InfoSec Lead: LLM Security & CI/CD (Remote)

Eliassen Group

Nashville (TN)

On-site

USD 125,000 - 146,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision benefits
401k with company matching
Life insurance

Job summary

Eliassen Group is seeking a Lead Information Security Engineer to implement, operate, and improve an LLM-based code vulnerability detection capability. The role focuses on delivering a scanner, evaluation harness, and CI/CD pipelines, then transitioning to operations including patching, tuning, and feature work.

The position supports a four-person rotating 24/7 schedule, with most time devoted to engineering and feature work.

Qualifications

  • 2+ years of related engineering experience, including hands-on information security or software development work.
  • Exposure to AWS Bedrock or equivalent hosted LLM platforms, including model invocation and guardrail configuration.
  • Working knowledge of Infrastructure as Code and ability to build and modify Terraform modules.
  • Experience with CI/CD pipelines, preferably Jenkins, integrated with GitHub.
  • Familiarity with application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
  • Clear written and verbal communication of technical status, risks, and blockers to peers and leadership.
  • Willingness and availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays.

Responsibilities

  • Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt and agent implementation, model invocation patterns, cost and token controls, and result normalization.
  • Build and maintain the evaluation harness to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
  • Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
  • Deliver findings and operational telemetry into Splunk, and build dashboards and alerting for scanner health, coverage, and throughput.
  • Engineer and implement well-architected solutions aligned to software development best practices.
  • Design, test, and implement solutions at the Story and Feature level within an established architecture.
  • Contribute to standards, procedures, runbooks, and guidelines for Information Security operations.
  • Provide ongoing operational support, patching, and defect resolution after go-live.
  • Participate in a four-person rotating 24/7 shift schedule, including nights, weekends, and holidays, averaging 40 hours per week.
  • Monitor scanner health, pipeline execution, and alert queues during assigned shifts. Execute documented runbooks and elevate per procedures.
  • Perform structured shift handoffs, documenting open issues, in-flight changes, and outstanding escalations.
  • Maintain controls and documentation to ensure compliance with company and regulatory requirements.
  • Understand virtualization and containerization technologies.
  • Perform other duties as assigned.

Skills

AWS Bedrock
Terraform
Jenkins
GitHub
CI/CD
Splunk
Documentation/Runbooks

Tools

AWS Bedrock
GitHub
Jenkins
Splunk
Terraform
EC2/ECS

Job description

Eliassen Group is seeking a Lead Information Security Engineer to implement, operate, and improve an LLM-based code vulnerability detection capability. The role focuses on delivering a scanner, evaluation harness, and CI/CD pipelines, then transitioning to operations including patching, tuning, and feature work.

The position supports a four-person rotating 24/7 schedule, with most time devoted to engineering and feature work.

Get your free, confidential resume review.
or drag and drop your file here.