Company Information
AEG brings music, sports, and live entertainment together to create moments people remember around the world. Each year, more than 100 million fans experience live events across five continents—from global touring, concerts, and festivals to iconic sports and entertainment destinations.
Through our music division, AEG Presents, one of the world’s leading operators of tours, concerts, and music festivals, we help shape the sound of now. We work with artists at every stage of their careers to bring live music to life, connecting artists with fans on stages around the world.
Headquartered in Los Angeles, AEG Presents is driven by creativity, innovation, and purpose, and powered by people who want their work to show up in the real world.
If you’re ready to help create moments that matter, there’s a place for you here. Because it happens here.
Job Summary
The Development Security Operations (DevSecOps) Engineer is a technical role responsible for implementing and maintaining secure software development practices across the organization. Working closely with development, operations, and security teams, this position helps ensure that software delivery processes and environments align with industry best practices while maintaining operational efficiency and strong security controls. The DevSecOps Engineer supports the integration of security throughout the software development lifecycle, assists in identifying and mitigating security risks, and contributes to the continuous improvement of security automation, monitoring, and compliance capabilities.
Essential Functions
- Implement and maintain secure software development practices across the organization by:
- Performing code reviews and collaborate with development teams to address security vulnerabilities and implement secure coding practices.
- Providing guidance and support to development teams in implementing secure coding practices and integrating security into the development lifecycle.
- Work to provide security efforts with DevOps team to secure infrastructure and ensure secure deployment and operation of applications.
- Work with cross-functional teams to define security requirements, standards, and guidelines for software development projects.
- Enhance and monitor the tools used within the development and operations process. This includes:
- Reviewing and enhancing CI/CD pipelines using Github Actions, Azure DevOps, AWS Code pipeline, and Jenkins.
- Utilizing tools like Orca Security, Sysdig, Codacy and Azure Log Analytics to monitor and analyze system logs and application code for security vulnerabilities.
- Staying up to date with the latest security trends, vulnerabilities, and industry best practices, and ensure their integration into our software development processes.
- Secure Image and Artifact Management: Protect container images, build artifacts, and other software packages used in the CI/CD pipeline. Scan these artifacts for vulnerabilities before deploying them and utilize secure registries for storage and distribution.
- Work on the implementation as well as help maintain a security program. This includes:
- Conducting Risk Assessments using frameworks like the OWASP top 10
- Developing a Risk Treatment Plan
- Determining and create needed information Security Policies
- Determining and create needed information Security Objectives
- Maintain and help develop Security Reports
- Help implement Security Controls within each dev group
- Manage vendor relations
- Work with internal and external team in working on audits, incident response, and/or compliance processes.
- Work to define requirements and processes for Disaster Recovery (DR) and Business Continuity. After requirements and processes are determined and approved, assist in the facilitation of a DR test.
Required Qualifications
- BA/BS Degree (4- year)
- 2-5 years of related work experience
- Have experience managing vendor relationships and running an implementation from start to finish.
- Has been a team lead or managed a team of security professionals.
- Experience with a unified, real-time monitoring and analytics platform, such as Azure Log Analytics, Google Cloud Operations (Stackdriver), AWS CloudWatch, Sentry, Splunk or Datadog
- Experience in at least one programming language (JavaScript, Ruby, Python, PHP, C#)
- Experience with cloud environment such as AWS, Azure, and/or Google Cloud Platform
- Experience using a CI/CD tool like Github Actions, CircleCI, Jenkins, Azure DevOps, or AWS CodePipeline
- Experience with apply frameworks in the Software Development Lifecycle like OWASP top 10, NIST, etc
- Experience configuring infrastructure and application alerts, alarms, and notifications.
- Proven experience as a DevSecOps Engineer, Software Security engineer, Security Engineer, or in a similar role
- Eagerness to work in a highly collaborative team environment
- Knowledge of secure software development lifecycle (SSDLC) practices and secure coding principles
- Strong analytical, decision-making, interpersonal, and conflict resolution skills
- Great verbal and written communication skills
- Results driven with reliable follow through
- Comfortable using Git version control.
- Familiarity with industry security standards and frameworks such as OWASP top 10, NIST, ISO 27001, or CIS benchmarks
Payscale: $128,000
Bonus: This position is not eligible for a bonus under the current bonus plan requirements.
Benefits: Full-time: We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.
AEG reserves the right to change or modify the employee’s job description whether orally or in writing, at any time during the employment relationship. AEG may require an employee to perform duties outside their normal description.
AEG's policy is to hire the most qualified applicants, and we comply with all applicable federal, state and local employment laws in making hiring and employee decisions. We are an equal opportunity employer and do not discriminate against applicants or employees on the basis of race, color, marital status, disability, religion, age, sex, sexual orientation, national origin, genetic information, veteran status, or any other legally protected status recognized by applicable federal, state or local law.
Employer does not offer work visa sponsorship for this position.