Principal Technology Compliance Program Manager - Vulnerability Management
About the role
The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. This role defines long-term strategy for the identification, assessment, prioritization, and remediation of security vulnerabilities across our technology environment and exercises considerable latitude and initiative to solve broad, complex problems.
Responsibilities
- Ensure the vulnerability management program aligns with regulatory requirements (e.g., PCI-DSS, HIPAA, NIST, ISO 27001) and integrates with other security tools such as SIEM, CMDB, and ticketing systems.
- Define long-term strategy for developing, implementing, and continuously improving the enterprise vulnerability management strategy and roadmap.
- Influence across company and several levels up to execute on IT assessments focusing on compliance with information security policy, procedures and standards.
- Manage and optimize vulnerability management tools (e.g., Tenable, Qualys, Rapid7, etc.) to continuously improve the internal audit and risk management review.
- Serve as the primary point of contact between penetration testers and internal stakeholders, ensuring clear scope definition, rules of engagement, and minimal business disruption.
- Define and track key performance indicators (KPIs) and metrics to measure program effectiveness.
- Analyze and track findings, validate results, and work with relevant teams to prioritize and remediate identified vulnerabilities.
- Manage execution of timely delivery of reports to leadership and stakeholders, maintain documentation, and integrate findings into the broader vulnerability management lifecycle.
- Oversee regular vulnerability scanning and assessments across infrastructure, applications, and cloud environments.
- Facilitate, schedule, and coordinate internal and third-party penetration tests across applications, networks, and cloud environments.
- Maintain documentation and evidence for audits and compliance reviews.
Requirements
- 7 years of experience in IT Security and Compliance, or related area.
- Bachelor’s degree in Information Security, Information Technology, Computer Science or related field, or an additional two years of relevant training/experience in lieu of this degree.
- Experience in project management, including all elements of scope, schedule, budgeting, risk evaluation, quality, integration, staffing, and communications.
- Knowledge of security regulations (e.g., Sarbanes-Oxley, Payment Card Industry Data Security Specification [PCI DSS], Health Insurance Portability and Accountability Act [HIPAA]) and standards (e.g. ISO 27001, NIST SP800-series).
- Excellent verbal and written communication skills.
- Minimum age of 18.
- Must be authorized to work in the U.S.
Skills
- Preferred industry certification in security (e.g. CISA, CISSP, and/or GIAC).
- Preferred industry certification in project management (e.g. PMP).
- 2 years of experience leading people.
- Detailed technical knowledge in security engineering, system and network security, authentication and security protocols.
Benefits
Salary Range: $141,250 - $211,900 / year
Job-Specific Experience, Education & Skills Required: See above.
Job-Specific Leadership Expectations: See above.
Total Rewards: See above.
Regulatory Information
Equal Employment Opportunity Policy Statement: See above.
Government Contractor & Department of Transportation (DOT) Regulations
Post-offer and/or pre-employment drug testing will be conducted to determine the presence of marijuana, cocaine, opioids, phencyclidine (PCP) and amphetamines or a metabolite of these drugs prior to any offer or employment or transfer into a safety-sensitive position. Failure to submit to testing or positive indications of drug use will render the applicant ineligible for employment with Alaska Airlines/Hawaiian Airlines/Horizon Air and any employment offer will be withdrawn.
Application Instructions
Apply by 7:00 PM Pacific Time on 8/31/2026