
Information Security Engineer IV (NO C2C)
OpTech
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
Job description
JOB DESCRIPTION
- The Information Security Engineer (ISE) will be responsible for defining, delivering, and supporting the enterprise security tools.
This role is specifically responsible for building, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability. The initial phase is build: design and deliver the scanner, evaluation harness, and CI/CD pipelines. Once operational, the role shifts to run: patching, tuning, feature development, and sustained operational support. Finding triage and remediation ownership are out of scope for this role.
ESSENTIAL DUTIES & RESPONSIBILITIES:
-
Serve as a security engineer/consultant on cloud projects.
-
Build and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt/agent design, model invocation patterns, cost and token controls, and result normalization.
-
Develop and maintain the evaluation harness used to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
-
Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
-
Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health, coverage, and throughput.
-
Engineer and implement well-architected solutions while adhering to software development best practices.
-
Advise Principal Engineers and Product Owners on operations and evolution of their product.
-
Design, test, and implement solutions at the Feature level.
-
Support the Bank's operational information security responsibilities, including the development and maintenance of standards, procedures, and guidelines necessary to satisfy the Information Security department's operations.
-
Provide ongoing operational support, patching, and defect resolution for the deployed scanner after go-live.
-
Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays. Scheduled hours average 40 per week.
-
Maintain appropriate controls and documentation to ensure compliance with all company and regulatory requirements.
-
Understand virtualization/containerization technologies.
-
Participate in operational on-call rotation within normal working hours (not eligible for overtime).
-
Other duties as assigned.
SUPERVISORY RESPONSIBILITIES:
None.
REQUIRED KNOWLEDGE, SKILLS & ABILITIES:
-
4+ years of related engineering experience, including hands-on information security or software development work.
-
Hands-on experience with AWS Bedrock or equivalent hosted LLM platforms, including model selection, inference optimization, and guardrail configuration.
-
Demonstrated understanding of Infrastructure as Code best practices and strong experience building Terraform modules.
-
Experience building and maintaining CI/CD pipelines, preferably Jenkins, integrated with GitHub.
-
Working knowledge of application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
-
Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language appropriate for each group.
-
Eligible to work in the US without the need for sponsorship now or in the future.
PREFERRED KNOWLEDGE, SKILLS & ABILITIES:
-
Demonstrated experience building on AWS, including IAM, ECS, and service-to-service authentication patterns.
-
Experience with agentic or multi-step LLM workflows, including context management across large repositories.
-
Experience with RESTful APIs and event-driven architectures.
-
Splunk development experience, including data onboarding, search, and dashboarding.
-
Experience with containerized workloads and Linux systems.
-
Experience working in Agile methodologies and development.
-
Prior experience in a regulated financial services environment.
-
Industry standard certifications such as AWS Security Specialty, AWS Solutions Architect Associate, CompTIA Security+, ISC2 CISSP, or SANS.