Information Security Engineer III
About the role
This position is for a Lead Information Security Engineer responsible for delivering and supporting enterprise security tools. The role focuses on implementing, operating, and continuously improving an LLM-based code vulnerability detection and reporting capability.
Responsibilities
- Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock.
- Build and maintain the evaluation harness to measure scanner quality and report on detection performance.
- Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
- Deliver findings and operational telemetry into Splunk; build dashboards and alerting for scanner health and throughput.
- Engineer, design, test, and implement well-architected solutions while adhering to software development best practices.
- Contribute to the development and maintenance of standards, procedures, and runbooks for Information Security operations.
- Provide ongoing operational support, patching, and defect resolution for the deployed scanner.
- Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays.
- Maintain controls and documentation to ensure compliance with all company and regulatory requirements.
Requirements
- Experience: 2+ years of related engineering experience, including hands-on information security or software development work.
- Experience with DevOps practices and tools such as Jenkins, GitHub, CI/CD, and Terraform.
- Exposure to AWS Bedrock or equivalent hosted LLM platforms.
- Working knowledge of Infrastructure as Code best practices and Terraform.
- Experience working within CI/CD pipelines, preferably Jenkins, integrated with GitHub.
- Familiarity with application security concepts and SAST/SCA tooling behavior.
- Understanding of virtualization and containerization technologies.
Qualifications
- Ability to communicate technical status, risks, and blockers clearly.
- Willingness and availability to work an assigned shift within a rotating 24/7 schedule.
- Ability to work independently during off-hours shifts.
Skills
- Ability to communicate technical status, risks, and blockers clearly.
- Willingness and availability to work an assigned shift within a rotating 24/7 schedule.
- Ability to work independently during off-hours shifts.
Benefits
Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.