Job Title: Information Security Engineer IV
Location: (City, State)
Duration: Contract - 4 months
Pay Range: $80/hr $90/hr (W2)
Job ID: 409015
About BCforward
BCforward is a leading global IT consulting and workforce solutions firm providing services and support to Fortune 500 and government clients. Founded in 1998, BCforward has grown with our customers needs into a full-service business solutions provider. With delivery centers and offices across North America and India, we take pride in building long-term relationships and delivering excellence through innovation, collaboration, and integrity.
Job Description
We are seeking an experienced Information Security Engineer IV to define, deliver, and support enterprise security tools with a focus on building, operating, and improving an LLM-based code vulnerability detection and reporting capability. The initial phase focuses on design and delivery of the scanner, evaluation harness, and CI/CD pipelines, followed by ongoing operations including patching, tuning, feature development, and sustained support. Finding triage and remediation ownership are out of scope for this role.
Responsibilities:
* Serve as a security engineer and consultant on cloud projects.
* Build and operate an LLM-based code vulnerability detection capability on AWS Bedrock, including prompt and agent design, model invocation patterns, cost and token controls, and result normalization.
* Develop and maintain an evaluation harness with regression corpora, repeatable test execution, and performance reporting over time.
* Build and maintain scanning pipelines integrated with GitHub and Jenkins, deployed to ECS and provisioned through Terraform.
* Deliver findings and operational telemetry into Splunk and develop dashboards and alerting for scanner health, coverage, and throughput.
* Engineer and implement well-architected solutions that follow software development best practices.
* Advise Principal Engineers and Product Owners on operations and product evolution.
* Design, test, and implement solutions at the feature level.
* Support operational information security responsibilities, including development and maintenance of standards, procedures, and guidelines.
* Provide ongoing operational support, patching, and defect resolution for the deployed scanner after go-live.
* Participate in a four-person rotating shift schedule providing 24/7 coverage, including nights, weekends, and holidays, averaging 40 hours per week.
* Maintain appropriate controls and documentation to ensure compliance with company and regulatory requirements.
* Understand virtualization and containerization technologies.
* Participate in operational on-call rotation within normal working hours.
* Perform other duties as assigned.
Required Skills & Qualifications:
* 4+ years of related engineering experience in information security or software development.
* Hands-on experience with AWS Bedrock or similar hosted LLM platforms, including model selection, inference optimization, and guardrail configuration.
* Strong Infrastructure as Code skills and experience building reusable Terraform modules.
* Experience building and maintaining CI/CD pipelines, preferably Jenkins, integrated with GitHub.
* Working knowledge of application security concepts, common vulnerability classes, and SAST/SCA tooling behavior.
* Clear verbal and written communication skills for management, business sponsors, and technical audiences.
* Eligibility to work in the United States without current or future sponsorship.
Preferred Skills:
Apply here: https://www.aplitrak.com/?adid=YmJnZW5lcmljLjQ5NDA4LjEwNTA4QGJjZm9yd2FyZGNvbXAuYXBsaXRyYWsuY29t