Principal Technology Compliance Program Manager - Vulnerability Management
Alaska Air Group · SeaTac, WA
Start free. No credit card.
Company
Alaska Airlines
The Team
Guided by our purpose, core values, and leadership principles, we are creating an airline people love. Our corporate teams set the strategies and operational plans to ensure the success of our company. Whether we use our expertise in accounting, human resources, finance, planning, legal, marketing, or any of our operational divisions, our shared passion for travel and our guests is what motivates us to achieve excellence each day. If you share our passion for creating an airline people love, we want to hear from you.
Role Summary
The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual contributor, this role defines long-term strategy for the identification, assessment, prioritization, and remediation of security vulnerabilities across our technology environment and exercises considerable latitude and initiative to solve broad, complex problems.
Key Duties
- As the lead subject matter expert in technology compliance, ensure the vulnerability management program aligns with regulatory requirements (e.g., PCI-DSS, HIPAA, NIST, ISO 27001) and integrates with other security tools such as SIEM, CMDB, and ticketing systems.
- Define long-term strategy for developing, implementing, and continuously improving the enterprise vulnerability management strategy and roadmap.
- Influence across company and several levels up to execute on IT assessments focusing on compliance with information security policy, procedures and standards.
- Manage and optimize vulnerability management tools (e.g., Tenable, Qualys, Rapid7, etc.) to continuously improve the internal audit and risk management review.
- Consult Alaska Air Group divisions, IT departments and project resources regarding the development, management approval, and implementation of objectives, goals, policies, standards, guidelines, and other requirement statements needed to support information security compliance throughout the company.
- Serve as the primary point of contact between penetration testers and internal stakeholders, ensuring clear scope definition, rules of engagement, and minimal business disruption.
- Define and track key performance indicators (KPIs) and metrics to measure program effectiveness.
- Analyze and track findings, validate results, and work with relevant teams to prioritize and remediate identified vulnerabilities.
- Manage execution of timely delivery of reports to leadership and stakeholders, maintain documentation, and integrate findings into the broader vulnerability management lifecycle.
- Oversee regular vulnerability scanning and assessments across infrastructure, applications, and cloud environments.
- Facilitate, schedule, and coordinate internal and third-party penetration tests across applications, networks, and cloud environments.
- Maintain documentation and evidence for audits and compliance reviews.
Job-Specific Experience, Education & Skills
Required
- 7 years of experience in IT Security and Compliance, or related area.
- Bachelor’s degree in Information Security, Information Technology, Computer Science or related field, or an additional two years of relevant training/experience in lieu of this degree.
- Experience in project management, including all elements of scope, schedule, budgeting, risk evaluation, quality, integration, staffing, and communications.
- Knowledge of security regulations (e.g., Sarbanes-Oxley, Payment Card Industry Data Security Specification [PCI DSS], Health Insurance Portability and Accountability Act [HIPAA]) and standards (e.g. ISO 27001, NIST SP800-series).
- Excellent verbal and written communication skills.
- High school diploma or equivalent.
- Minimum age of 18.
- Must be authorized to work in the U.S.
Preferred
- Industry certification in security (e.g. CISA, CISSP, and/or GIAC).
- Industry certification in project management (e.g. PMP).
- 2 years of experience leading people.
- Demonstrated knowledge and experience in information security, software development and/or network security for large organizations.
- Detailed technical knowledge in security engineering, system and network security, authentication and security protocols.
About the Job
Job-Specific Leadership Expectations
- Embody our values to own safety, do the right thing, be caring and kind, and deliver performance.
- Create a culture where all employees feel safe and supported.
Salary Details
Pay will be based on multiple factors, including and not limited to location, relevant experience/level and skillset while balancing internal equity relative to other Alaska/Hawaiian/Horizon employees. Alaska/Hawaiian/Horizon is committed to fair, unbiased compensation along with competitive benefits in all locations in which we operate.
Note: We don’t typically hire at the top of the range.
Total Rewards
Alaska Airlines, Hawaiian Airlines and Horizon Air pay and benefits can vary by company, location, number of regularly scheduled hours worked, length of employment, and employment status.
- Free stand-by travel privileges on Alaska Airlines, Hawaiian Airlines & Horizon Air
- Comprehensive well-being programs including medical, dental and vision benefits
- Generous 401k match program
- Annual bonus plans
- Generous holiday and paid time off
Responsibilities
The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual contributor, this role defines long-term strategy for the identification, assessment, prioritization, and remediation of security vulnerabilities across our technology environment and exercises considerable latitude and initiative to solve broad, complex problems.
Qualifications
- As the lead subject matter expert in technology compliance, ensure the vulnerability management program aligns with regulatory requirements (e.g., PCI-DSS, HIPAA, NIST, ISO 27001) and integrates with other security tools such as SIEM, CMDB, and ticketing systems.
- Define long-term strategy for developing, implementing, and continuously improving the enterprise vulnerability management strategy and roadmap.
- Influence across company and several levels up to execute on IT assessments focusing on compliance with information security policy, procedures and standards.
- Manage and optimize vulnerability management tools (e.g., Tenable, Qualys, Rapid7, etc.) to continuously improve the internal audit and risk management review.
- Consult Alaska Air Group divisions, IT departments and project resources regarding the development, management approval, and implementation of objectives, goals, policies, standards, guidelines, and other requirement statements needed to support information security compliance throughout the company.
- Serve as the primary point of contact between penetration testers and internal stakeholders, ensuring clear scope definition, rules of engagement, and minimal business disruption.
- Define and track key performance indicators (KPIs) and metrics to measure program effectiveness.
- Analyze and track findings, validate results, and work with relevant teams to prioritize and remediate identified vulnerabilities.
- Manage execution of timely delivery of reports to leadership and stakeholders, maintain documentation, and integrate findings into the broader vulnerability management lifecycle.
- Oversee regular vulnerability scanning and assessments across infrastructure, applications, and cloud environments.
- Facilitate, schedule, and coordinate internal and third-party penetration tests across applications, networks, and cloud environments.
- Maintain documentation and evidence for audits and compliance reviews.