$153,000 – $194,600
Listed on Allegiant’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
Lead a team of engineers building and maintaining security tooling across CI/CD pipelines, cloud infrastructure, and infrastructure-as-code for a major airline modernizing its application portfolio. This role suits experienced security engineers who have shipped production systems that development teams actually use, with demonstrated expertise spanning application security, pipeline engineering, cloud platforms, and IaC governance.
Our summary, not Allegiant’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- 8+ years in information security
- 8+ years implementing network security platforms and strategies
- Production experience building and maintaining security scanning in CI/CD pipelines with GitHub Actions
- Hands-on administration of GitHub Advanced Security or equivalent for organizations with 50+ repositories
- Written and enforced custom Checkov policies or equivalent against Terraform codebases
- Deep working knowledge of AWS security constructs including Control Tower, IAM, VPC, and Transit Gateway
- Experience operating a CNAPP platform such as Palo Alto Cortex Cloud, Prisma Cloud, Wiz, or Orca
- Demonstrated delivery of security tooling adopted by development teams in production
- Lead or mentor experience with 2+ engineers
- Communication and mentorship ability to coach junior and mid-level engineers
Nice to have
- Production experience across all four domains: application security, pipeline engineering, cloud infrastructure security, and IaC governance
- Administered GitHub Advanced Security with active developer adoption metrics
- Authored Checkov policies that enforced specific compliance or security outcomes in production
- Operated a CNAPP platform including onboarding, policy configuration, and integration with engineering workflows
- Integrated security scan outputs into a SIEM and SOAR platform
- Experience with Cloud Custodian or similar cloud governance automation
- Gathered compliance evidence from automated tooling for PCI-DSS, NIST, or CIS audits
- Hands-on experience securing agentic AI systems with public artifacts demonstrating this work
- References or artifacts from security tooling adopted by development teams