Principal Technology Compliance Program Manager - Vulnerability Management

Alaska Airlines — SeaTac, WA

Posted: 2026-09-09

Job Description

• Principal individual-contributor subject matter expert defining enterprise technology compliance and vulnerability management strategy across infrastructure, applications, and cloud environments.
• Manage and optimize Tenable, Qualys, Rapid7, SIEM, CMDB, and ticketing integrations; oversee vulnerability scanning, findings validation, prioritization, and remediation.
• Ensure program alignment with PCI-DSS, HIPAA, NIST, ISO 27001, Sarbanes-Oxley, and other information-security requirements, while maintaining audit evidence and compliance documentation.
• Coordinate internal and third-party penetration tests, define scope and rules of engagement, track KPIs, and deliver reports to leadership and stakeholders.
• Requires 7 years of IT security/compliance experience, a relevant bachelor’s degree or equivalent additional experience, project-management experience, U.S. work authorization, and strong written/verbal communication; preferred CISA, CISSP, GIAC, PMP, and 2 years leading people.

View job and apply