Principal Engineer, DevSecOps
Listed on 2026-05-29
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
Short
Description:
The Principal Engineer, Information Security (Dev Sec Ops ) is the technical lead for Allegiant's Dev Sec Ops program. This person owns the security tooling, policies, and automation that protect code, infrastructure, and cloud workloads as they move through CI/CD pipelines into production.
This is not a generalist security role. The principal engineer must have production experience across four disciplines simultaneously: application security, pipeline engineering, cloud infrastructure, and infrastructure-as-code (IaC) governance. The role also requires working knowledge of securing agentic AI workflows, including MCP server governance, AI gateway configuration, and trust boundaries for tool-using AI systems. The role requires someone who has shipped security tooling that development teams actually adopted, not just evaluated or recommended.
The principal engineer leads a team of two mid-level engineers, unblocks technical problems, reviews architecture decisions, and drives delivery against committed program objectives. This person reports to the Senior Manager of Information Security Engineering and works closely with Dev Ops, Full Stack Engineering, and Security Governance. Allegiant is modernizing its web applications, expanding into new customer channels, and integrating a recent acquisition.
Each of these increases the volume of code and infrastructure flowing through pipelines.
This role ensures security keeps pace with that velocity. This role prepares the principal engineer for future promotion tracks including Architect I and Manager I.
SummaryDev Sec Ops Principal Engineer
Key Duties:
- Proven and demonstrable ability to lead at least two other team members in an official capacity towards specific Dev Sec Ops outcomes.
- Lead the Dev Sec Ops team (two engineers) in daily execution, weekly syncs, and PI planning. Ensure stories are accurate, scoped, and deliverable.
- Own and drive the Dev Sec Ops roadmap across pipeline security, IaC policy enforcement, application security tooling, and cloud security posture management.
- Embedding threat modeling into pipelines and workflows to provide real-time analysis of architectural changes in products.
- Architect and maintain security gates in Git Hub Actions CI/CD pipelines. Define when and how scans run, what blocks a merge, and how results route to developers.
- Administer Git Hub Advanced Security across the organization:
CodeQL query suites, secret scanning policies, Dependabot configuration, and developer‑facing campaign management. - Author and deploy Checkov custom policies for Terraform IaC scanning. Drive golden policy adoption from current 25% pipeline coverage toward 75%+ with hard‑fail enforcement.
- Operate and configure Palo Alto Prisma or Cortex (CNAPP) for cloud security posture, image scanning, and App Sec integration.
- Manage Terraform‑based infrastructure security across multi‑account AWS environments using Control Tower, IAM, VPC, and Transit Gateway.
- Integrate security tooling outputs into SIEM and SOAR for alerting, triage, and response workflows.
- Mentor two mid‑level engineers. Identify skills gaps, provide hands‑on training, and review their work.
- Collaborate with Security Governance to produce compliance evidence for PCI‑DSS, NIST, and CIS controls derived from Dev Sec Ops tooling.
- Support acquisition security assessments by evaluating incoming technology stacks against Allegiant's IaC and pipeline security standards.
- Define and enforce security governance for agentic AI tooling, including MCP server registries, gateway configurations, and trust policies for AI‑to‑tool interactions.
- Document architecture decisions, policy rationale, and runbooks. Maintain documentation quality standards across the Dev Sec Ops team.
- Participate in SAFe Agile planning. Maintain strong Jira hygiene. Assist security leadership in backlog prioritization and capacity negotiation with product owners.
Pipeline security engineering
:
Production experience building and maintaining security scanning stages in CI/CD pipelines. Must demonstrate pipelines they have built that run in production today, not proofs of concept. Git Hub Actions is required.
Appli…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).