# Security Engineer

**Company:** [Worth AI](http://jobs.workable.com/companies/k2E8uRLJaqV8qQDdQHzTkn.md)
**Location:** Remote
**Workplace:** remote
**Employment type:** Full-time
**Department:** IT

[Apply for this job](http://jobs.workable.com/view/e2b2924c-6ca4-4bed-8ecb-42fdb6884db9)

## Description

At Worth AI, we're building technology that transforms how financial decisions are made and we're doing it with precision, security, and speed. As we scale, we're looking for a hands-on Security Engineer to strengthen our vulnerability management program, harden our AWS environment, and help build application security into how we ship software.

This role is project-driven: you'll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You'll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.

Responsibilities

-   Vulnerability Management (Primary Focus)
-   Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
-   Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
-   Monitor and report on remediation SLAs; escalate aging or high-severity findings
-   Maintain vulnerability management documentation, metrics, and recurring reporting
-   Identity Management
-   Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.

Cloud Security (AWS)

-   Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
-   Implement and maintain security guardrails and baseline configurations across AWS accounts
-   Investigate and respond to cloud security alerts and incidents
-   Support least-privilege access reviews and cloud configuration audits

Application Security

-   Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
-   Review and triage AppSec findings with engineering teams and track remediation to closure
-   Participate in secure code reviews and threat modeling for new features and services
-   Help maintain secure development guidelines and AppSec tooling

Security Operations & Ticketing

-   Triage and resolve security tickets and requests within defined SLAs
-   Take ownership of incidents and requests through to resolution, escalating when needed
-   Maintain clear, accurate documentation of decisions, incidents, and remediation status
-   Project & Cross-Functional Work
-   Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
-   Collaborate with engineering, IT, and compliance to embed security into everyday workflows
-   Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

## Requirements

-   2–4 years of experience in a security engineering, security analyst, or related role
-   Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub,

CloudTrail)

-   Practical experience with vulnerability management tools and remediation workflows
-   Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
-   Experience managing a ticket queue against SLAs, with strong ownership and follow-through
-   Strong written and verbal communication skills; comfortable working cross-functionally
-   Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines

Preferred

-   AWS certification (Security Specialty or equivalent)
-   Experience with tools such as Wiz, Tenable, Qualys, or Snyk
-   Scripting experience (Python or bash) for automation and tooling
-   Exposure to compliance frameworks such as SOC 2
-   Experience with Jira, Linear, or similar ticketing/project tools

Additional Requirements

-   Comfortable working in-office 3 days per week
-   Able to work independently as a self-starter while collaborating across teams
-   Willing to participate in on-call or escalation coverage as needed

## Benefits

-   Health Care Plan (Medical, Dental & Vision)
-   Retirement Plan (401k, IRA)
-   Life Insurance
-   Flexible Paid Time Off
-   9 paid Holidays
-   Family Leave
-   Remote
-   Hybrid work (for Orlando Associates)
-   Free Food & Snacks (Orlando)
-   Wellness Resources
