Information Security Engineer

Eliassen Group
United States
1 day ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$91,520.0 - $112,320.0
Working hours
Shift work
Job source

Tech stack

Agile Methodology Amazon Web Services CompTIA Security+ Cyber Security Continuous Integration Github Identity and Access Management Python (Programming Language) Linux System Administration Scripting Large Language Models Software Security
+8 more
Containerization Kubernetes Cloudwatch Terraform Splunk Jenkins Servicenow Vulnerability Analysis

Job description

Our client seeks a Senior Information Security Engineer to operate and maintain an LLM-based code vulnerability detection and reporting capability. The role will focus on day-to-day run activities, including monitoring, executing runbooks, patching, and resolving defects in the deployed scanner and its pipelines. The position will contribute to build and feature work under direction from Lead and Principal Engineers. This role participates in a four-person rotation to support a 24/7 operational capability, with scheduled hours averaging 40 per week. Finding triage and remediation ownership are out of scope., * Operate and monitor an LLM-based code vulnerability detection capability on AWS Bedrock, including scanner health, job execution, model invocation errors, and token and cost consumption against defined thresholds.

  • Monitor scanning pipelines integrated with GitHub and Jenkins running on ECS and resolve failed jobs, queue backlogs, and environment issues.
  • Execute documented runbooks during assigned shift and escalate to Lead or Principal Engineering per established procedures.
  • Perform structured shift handoff with documentation of open issues, in-flight changes, and outstanding escalations.
  • Apply patches, dependency updates, and configuration changes through established change management processes.
  • Monitor Splunk dashboards and alerts for scanner health, coverage, and throughput and report anomalies and recurring failure patterns.
  • Execute the evaluation harness on a defined cadence and report results while identifying regressions in detection performance.
  • Implement assigned changes at the Story level within an established architecture, including Terraform and pipeline configuration updates.
  • Maintain and improve runbooks, operational procedures, and support documentation based on observed incidents.
  • Participate in a rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays.
  • Maintain controls and documentation to ensure compliance with company and regulatory requirements.
  • Understand virtualization and containerization technologies.

Requirements

  • 1+ years of related engineering or technical operations experience in information security, infrastructure, or software support.
  • Working knowledge of AWS fundamentals, including console and CLI navigation, IAM basics, and CloudWatch.
  • Ability to read and troubleshoot CI/CD pipeline failures, preferably Jenkins integrated with GitHub.
  • Ability to read and make guided modifications to Terraform and scripting in Python or equivalent.
  • Basic understanding of application security concepts and common vulnerability classes.
  • Ability to follow documented procedures precisely and escalate appropriately.
  • Clear written communication for operational status, incidents, and handoffs.
  • Availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays.
  • Ability to work independently during off-hours shifts with limited supervision.
  • Eligibility to work in the US without sponsorship now or in the future.
  • Preferred: experience in 24/7 operations, AWS Bedrock or hosted LLM platforms, ECS or other container orchestration, Splunk, Linux administration, ServiceNow or similar tooling, Agile methodologies, regulated financial services, and certifications such as AWS Cloud Practitioner, AWS Solutions Architect Associate, or CompTIA Security+.

Benefits & conditions

We can facilitate w2 and corp-to-corp consultants. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.

Rate: $44.00 to $54.00/hr. w2, Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

About the company

Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier · World Congress 2023

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all