Remote Lead InfoSec Engineer - LLM Vulnerability Scanning

Eliassen Group

Frankfort (KY)

On-site

USD 83,000 - 96,000

Part time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
401k matching
Life insurance

Job summary

Eliassen Group is seeking a Lead Information Security Engineer to implement, operate, and enhance an LLM-based vulnerability detection capability. You will deliver scanners, evaluation harnesses, and CI/CD pipelines and then transition to ongoing operations including patching and feature development.

The role involves a four-person rotating 24/7 schedule, with primary focus on engineering and feature work, and obligations to meet regulatory requirements.

Qualifications

  • 2+ years of related engineering experience, including hands-on information security or software development work.
  • Exposure to AWS Bedrock or equivalent hosted LLM platforms, including model invocation and guardrail configuration.
  • Working knowledge of Infrastructure as Code and ability to build and modify Terraform modules.
  • Experience with CI/CD pipelines, preferably Jenkins, integrated with GitHub.
  • Familiarity with application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
  • Clear written and verbal communication of technical status, risks, and blockers to peers and leadership.
  • Willingness and availability to work an assigned shift within a rotating 24/7 schedule, including nights, weekends, and holidays.
  • Ability to work independently during off-hours shifts with limited direct supervision.
  • Eligible to work in the US without sponsorship now or in the future.
  • Preferred: Hands-on AWS experience including IAM, ECS, and service-to-service authentication. AWS Bedrock model selection and inference optimization.
  • Preferred: Agentic or multi-step LLM workflows, including context management across large repositories.
  • Preferred: RESTful APIs and event-driven architectures.
  • Preferred: Splunk development for data onboarding, search, and dashboarding.
  • Preferred: Containerized workloads and Linux systems.
  • Preferred: Prior 24/7 operational support experience, shift handoff, and runbook execution.
  • Preferred: Agile methodologies and development practices.
  • Preferred: Regulated financial services environment experience.
  • Preferred: Certifications such as AWS Solutions Architect Associate, AWS Security Specialty, or CompTIA Security+.

Responsibilities

  • Implement and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt and agent implementation, model invocation patterns, cost and token controls, and result normalization.
  • Build and maintain the evaluation harness to measure scanner quality, including regression corpora, repeatable test execution, and reporting on detection performance over time.
  • Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
  • Deliver findings and operational telemetry into Splunk, and build dashboards and alerting for scanner health, coverage, and throughput.
  • Engineer and implement well-architected solutions aligned to software development best practices.
  • Design, test, and implement solutions at the Story and Feature level within an established architecture.
  • Contribute to standards, procedures, runbooks, and guidelines for Information Security operations.
  • Provide ongoing operational support, patching, and defect resolution after go-live.
  • Participate in a four-person rotating 24/7 shift schedule, including nights, weekends, and holidays, averaging 40 hours per week.
  • Monitor scanner health, pipeline execution, and alert queues during assigned shifts. Execute documented runbooks and elevate per procedures.
  • Perform structured shift handoffs, documenting open issues, in-flight changes, and outstanding escalations.
  • Maintain controls and documentation to ensure compliance with company and regulatory requirements.
  • Understand virtualization and containerization technologies.
  • Perform other duties as assigned.

Skills

LLM-based security engineering
AWS Bedrock
Terraform
CI/CD pipelines
GitHub
Jenkins
Splunk dashboards
Vulnerability detection
SAST/SCA tooling
Containerization basics

Tools

AWS Bedrock
Terraform
GitHub
Jenkins
Splunk

Job description

Eliassen Group is seeking a Lead Information Security Engineer to implement, operate, and enhance an LLM-based vulnerability detection capability. You will deliver scanners, evaluation harnesses, and CI/CD pipelines and then transition to ongoing operations including patching and feature development.

The role involves a four-person rotating 24/7 schedule, with primary focus on engineering and feature work, and obligations to meet regulatory requirements.

Get your free, confidential resume review.
or drag and drop your file here.