Information Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+9 more
Job description
Software Guidance & Assistance, Inc., (SGA), is searching for a Information Security Engineer for a Remote contract position with one of our premier financial services clients in Ohio.
The Information Security Engineer (ISE) will be responsible for defining, delivering, and supporting the enterprise security tools. This role is specifically responsible for building, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability. The initial phase is build: design and deliver the scanner, evaluation harness, and CI/CD pipelines. Once operational, the role shifts to run: patching, tuning, feature development, and sustained operational support. Finding triage and remediation ownership are out of scope for this role., * Serve as a security engineer/consultant on cloud projects.
- Build and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt/agent design, model invocation patterns, cost and token controls, and result normalization.
- Develop and maintain the evaluation harness used to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
- Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
- Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health, coverage, and throughput.
- Engineer and implement well-architected solutions while adhering to software development best practices.
- Advise Principal Engineers and Product Owners on operations and evolution of their product.
- Design, test, and implement solutions at the Feature level.
- Support the Bank’s operational information security responsibilities, including the development and maintenance of standards, procedures, and guidelines necessary to satisfy the Information Security department’s operations.
- Provide ongoing operational support, patching, and defect resolution for the deployed scanner after go-live.
- Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays. Scheduled hours average 40 per week.
- Maintain appropriate controls and documentation to ensure compliance with all company and regulatory requirements.
- Understand virtualization/containerization technologies.
- Participate in operational on-call rotation within normal working hours (not eligible for overtime).
Requirements
- 4+ years of related engineering experience, including hands-on information security or software development work.
- Hands-on experience with AWS Bedrock or equivalent hosted LLM platforms, including model selection, inference optimization, and guardrail configuration.
- Demonstrated understanding of Infrastructure as Code best practices and strong experience building Terraform modules.
- Experience building and maintaining CI/CD pipelines, preferably Jenkins, integrated with GitHub.
- Working knowledge of application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
- Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language appropriate for each group.
- Eligible to work in the US without the need for sponsorship now or in the future.
Preferred Skills:
- Demonstrated experience building on AWS, including IAM, ECS, and service-to-service authentication patterns.
- Experience with agentic or multi-step LLM workflows, including context management across large repositories.
- Experience with RESTful APIs and event-driven architectures.
- Splunk development experience, including data onboarding, search, and dashboarding.
- Experience with containerized workloads and Linux systems.
- Experience working in Agile methodologies and development.
- Prior experience in a regulated financial services environment.
- Industry standard certifications such as AWS Security Specialty, AWS Solutions Architect Associate, CompTIA Security+, ISC2 CISSP, or SANS.
About the company
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let’s work better together, we mean it. You’ll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Is Software Engineering Over-Saturated?
Dev Digest 138 - Are you secure about this?