Information Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
The Senior Information Security Engineer (Sr ISE) will be responsible for supporting and maintaining the enterprise security tools. This role is specifically responsible for the day-to-day operation of an LLM-based code vulnerability detection and reporting capability. The primary focus is run: monitoring, executing runbooks, patching, and resolving defects in the deployed scanner and its pipelines. The role contributes to build and feature work under direction from Lead and Principal Engineers, but is not responsible for solution design. This position is one of four engineers providing rotating coverage for a 24/7 operational capability. Scheduled hours average 40 per week, and alert volume is expected to be low, so shift time not spent on active response is directed toward maintenance, documentation, and assigned engineering tasks. Finding triage and remediation ownership are out of scope for this role., * Operate and monitor an LLM-based code vulnerability detection capability on AWS Bedrock, including scanner health, job execution, model invocation errors, and token and cost consumption against defined thresholds.
- Monitor scanning pipelines integrated with GitHub and Jenkins running on ECS; investigate and resolve failed jobs, queue backlogs, and environment issues.
- Execute documented runbooks during assigned shift and escalate to Lead or Principal Engineering per established procedures.
- Perform structured shift handoff, including documentation of open issues, in-flight changes, and outstanding escalations.
- Apply patches, dependency updates, and configuration changes through established change management processes.
- Monitor Splunk dashboards and alerts for scanner health, coverage, and throughput; report anomalies and recurring failure patterns.
- Execute the evaluation harness on a defined cadence and report results; identify regressions in detection performance.
- Implement assigned changes at the Story level within an established architecture, including Terraform and pipeline configuration updates.
- Maintain and improve runbooks, operational procedures, and support documentation based on observed incidents.
- Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays. Scheduled hours average 40 per week.
- Maintain appropriate controls and documentation to ensure compliance with all company and regulatory requirements.
- Understand virtualization/containerization technologies.
- Other duties as assigned.
Requirements
- 1+ years of related engineering or technical operations experience, including hands-on information security, infrastructure, or software support work.
- Working knowledge of AWS fundamentals, including console and CLI navigation, IAM basics, and CloudWatch.
- Ability to read and troubleshoot CI/CD pipeline failures, preferably Jenkins, integrated with GitHub.
- Ability to read and make guided modifications to Terraform and scripting in Python or equivalent.
- Basic understanding of application security concepts and common vulnerability classes.
- Ability to follow documented procedures precisely and escalate appropriately when procedures do not cover the situation.
- Able to communicate operational status, incidents, and handoff details clearly in writing.
- Willingness and availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays.
- Able to work independently during off-hours shifts with limited direct supervision.
Preferred Skills:
- Prior experience supporting a 24/7 operational environment, including shift handoff and runbook execution.
- Exposure to AWS Bedrock or equivalent hosted LLM platforms.
- Hands-on experience with ECS or other container orchestration platforms.
- Splunk experience, including search and dashboard use.
- Experience with Linux systems administration.
- Experience working with ServiceNow or equivalent incident and change management tooling.
- Experience working in Agile methodologies.
- Prior experience in a regulated financial services environment.
- Industry standard certifications such as AWS Cloud Practitioner, AWS Solutions Architect Associate, or CompTIA Security+.
About the company
By applying for a job with SGA, you agree to allow SGA to process your application for this and future opportunities in accordance with our Privacy Policy. Also, to ensure timely processing, you agree to be contacted by our AI recruiter via email, text, or phone. Message frequency varies and data rates may apply, but you can reply STOP to any SMS message to opt-out of texts and may contact SGA at to opt-out of AI communications. The choice not to engage with AI will not adversely impact your consideration for placement. AI is not used to make any hiring determinations.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let’s work better together, we mean it. You’ll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Understanding and Mitigating Common Web Vulnerabilities
Is Software Engineering Over-Saturated?