Title: Information Security Engineer IV (Code Security) Location: 100% Remote
Duration: 6 months Contract
About the Role This is a code security engineering seat: you'll run and continuously sharpen the tooling that keeps application code safe - Static Application Security Testing (SAST), Software Composition Analysis (SCA), and API Security platforms. Day to day splits between keeping those platforms healthy, watching runtime signals, unblocking developers who hit findings, and building the integrations, automation, and reporting that make security visible across the SDLC. Expect a rotating on-call schedule. The role is not eligible for overtime.
What You Bring Must-Have - Hands-on background in API Security
- Working experience with Software Composition Analysis (SCA)
- Working experience with Static Application Security Testing (SAST)
- Terraform, or an equivalent Infrastructure as Code toolset
- Coding fluency in at least one modern language - Javascript / NodeJS and Python are the ones in play here
- A history of supporting end users and chasing down technical issues to resolution
- Proven work building automation, integrations, or operational tooling
- Command of secure software development lifecycle (SSDLC) principles and application security practice
- Sharp analytical, troubleshooting, and communication instincts
Nice-to-Have - Amazon AWS
- Unit testing background
- Comfort writing one-off automation and data-processing scripts
- PowerBI
- Windows Server administration
- Familiarity with CI/CD pipelines, API gateways, and DevOps practices
What You'll Do Platform Ownership - Administer and support the SAST, SCA, and API Security platforms
- Configure, tune, and maintain security scanning and runtime monitoring
- Track platform health, scan coverage, performance metrics, and how well operations are actually running
Developer Enablement - Work through security findings and help engineering teams close vulnerabilities and cut risk
- Handle end-user support, troubleshooting, and onboarding for security tooling and the processes around it
Build & Automate - Design integrations tying security platforms to CI/CD pipelines, reporting systems, and other enterprise tools
- Write automation and one-off solutions that strip out operational overhead
- Apply Infrastructure as Code (IaC) practice to stand up and manage tooling and its supporting infrastructure
- Produce dashboards, metrics, and reporting that give the security program real visibility for decision-making
Partnership - Work alongside development, DevOps, and security teams to fold security into engineering workflows
- Feed into security tooling roadmaps, enhancement work, and ongoing operational improvement
Founded in 2014, ConglomerateIT is a global leader in delivering innovative IT solutions and services. Headquartered in the USA with a presence in the UK, Canada, and India, we specialize in offering industry-leading expertise and cutting-edge products that help our clients maximize their technological investments. Our focus on best-in-class solutions, a highly knowledgeable team, and proactive talent mapping ensure we remain at the forefront of the IT industry.
ConglomerateIT is driven by our Center for Excellence and Innovation, an initiative dedicated to keeping us ahead in a rapidly evolving technology landscape. We understand that building strong relationships is key to our success, and this commitment has enabled us to partner with Fortune 500 companies and leading system integrators worldwide. Our ability to provide local talent on a global scale ensures that we can meet the contingent project requirements of our clients efficiently and effectively.