Job Duties
• Provide technical leadership to the DevSecOps team daily and during PI planning.
• Lead the DevSecOps team in weekly syncs to track program progress, remove blockers, and adjust priorities.
• Advises the IT organization towards adoption of standards and influences security security culture—setting the tone and expectations for secure SDLC.
• Own GitHub Advanced Security administration: manage CodeQL query suites, configure secret scanning policies, tune Dependabot alerts, and run developer adoption campaigns.
• Build, maintain, and enforce security scanning stages in GitHub Actions pipelines across the organization.
• Author custom Checkov policies for Terraform IaC. Drive golden policy deployment across all pipelines toward hard-fail enforcement.
• Operate and configure Cortex Cloud (CNAPP) for cloud workload protection, image scanning, and application security posture.
• Manage Terraform-based security infrastructure across multi-account AWS environments (Control Tower, IAM, VPC, Transit Gateway).
• Integrate DevSecOps tooling outputs into SIEM and Cortex XSOAR (SOAR) for detection, alerting, and automated response.
• Collaborate with Security Governance to generate and validate compliance evidence from automated tooling for PCI-DSS, NIST, and CIS.
• Evaluate incoming technology stacks from acquisitions against Allegiant’s pipeline and IaC security standards.
• Document architecture decisions, security policies, and operational runbooks. Maintain team documentation standards.
• Identify skills gaps on the DevSecOps team. Provide training, pair on complex work, and review output from junior and mid-level engineers.
• Work with DevOps and Full Stack Engineering to ensure security gates are adopted, not circumvented. Measure and report on developer adoption.
• Maintain SAFe Agile practices. Keep Jira hygiene current. Assist security leadership with story sizing, capacity planning, and backlog negotiation.
• Promote awareness of DevSecOps program objectives during PI planning and cross-team syncs.
• Recommend and implement efficiencies for security alerting, triage workflows, and operational intake.
• Define and maintain security controls for agentic AI tooling: MCP trusted server registries, gateway configurations, tool-use authorization policies, and usage standards.
• Troubleshoot and resolve escalated security tooling issues across pipelines, cloud infrastructure, and application scanning.
• Support the security manager in long-range planning, roadmap development, and team growth strategy.
• Other duties as assigned.