Role: Information Security Engineer IV
Location: Remote
Role Summary
Looking for an Information Security Engineer with strong GenAI/LLM, AWS, DevOps, and application security experience to build and support an LLM-based code vulnerability detection and reporting platform.
Must Have Skills
1+ year GenAI/LLM development experience
AWS Bedrock or equivalent hosted LLM platform
Security / Application Security
Terraform / Infrastructure as Code
Jenkins & GitHub
CI/CD pipelines
SAST/SCA and common application vulnerabilities
Strong software development and engineering experience
Experience with cloud/security engineering
Nice to Have
AWS IAM
AWS ECS / Fargate
Python
Splunk
REST APIs
Event-driven architecture
Agentic / multi-step LLM workflows
Docker / containerization
Linux
Agile
Financial services experience
AWS Security Specialty / Solutions Architect / Security+ / CISSP / SANS
Key Responsibilities
Build an LLM-based vulnerability scanner using AWS Bedrock
Design prompts, agents, model invocation, guardrails, and token/cost controls
Develop an evaluation framework to measure scanner accuracy
Build CI/CD pipelines using Jenkins, GitHub, Terraform, and ECS
Integrate security findings and telemetry with Splunk
Support, patch, tune, and enhance the scanner after deployment
Work with security, engineering, and product teams
Participate in a 24/7 rotating four-person shift schedule
Critical Screening Questions
1. How many years of GenAI/LLM development experience do you have?
2. Have you worked hands-on with AWS Bedrock? What did you build?
3. Describe your experience building LLM-based security or vulnerability scanning solutions.
4. How strong is your Terraform experience?
5. Have you built Jenkins/GitHub CI/CD pipelines?
6. What experience do you have with SAST, SCA, and application vulnerabilities?
7. Have you worked with AWS ECS/Fargate?
8. What is your experience with Splunk?