Job Title: AI-focused Information Security Engineer / AI Security Developer
Duration: 12+ Months with possible extension
Location: 100% Remote
TECHNICAL SKILLS
Must Have: 1+ year(s) of Gen AI related development, DevOps practices and tools (Jenkins, Github, CI/CD, Terraform), Security
Nice To Have: , , ,
JOB SUMMARY
AI Developer Security Scanning
JOB DESCRIPTION
- The Information Security Engineer (ISE) will be responsible for defining, delivering, and supporting the enterprise security tools.
- This role is specifically responsible for building, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability. The initial phase is build: design and deliver the scanner, evaluation harness, and CI/CD pipelines. Once operational, the role shifts to run: patching, tuning, feature development, and sustained operational support. Finding triage and remediation ownership are out of scope for this role.
ESSENTIAL DUTIES & RESPONSIBILITIES:
- Serve as a security engineer/consultant on cloud projects.
- Build and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt/agent design, model invocation patterns, cost and token controls, and result normalization.
- Develop and maintain the evaluation harness used to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
- Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
- Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health, coverage, and throughput.
- Engineer and implement well-architected solutions while adhering to software development best practices.
- Advise Principal Engineers and Product Owners on operations and evolution of their product.
- Design, test, and implement solutions at the Feature level.
- Support the Bank's operational information security responsibilities, including the development and maintenance of standards, procedures, and guidelines necessary to satisfy the Information Security department's operations.
- Provide ongoing operational support, patching, and defect resolution for the deployed scanner after go-live.
- Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays. Scheduled hours average 40 per week.
- Maintain appropriate controls and documentation to ensure compliance with all company and regulatory requirements.
- Understand virtualization/containerization technologies.
- Participate in operational on-call rotation within normal working hours (not eligible for overtime).
- Other duties as assigned.
REQUIRED KNOWLEDGE, SKILLS & ABILITIES:
- 4+ years of related engineering experience, including hands-on information security or software development work.
- Hands-on experience with AWS Bedrock or equivalent hosted LLM platforms, including model selection, inference optimization, and guardrail configuration.
- Demonstrated understanding of Infrastructure as Code best practices and strong experience building Terraform modules.
- Experience building and maintaining CI/CD pipelines, preferably Jenkins, integrated with GitHub.
- Working knowledge of application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
- Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language appropriate for each group.
- Eligible to work in the US without the need for sponsorship now or in the future.
PREFERRED KNOWLEDGE, SKILLS & ABILITIES:
- Demonstrated experience building on AWS, including IAM, ECS, and service-to-service authentication patterns.
- Experience with agentic or multi-step LLM workflows, including context management across large repositories.
- Experience with RESTful APIs and event-driven architectures.
- Splunk development experience, including data onboarding, search, and dashboarding.
- Experience with containerized workloads and Linux systems.
- Experience working in Agile methodologies and development.
- Prior experience in a regulated financial services environment.
Industry standard certifications such as AWS Security Specialty, AWS Solutions Architect Associate, CompTIA Security+, ISC2 CISSP, or SANS.