3 months ago
St. Paul, MN, USA or Las Vegas, NV, USAStaff+
Base Salary
$153k - $195k/yr
Responsibilities
- Lead the two-engineer DevSecOps team through daily execution, planning, mentoring, technical reviews, and blocker removal.
- Own the DevSecOps roadmap covering pipeline security, IaC policy enforcement, application security tooling, cloud security posture management, and agentic AI security governance.
- Build and maintain production security scanning stages and enforcement gates in GitHub Actions pipelines.
- Administer GitHub Advanced Security, including CodeQL query suites, secret scanning, Dependabot, and developer adoption campaigns.
- Author and enforce custom Checkov policies for Terraform and drive organization-wide golden policy adoption.
- Operate CNAPP tooling for cloud security posture, image scanning, and application security integration.
- Manage Terraform-based security infrastructure across multi-account AWS environments using Control Tower, IAM, VPC, and Transit Gateway.
- Integrate security tooling outputs with SIEM and SOAR platforms for alerting, triage, and automated response.
- Generate compliance evidence for PCI-DSS, NIST, and CIS controls and assess acquired technology stacks against security standards.
- Define and maintain security controls for agentic AI tooling, including MCP registries, AI gateway configurations, trust policies, and tool-use authorization.
- Document architecture decisions, security policies, and operational runbooks while supporting SAFe planning and Jira hygiene.
Requirements
- At least eight years of experience in information security.
- At least eight years of experience supporting or implementing network security platforms and strategies.
- Bachelor’s degree or equivalent experience.
- Production experience building and maintaining security scanning stages in CI/CD pipelines; GitHub Actions is required.
- Hands-on administration of GitHub Advanced Security or equivalent in an organization with 50 or more repositories, with evidence of developer adoption.
- Experience authoring and enforcing custom Checkov, Bridgecrew, tfsec, or Sentinel policies against Terraform codebases.
- Deep production knowledge of AWS Control Tower, IAM including ABAC patterns, VPC architecture, Transit Gateway, and multi-account strategies.
- Experience operating a CNAPP platform such as Palo Alto Cortex Cloud, Prisma Cloud, Wiz, or Orca.
- Demonstrated delivery of security tooling that development teams adopted in production.
- Experience securing agentic AI workflows, including MCP server governance, AI gateway configuration, prompt-injection mitigation, or tool-use authorization policies.
- Ability to lead or mentor engineers through pairing, documentation, direct feedback, and technical guidance.
- Technical certifications are optional; CISSP is optional.
- Must be authorized to work in the United States and pass a criminal background check.
Benefits
- Visa sponsorship is not available.
- The role may require work during various shifts or days in a 24-hour situation, some travel, and reporting to the assigned work location during declared emergencies unless prohibited by law or order.
- Reasonable accommodations may be made for individuals with disabilities.
- Allegiant is an equal opportunity employer and welcomes veterans and individuals with disabilities.
