Principal Engineer, DevSecOps
Allegiantair
| Company | Allegiantair |
| Category | Engineering |
| Location | Las Vegas |
| Remote | On-site (inferred) |
| Employment | Full-time |
| Level | Lead |
| Salary | USD 153k–195k |
| Posted | 26 May 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (lever) |
Description
Short Description
The Principal Engineer, Information Security (DevSecOps) is the technical lead for Allegiant's DevSecOps program. This person owns the security tooling, policies, and automation that protect code, infrastructure, and cloud workloads as they move through CI/CD pipelines into production.
This is not a generalist security role. The principal engineer must have production experience across four disciplines simultaneously: application security, pipeline engineering, cloud infrastructure, and infrastructure-as-code (IaC) governance. The role also requires working knowledge of securing agentic AI workflows, including MCP server governance, AI gateway configuration, and trust boundaries for tool-using AI systems. The role requires someone who has shipped security tooling that development teams actually adopted, not just evaluated or recommended.
The principal engineer leads a team of two mid-level engineers, unblocks technical problems, reviews architecture decisions, and drives delivery against committed program objectives. This person reports to the Senior Manager of Information Security Engineering and works closely with DevOps, Full Stack Engineering, and Security Governance. Allegiant is modernizing its web applications, expanding into new customer channels, and integrating a recent acquisition. Each of these increases the volume of code and infrastructure flowing through pipelines.
This role ensures security keeps pace with that velocity. This role prepares the principal engineer for future promotion tracks including Architect I and Manager I.
Summary
DevSecOps Principal Engineer Key Duties:
• Proven and demonstrable ability to lead at least two other team members in an official capacity towards specific DevSecOps outcomes.
• Lead the DevSecOps team (two engineers) in daily execution, weekly syncs, and PI planning. Ensure stories are accurate, scoped, and deliverable.
• Own and drive the DevSecOps roadmap across pipeline security, IaC policy enforcement, application security tooling, and cloud security posture management.
• Embedding threat modeling into pipelines and workflows to provide real-time analysis of architectural changes in products.
• Architect and maintain security gates in GitHub Actions CI/CD pipelines. Define when and how scans run, what blocks a merge, and how results route to developers.
• Administer GitHub Advanced Security across the organization: CodeQL query suites, secret scanning policies, Dependabot configuration, and developer-facing campaign management.
• Author and deploy Checkov custom policies for Terraform IaC scanning. Drive golden policy adoption from current 25% pipeline coverage toward 75%+ with hard-fail enforcement.
• Operate and configure Palo Alto Prisma or Cortex (CNAPP) for cloud security posture, image scanning, and AppSec integration.
• Manage Terraform-based infrastructure security across multi-account AWS environments using Control Tower, IAM, VPC, and Transit Gateway.
• Integrate security tooling outputs into SIEM and SOAR for alerting, triage, and response workflows.
• Mentor two mid-level engineers. Identify skills gaps, provide hands-on training, and review their work.
• Collaborate with Security Governance to produce compliance evidence for PCI-DSS, NIST, and CIS controls derived from DevSecOps tooling.
• Support acquisition security assessments by evaluating incoming technology stacks against Allegiant's IaC and pipeline security standards.
• Define and enforce security governance for agentic AI tooling, including MCP server registries, gateway configurations, and trust policies for AI-to-tool interactions.
• Document architecture decisions, policy rationale, and runbooks. Maintain documentation quality standards across the DevSecOps team.
• Participate in SAFe Agile planning. Maintain strong Jira hygiene. Assist sec