Tech Lead Cybersecurity Engineer - Governance Risk & Compliance (GRC)
- Salary
- $168.7K–$187.4K
- Hiring from
- United States
- Work type
- Remote
- Posted
Show job descriptionHide job description
Department:
TechnologyOur Company Promise
We are committed to provide our Employees a stable work environment with equal opportunity for learning and personal growth. Creativity and innovation are encouraged for improving the effectiveness of Southwest Airlines. Above all, Employees will be provided the same concern, respect, and caring attitude within the organization that they are expected to share externally with every Southwest Customer.
Job Description:
As a Tech Lead Cybersecurity Engineer on the Governance, Risk & Compliance (GRC) Team, you’ll shape the technology that helps Southwest manage cyber risk, meet evolving regulatory requirements, and protect its Customers, Employees, and operation. Working at the intersection of cybersecurity, compliance, data, and engineering, you’ll lead the design and integration of scalable solutions that automate evidence collection, control testing, continuous monitoring, reporting, and other critical compliance activities. You’ll partner across Cybersecurity, Engineering, Digital Technology, Audit, Legal, and Compliance to translate complex requirements into secure, well-integrated technology capabilities, including AWS-based solutions and a maturing common platform. As an enterprise subject matter expert, you’ll guide Partner Teams, mentor Engineers, strengthen security standards, and help embed compliance into technology solutions from the start. Through technical leadership, automation, and data-driven insights, you’ll reduce manual effort, improve audit readiness, strengthen Southwest’s security posture, and enable the Company to innovate with greater speed, confidence, and resilience.
Additional Details
- This role is offered as a remote workplace position, which may require travel for training, meetings, conferences, etc. Outside of those required visits, the majority of your working time may be spent in a remote location, away from our Corporate Campus. Please note, while this is a remote position, there is a limited group of states or localities ineligible for Employees to regularly perform their work. Those ineligible locations are: Alaska, California, Colorado, Delaware, Illinois, Iowa, Maryland, Massachusetts, Montana, New Hampshire, New Jersey, New York, North Dakota, Oregon, Pennsylvania, South Dakota, Vermont, West Virginia, Washington, Wyoming, and Puerto Rico.
- U.S. citizenship or current authorization to work in the U.S. required and no current or future work authorization sponsorship available.
We’re committed to fair hiring practices and to making employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age, military or veteran status, disability, genetic information, or other legally protected characteristics.
Responsibilities
- Provide security guidance to application and Partner Teams to remediate security vulnerabilities, risk items, and policy exceptions
- Deliver training for clients in use of the key Cybersecurity systems, and automated environments
- Identify Cybersecurity problems, plan solutions, recommend software and systems, and coordinate developments in an orderly manner to meet business requirements
- Act as an agent for change to reflect the latest Cybersecurity standards and practices
- Serves as an enterprise subject matter expert (SME) and advocate of IT Security standards and reference architectures
- Act as a Mentor to both Co-Hearts on responding to production program issues and coaches on resolutions in Cybersecurity and Partner Teams
- Lead testing and implement system enhancements using techniques that preserve system integrity and drives a results-oriented environment
- Develop, test and operate end-to-end software solutions using machine learning, related optimization, and knowledge systems
- Ensure that systems are functionally appropriate, technically sound, and well-integrated
- May perform other job duties as directed by Employee's Leaders
Knowledge, Skills and Abilities
- Knowledge of existing elements in value pipeline, including: PingFederate, eDirectory, Active Directory, CyberArk, and Micro Focus IDM
- Skilled in cloud computing technology and its concepts (AWS)
- Skilled in infrastructure-as-code (IaC) development (Terraform, CloudFormation or similar) and automated configuration management using configuration-as-code (CaC) development (Chef, Puppet, Ansible or similar)
- Skilled in implementing Cybersecurity specific Integration Tests for integrations providing Identity, Security Policy, and Cryptography utilizing tools such as Terragrunt and Gradle
- Skilled in performance, logging and monitoring tools such as Prometheus, ELK Stack, AppD and their integration into platform tools such as AWS CloudWatch
- Skilled in credential management tools and solutions like AWS Secrets Manager, CyberArk or Hashicorp Vault
- Skilled in creating parameterized build jobs via GitLab or Jenkins for Continuous Integration of Security and environmental variables
- Knowledge of architectural principles, design patterns and common methodologies across a variety of technologies
- Ability to mentor and guide technical resources, with a focus on growth of the technical bench
Education
- Required: High School Diploma or GED
- Required: Bachelor's degree in Computer Science, Engineering, Information systems or similar fields of study or equivalent advanced level experience
Experience
- Required: Expert-level experience, expansive and far-reaching knowledge in developing, implementing, or integrating technologies for Enterprise security
- Preferred: Experience designing and implementing automated compliance controls, continuous controls monitoring, evidence collection solutions, and compliance-by-design principles supporting PCI DSS, NIST, SOX, CMMC, and other regulatory frameworks.
- Preferred: Experience developing compliance analytics, dashboards, executive reporting, key performance indicators (KPIs), and data-driven insights that improve audit readiness, control effectiveness, and risk visibility.
- Preferred: Demonstrated ability to communicate complex technical and compliance concepts to both technical and non-technical audiences, including executive leadership, auditors, regulators, and business stakeholders.
- Preferred: Deep expertise supporting PCI DSS compliance programs within a Level 1 merchant environment, including PCI scoping, control implementation, evidence management, audit testing, assessment readiness, remediation planning, and direct engagement with QSAs, Internal Audit, and technology stakeholders.
- Preferred: Previous QSA, ISA, PCI Professional (PCIP), or related compliance certification experience.
Licensing/Certification
- N/A
Physical Abilities
- Ability to perform work duties from [limited space work station/desk/office area] for extended periods of time
- Ability to communicate and interact with others in the English language to meet the demands of the job
- Ability to use a computer and other office productivity tools with sufficient speed and accuracy to meet the demands of the job
Other Qualifications
- Must maintain a well-groomed appearance per Company appearance standards as described in established guidelines
- Must be a U.S. citizen or have authorization to work in the United States as defined by the Immigration Reform Act of 1986
- Must be at least 18 years of age
- Must be able to comply with Company attendance standards as described in established guidelines
- Must be able to travel and /or attend Company and non-Company facilities and remote locations such as remote-based offices as necessary
Pay & Benefits
Competitive market salary from $168,650 per year to $187,400 per year* depending on qualifications and experience. For eligible Leadership and individual contributor roles, additional bonus opportunities are available and awarded at the discretion of the company.
Benefits you’ll love:
- Fly for free, as a privilege, on any open seat on all Southwest flights (your eligible dependents too)
- Southwest will help fund your 401(k) retirement savings with Company contributions up to 9.3% of your eligible earnings**
- Potential for annual ProfitSharing contribution in the Southwest Retirement Savings Plan- when Southwest profits, you profit***
- Competitive health insurance for you and your eligible dependents (including pets)
- Southwest offers health plan coverage options that start from the very first day of employment. You will have 30 days to select and enroll in your health plan with coverage retroactively available to your first day of employment.
- Explore more Benefits you’ll love: https://careers.southwestair.com/benefits
*Pay amount does not guarantee employment for any particular period of time.
**401(k) match contributions are subject to Retirement Savings Plan vesting schedule and applicable IRS limits ***ProfitSharing contributions are subject to Retirement Savings Plan vesting schedule and are made at the discretion of the Company.
Southwest Airlines is an Equal Opportunity Employer.
Please print/save this job description because it won't be available after you apply.