Lead Information Security Engineer

Everforth Apex
United States
6 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Artificial Intelligence Amazon Web Services CompTIA Security+ Cyber Security Continuous Integration Linux DevOps Github Identity and Access Management Python (Programming Language) Software Engineering
+13 more
Software Organization Large Language Models Software Security AWS ECS Event Driven Architecture Containerization AWS Fargate Restful APIs Terraform Splunk Jenkins Static Application Security Testing Vulnerability Analysis

Job description

This position is for a Lead Information Security Engineer responsible for delivering and supporting enterprise security tools. The role focuses on implementing, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability. The initial phase involves building the scanner, evaluation harness, and CI/CD pipelines, followed by operational support, including patching, tuning, and feature development., * Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock.

  • Build and maintain the evaluation harness to measure scanner quality and report on detection performance.
  • Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
  • Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health and throughput.
  • Engineer, design, test, and implement well-architected solutions while adhering to software development best practices.
  • Contribute to the development and maintenance of standards, procedures, and runbooks for Information Security operations.
  • Provide ongoing operational support, patching, and defect resolution for the deployed scanner.
  • Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays.
  • Monitor scanner health, pipeline execution, and alert queues during assigned shifts, executing runbooks and escalating as needed.
  • Perform structured shift handoffs, documenting open issues and in-flight changes.
  • Maintain controls and documentation to ensure compliance with all company and regulatory requirements.

Requirements

  • 2+ years of related engineering experience, including hands-on information security or software development work.
  • 1+ year(s) of Gen AI related development.
  • Experience with DevOps practices and tools such as Jenkins, GitHub, CI/CD, and Terraform.

Technical Skills:

  • Exposure to AWS Bedrock or equivalent hosted LLM platforms.
  • Working knowledge of Infrastructure as Code best practices and Terraform.
  • Experience working within CI/CD pipelines, preferably Jenkins, integrated with GitHub.
  • Familiarity with application security concepts and SAST/SCA tooling behavior.
  • Understanding of virtualization and containerization technologies.

General Skills:

  • Ability to communicate technical status, risks, and blockers clearly.
  • Willingness and availability to work an assigned shift within a rotating 24/7 schedule.
  • Ability to work independently during off-hours shifts.
  • Eligible to work in the US without the need for sponsorship now or in the future.

Preferred Qualifications

  • Hands-on experience building on AWS, including IAM, ECS, and AWS ECS Fargate.
  • Hands-on experience with Amazon Bedrock, including model selection and inference optimization.
  • Experience with agentic or multi-step LLM workflows.
  • Experience with RESTful APIs and event-driven architectures.
  • Splunk development experience.
  • Experience with containerized workloads, Linux systems, and Python.
  • Prior experience supporting a 24/7 operational environment.
  • Experience working in Agile methodologies.
  • Prior experience in a regulated financial services environment.
  • Industry standard certifications such as AWS Solutions Architect Associate, AWS Security Specialty, or CompTIA Security+.

About the company

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all