needs.\nAbility to collaborate effectively with globally distributed teams and accommodate occasional meetings across multiple time zones.\nAbility to manage multiple concurrent projects and adapt to changing priorities in a fast-paced environment.\nExperience with programming languages including JavaScript, Python, Ruby, PHP, or C#.\nExperience with CI/CD platforms such as GitHub Actions, Jenkins, CircleCI, Azure DevOps, or similar technologies.\nKnowledge of application security testing methodologies including SAST, DAST, SCA, and container security scanning.\nExperience with OWASP Top 10, NIST Secure Software Development Framework (SSDF), and related security frameworks.\nExperience configuring application and infrastructure monitoring solutions, alerts, and notifications.\nFamiliarity with container technologies and cloud-native application deployment models.\nStrong analytical, troubleshooting, and problem-solving skills.\nExcellent verbal and written communication skills.\nAbility to work effectively within a highly collaborative global environment.\nSelf-motivated with strong ownership, accountability, and attention to detail.\nRelevant certifications such as CISSP, CSSLP, GIAC Web Application Penetration Tester (GWAPT), GIAC Cloud Security Automation (GCSA), AWS Security Specialty, Microsoft Azure Security Engineer Associate, Certified Kubernetes Security Specialist (CKS), or equivalent certifications.\nPay Scale: $140,000.00 - $160,000.00\nThe pay scale shown above is for the LA Metro area. Actual pay scale may differ based on geographic region.\nBonus: This position is eligible for a bonus under the current bonus plan requirements.\nBenefits: We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.\nAEG reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. AEG may require an employee to perform duties outside their normal description.\nAEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.\nEmployer does not offer work visa sponsorship for this position.","description_format":"text","description_chars":9344,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"master","optional":false},"security_clearance":false,"languages":[]},"benefits":["401k plan","Life insurance","Parental leave","Vision insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Events & Ticketing","Ticketing","Application Security"],"lifecycle":[{"event":"open","at":"2026-09-23T05:21:25Z"}],"liveness":{"score":60,"band":"ok","label":"Likely open","p_open":1,"p_active":0.602,"p_room":1,"age_days":0,"expected_fill_days":43,"reasons":["conf:0","stale_co","win:early"],"computed_at":"2026-09-23T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/anschutz-entertainment-group-lead-devsecops-engineer","json_url":"https://alion.io/job/anschutz-entertainment-group-lead-devsecops-engineer.json","meta":{"generated_at":"2026-09-24T01:58:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}