Skip to content
NEXTMOVEFDE careers · United States

Principal Engineer, DevSecOps

AI summary of the role

The Principal Engineer, DevSecOps is the technical lead for Allegiant's DevSecOps program, owning security tooling, policies, and automation across CI/CD pipelines.

No longer in the current catalog. Last included 2026-09-09. Check the employer’s posting for availability.

What you’ll do

  • Lead the DevSecOps team (two engineers) in daily execution, weekly syncs, and PI planning.
  • Own and drive the DevSecOps roadmap across pipeline security, IaC policy enforcement, application security tooling, and cloud security posture management.
  • Architect and maintain security gates in GitHub Actions CI/CD pipelines.
  • Administer GitHub Advanced Security across the organization: CodeQL, secret scanning, Dependabot.

What you’ll bring

  • Minimum eight (8) years experience in information security.
  • Minimum eight (8) years supporting / implementing network security platforms & strategies.
  • Production experience building and maintaining security scanning stages in CI/CD pipelines (GitHub Actions required).
  • Hands-on administration of GitHub Advanced Security or equivalent in an organization with 50+ repositories.

Technologies

DevSecOps · GitHub Actions · GitHub Advanced Security · CodeQL · Checkov · Terraform · AWS · Palo Alto Prisma · Cortex Cloud · CNAPP · SIEM · SOAR

Source and classification

Internal deployment & tooling · Evidence for this classification:

Short Description The Principal Engineer, Information Security (DevSecOps) is the technical lead for Allegiant's DevSecOps program. This person owns the security tooling, policies, and automation that protect code, infrastructure, and cloud workloads as they move through CI/CD pipelines into production. This is not a generalist security role. The principal engineer must have production experience across four disciplines simultaneously: application security, pipeline engineering, cloud infrastructure, and infrastructure-as-code (IaC) governance. The role also requires working knowledge of securing agentic AI workflows, including MCP server governance, AI gateway configuration, and trust boundaries for tool-using AI systems. The role requires someone who has shipped security tooling that development teams actually adopted, not just evaluated or recommended. The principal engineer leads
More from the job description

Short Description The Principal Engineer, Information Security (DevSecOps) is the technical lead for Allegiant's DevSecOps program. This person owns the security tooling, policies, and automation that protect code, infrastructure, and cloud workloads as they move through CI/CD pipelines into production. This is not a generalist security role. The principal engineer must have production experience across four disciplines simultaneously: application security, pipeline engineering, cloud infrastructure, and infrastructure-as-code (IaC) governance. The role also requires working knowledge of securing agentic AI workflows, including MCP server governance, AI gateway configuration, and trust boundaries for tool-using AI systems. The role requires someone who has shipped security tooling that development teams actually adopted, not just evaluated or recommended. The principal engineer leads a team of two mid-level engineers, unblocks technical problems, reviews architecture decisions, and drives delivery against committed program objectives. This person reports to the Senior Manager of Information Security Engineering and works closely with DevOps, Full Stack Engineering, and Security Governance. Allegiant is modernizing its web applications, expanding into new customer channels, and integrating a recent acquisition. Each of these increases the volume of code and infrastructure flow [... source excerpt omitted ...] Fe Agile planning. Maintain strong Jira hygiene. Assist security leadership in backlog prioritization and capacity negotiation with product owners. Pipeline security engineering: Production experience building and maintaining security scanning stages in CI/CD pipelines. Must demonstrate pipelines they have built that run in production today, not proofs of concept. GitHub Actions is required. Application security tooling at scale: Hands-on administration of GitHub Advanced Security or equivalent (Snyk, Veracode, Checkmarx) in an organization with 50+ repositories. Must show evidence of driving developer adoption of scan results, not just enabling tools. Infrastructure-as-code polic [... source excerpt omitted ...] ng knowledge of AWS security constructs: Control Tower, IAM (including ABAC patterns), VPC architecture, Transit Gateway, and multi-account strategies. Must have operated these in production, not just designed them. CNAPP operations: Experience operating a cloud-native application protection platform (Palo Alto Cortex Cloud preferred, Prisma Cloud, Wiz, or Orca acceptable). Must describe onboarding workflows, policy tuning, and integration with engineering teams. Delivery track record: Candidates must provide specific examples of security tooling they shipped that was adopted by development teams. "Evaluated," "assessed," or "recommended" do not count. We need builders who finish.

How jobs are selected

Employer postings · Data from · Sources