Principal Engineer, DevSecOps

AllegiantLas Vegas, NV
Onsite

About The Position

The Principal Engineer, Information Security (DevSecOps) is the technical lead for Allegiant's DevSecOps program. This person owns the security tooling, policies, and automation that protect code, infrastructure, and cloud workloads as they move through CI/CD pipelines into production. This is not a generalist security role. The principal engineer must have production experience across four disciplines simultaneously: application security, pipeline engineering, cloud infrastructure, and infrastructure-as-code (IaC) governance. The role also requires working knowledge of securing agentic AI workflows, including MCP server governance, AI gateway configuration, and trust boundaries for tool-using AI systems. The role requires someone who has shipped security tooling that development teams actually adopted, not just evaluated or recommended. The principal engineer leads a team of two mid-level engineers, unblocks technical problems, reviews architecture decisions, and drives delivery against committed program objectives. This person reports to the Senior Manager of Information Security Engineering and works closely with DevOps, Full Stack Engineering, and Security Governance. Allegiant is modernizing its web applications, expanding into new customer channels, and integrating a recent acquisition. Each of these increases the volume of code and infrastructure flowing through pipelines. This role ensures security keeps pace with that velocity. This role prepares the principal engineer for future promotion tracks including Architect I and Manager I.

Requirements

  • Production experience building and maintaining security scanning stages in CI/CD pipelines. Must demonstrate pipelines they have built that run in production today, not proofs of concept. GitHub Actions is required.
  • Hands-on administration of GitHub Advanced Security or equivalent (Snyk, Veracode, Checkmarx) in an organization with 50+ repositories. Must show evidence of driving developer adoption of scan results, not just enabling tools.
  • Experience writing and enforcing custom Checkov policies (or Bridgecrew, tfsec, Sentinel) against Terraform codebases. Must be able to describe policies they authored and the compliance or security outcomes those policies enforced.
  • Deep working knowledge of AWS security constructs: Control Tower, IAM (including ABAC patterns), VPC architecture, Transit Gateway, and multi-account strategies. Must have operated these in production, not just designed them.
  • Experience operating a cloud-native application protection platform (Palo Alto Cortex Cloud preferred, Prisma Cloud, Wiz, or Orca acceptable). Must describe onboarding workflows, policy tuning, and integration with engineering teams.
  • Candidates must provide specific examples of security tooling they shipped that was adopted by development teams. "Evaluated," "assessed," or "recommended" do not count. We need builders who finish.
  • Demonstrated experience securing agentic AI workflows: MCP server trust boundaries, AI gateway configuration, prompt injection mitigation, or tool-use authorization policies. Candidates should be able to point to public work (GitHub repositories, blog posts, conference talks, or open-source contributions) showing hands-on engagement with AI security, not just awareness of the topic.
  • Able to coach junior and mid-level engineers through hands-on pairing, clear documentation, and direct feedback. Comfortable presenting architecture decisions to security leadership and engineering stakeholders.
  • Combination of Education and Experience will be considered.
  • Must be authorized to work in the US as per the Immigration Act of 1986.
  • Must pass a Criminal Background Check.
  • Bachelor’s Degree or equivalent experience.
  • Technical certifications or equivalents, CISSP is optional.
  • Minimum eight (8) years experience in information security.
  • Minimum eight (8) years supporting / implementing network security platforms & strategies.

Nice To Haves

  • Has production experience across all four domains: application security, pipeline engineering, cloud infrastructure security, and IaC governance. Can demonstrate work in each, not just one or two.
  • Has administered GitHub Advanced Security (CodeQL, secret scanning, Dependabot) for an organization with active developer adoption metrics.
  • Has authored custom Checkov or equivalent IaC policies that enforced specific compliance or security outcomes in production pipelines.
  • Has operated a CNAPP platform (Palo Alto Cortex Cloud, Prisma Cloud, Wiz, or Orca) including onboarding, policy configuration, and integration with engineering workflows.
  • Has integrated security scan outputs into a SIEM and SOAR (Cortex XSOAR preferred) platform.
  • Has experience with Cloud Custodian or similar cloud governance automation.
  • Has gathered compliance evidence from automated tooling for PCI-DSS, NIST, or CIS audits.
  • Has led or mentored a small engineering team (2-5 engineers).
  • Has hands-on experience securing agentic AI systems: MCP server configuration, AI gateway trust policies, tool-use authorization, or prompt injection controls. Can point to public artifacts (GitHub repos, blog posts, talks, open-source work) demonstrating this experience.
  • Can provide references or artifacts demonstrating security tooling adopted by development teams in production.

Responsibilities

  • Provide technical leadership to the DevSecOps team daily and during PI planning.
  • Lead the DevSecOps team in weekly syncs to track program progress, remove blockers, and adjust priorities.
  • Advises the IT organization towards adoption of standards and influences security security culture—setting the tone and expectations for secure SDLC.
  • Own GitHub Advanced Security administration: manage CodeQL query suites, configure secret scanning policies, tune Dependabot alerts, and run developer adoption campaigns.
  • Build, maintain, and enforce security scanning stages in GitHub Actions pipelines across the organization.
  • Author custom Checkov policies for Terraform IaC. Drive golden policy deployment across all pipelines toward hard-fail enforcement.
  • Operate and configure Cortex Cloud (CNAPP) for cloud workload protection, image scanning, and application security posture.
  • Manage Terraform-based security infrastructure across multi-account AWS environments (Control Tower, IAM, VPC, Transit Gateway).
  • Integrate DevSecOps tooling outputs into SIEM and Cortex XSOAR (SOAR) for detection, alerting, and automated response.
  • Collaborate with Security Governance to generate and validate compliance evidence from automated tooling for PCI-DSS, NIST, and CIS.
  • Evaluate incoming technology stacks from acquisitions against Allegiant's pipeline and IaC security standards.
  • Document architecture decisions, security policies, and operational runbooks. Maintain team documentation standards.
  • Identify skills gaps on the DevSecOps team. Provide training, pair on complex work, and review output from junior and mid-level engineers.
  • Work with DevOps and Full Stack Engineering to ensure security gates are adopted, not circumvented. Measure and report on developer adoption.
  • Maintain SAFe Agile practices. Keep Jira hygiene current. Assist security leadership with story sizing, capacity planning, and backlog negotiation.
  • Promote awareness of DevSecOps program objectives during PI planning and cross-team syncs.
  • Recommend and implement efficiencies for security alerting, triage workflows, and operational intake.
  • Define and maintain security controls for agentic AI tooling: MCP trusted server registries, gateway configurations, tool-use authorization policies, and usage standards.
  • Troubleshoot and resolve escalated security tooling issues across pipelines, cloud infrastructure, and application scanning.
  • Support the security manager in long-range planning, roadmap development, and team growth strategy.
  • Other duties as assigned.

Benefits

  • Visa Sponsorship Available
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service