
Lead Information Security Engineer
Eliassen Group
Visa & sponsorship
- The posting says it will not sponsor a visa for this role.
Job description
Description
Remote
Our client seeks a Lead Information Security Engineer to implement, operate, and improve an LLM-based code vulnerability detection and reporting capability. The role delivers the scanner, evaluation harness, and CI/CD pipelines, then transitions to ongoing operations including patching, tuning, feature development, and support. The position participates in a four-person rotating 24/7 coverage schedule with most time dedicated to engineering and feature work. Triage and remediation ownership are out of scope.
We can facilitate w2 and corp-to-corp consultants. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $60.00 to $70.00/hr. w2
Responsibilities
-
Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt and agent implementation, model invocation patterns, cost and token controls, and result normalization.
-
Build and maintain the evaluation harness to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
-
Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
-
Deliver findings and operational telemetry into Splunk, and build dashboards and alerting for scanner health, coverage, and throughput.
-
Engineer and implement well-architected solutions aligned to software development best practices.
-
Design, test, and implement solutions at the Story and Feature level within an established architecture.
-
Contribute to standards, procedures, runbooks, and guidelines for Information Security operations.
-
Provide ongoing operational support, patching, and defect resolution after go-live.
-
Participate in a four-person rotating 24/7 shift schedule, including nights, weekends, and holidays, averaging 40 hours per week.
-
Monitor scanner health, pipeline execution, and alert queues during assigned shifts. Execute documented runbooks and escalate per procedures.
-
Perform structured shift handoffs, documenting open issues, in-flight changes, and outstanding escalations.
-
Maintain controls and documentation to ensure compliance with company and regulatory requirements.
-
Understand virtualization and containerization technologies.
-
Perform other duties as assigned.
Experience Requirements
-
2+ years of related engineering experience, including hands-on information security or software development work.
-
Exposure to AWS Bedrock or equivalent hosted LLM platforms, including model invocation and guardrail configuration.
-
Working knowledge of Infrastructure as Code and ability to build and modify Terraform modules.
-
Experience with CI/CD pipelines, preferably Jenkins, integrated with GitHub.
-
Familiarity with application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
-
Clear written and verbal communication of technical status, risks, and blockers to peers and leadership.
-
Willingness and availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays.
-
Ability to work independently during off-hours shifts with limited direct supervision.
-
Eligible to work in the US without sponsorship now or in the future.
-
Preferred: Hands-on AWS experience including IAM, ECS, and service-to-service authentication. AWS Bedrock model selection and inference optimization.
-
Preferred: Agentic or multi-step LLM workflows, including context management across large repositories.
-
Preferred: RESTful APIs and event-driven architectures.
-
Preferred: Splunk development for data onboarding, search, and dashboarding.
-
Preferred: Containerized workloads and Linux systems.
-
Preferred: Prior 24/7 operational support experience, shift handoff, and runbook execution.
-
Preferred: Agile methodologies and development practices.
-
Preferred: Regulated financial services environment experience.
-
Preferred: Certifications such as AWS Solutions Architect Associate, AWS Security Specialty, or CompTIA Security+.
Education Requirements