Information Security Engineer IV (Code Security Engineer)
W3Global · United States · 2 wk ago
RemoteRemoteInformation TechnologyContract
About the role
Looking for an Information Security Engineer with strong GenAI/LLM, AWS, DevOps, and application security experience to build and support an LLM-based code vulnerability detection and reporting platform.
Key responsibilities
- Build an LLM-based vulnerability scanner using AWS Bedrock
- Design prompts, agents, model invocation, guardrails, and token/cost controls
- Develop an evaluation framework to measure scanner accuracy
- Build CI/CD pipelines using Jenkins, GitHub, Terraform, and ECS
- Integrate security findings and telemetry with Splunk
- Support, patch, tune, and enhance the scanner after deployment
- Work with security, engineering, and product teams
- Participate in a 24/7 rotating four-person shift schedule
Must have skills
- 1+ year GenAI/LLM development experience
- AWS Bedrock or equivalent hosted LLM platform
- Security / Application Security
- Terraform / Infrastructure as Code
- Jenkins & GitHub CI/CD pipelines
- SAST/SCA and common application vulnerabilities
- Strong software development and engineering experience
- Experience with cloud/security engineering
Nice to have
- AWS IAM
- AWS ECS / Fargate
- Python
- Splunk
- REST APIs
- Event-driven architecture
- Agentic / multi-step LLM workflows
- Docker / containerization
- Linux
- Agile
- Financial services experience
- AWS Security Specialty / Solutions Architect / Security+ / CISSP / SANS
Screening questions
- How many years of GenAI/LLM development experience do you have?
- Have you worked hands-on with AWS Bedrock? What did you build?
- Describe your experience building LLM-based security or vulnerability scanning solutions.
- How strong is your Terraform experience?
- Have you built Jenkins/GitHub CI/CD pipelines?
- What experience do you have with SAST, SCA, and application vulnerabilities?
- Have you worked with AWS ECS/Fargate?
- What is your experience with Splunk?