Lead Information Security Engineer (Lead ISE)

Javen Technologies, Inc
United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Shift work
Job source

Tech stack

Agile Methodology Artificial Intelligence Amazon Web Services Cyber Security Continuous Integration Linux DevOps Github Identity and Access Management Runbook Software Engineering Test Execution Engine
+13 more
Software Organization Data Ingestion Large Language Models Software Security Model Validation Event Driven Architecture Containerization Restful APIs Terraform Splunk Jenkins Static Application Security Testing Vulnerability Analysis

Job description

The Lead Information Security Engineer (Lead ISE) will be responsible for delivering and supporting the enterprise security tools.

This role is specifically responsible for implementing, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability. The initial phase is build: deliver the scanner, evaluation harness, and CI/CD pipelines to an architecture defined with Principal Engineering. Once operational, the role shifts to run: patching, tuning, feature development, and sustained operational support. This position is one of four engineers providing rotating coverage for a 24/7 operational capability. Scheduled hours average 40 per week, and alert volume is expected to be low, so the majority of shift time is spent on engineering and feature work rather than active response. Finding triage and remediation ownership are out of scope for this role, 1. Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt/agent implementation, model invocation patterns, cost and token controls, and result normalization.

  1. Build and maintain the evaluation harness used to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
  2. Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
  3. Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health, coverage, and throughput.
  4. Engineer and implement well-architected solutions while adhering to software development best practices.
  5. Design, test, and implement solutions at the Story and Feature level within an established architecture.
  6. Contribute to the development and maintenance of standards, procedures, runbooks, and guidelines necessary to satisfy the Information Security department’s operations.
  7. Provide ongoing operational support, patching, and defect resolution for the deployed scanner after go-live.
  8. Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays. Scheduled hours average 40 per week.
  9. Monitor scanner health, pipeline execution, and alert queues during assigned shift; execute documented runbooks and escalate per established procedures.
  10. Perform structured shift handoff, including documentation of open issues, in-flight changes, and outstanding escalations.
  11. Maintain appropriate controls and documentation to ensure compliance with all company and regulatory requirements.
  12. Understand virtualization/containerization technologies.
  13. Other duties as assigned.

Requirements

  • 1+ year(s) of Gen AI related development
  • DevOps practices and tools (Jenkins, Github, CI/CD, Terraform)
  • Security, 1. 2+ years of related engineering experience, including hands-on information security or software development work. 2. Exposure to AWS Bedrock or equivalent hosted LLM platforms, including model invocation and guardrail configuration. 3. Working knowledge of Infrastructure as Code best practices and ability to build and modify Terraform modules. 4. Experience working within CI/CD pipelines, preferably Jenkins, integrated with GitHub. 5. Familiarity with application security concepts, common vulnerability classes, and SAST/SCA tooling behavior. 6. Able to communicate technical status, risks, and blockers clearly in writing and verbally to technical peers and leadership. 7. Willingness and availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays. 8. Able to work independently during off-hours shifts with limited direct supervision. 9. Eligible to work in the US without the need for sponsorship now or in the future.

Preferred knowledge, skills & abilities:

  1. Hands-on experience building on AWS, including IAM, ECS, and service-to-service authentication patterns.
  2. Hands-on experience with AWS Bedrock, including model selection and inference optimization.
  3. Experience with agentic or multi-step LLM workflows, including context management across large repositories.
  4. Experience with RESTful APIs and event-driven architectures.
  5. Splunk development experience, including data onboarding, search, and dashboarding.
  6. Experience with containerized workloads and Linux systems.
  7. Prior experience supporting a 24/7 operational environment, including shift handoff and runbook execution.
  8. Experience working in Agile methodologies and development.
  9. Prior experience in a regulated financial services environment.
  10. Industry standard certifications such as AWS Solutions Architect Associate, AWS Security Specialty, or CompTIA Security+.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all