Security Engineer

Worth AI
Miami, FL, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Amazon S3 JIRA Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Identity and Access Management Python (Programming Language) Open Web Application Security Secure Coding
+8 more
Software Vulnerability Management Scripting Software Security Amazon Virtual Private Cloud (VPC) Qualys Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

At Worth AI, we’re building technology that transforms how financial decisions are made and we’re doing it with precision, security, and speed. As we scale, we’re looking for a hands-on Security Engineer to strengthen our vulnerability management program, harden our AWS environment, and help build application security into how we ship software.

This role is project-driven: you’ll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You’ll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.

Responsibilities

  • Vulnerability Management (Primary Focus)
  • Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
  • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
  • Monitor and report on remediation SLAs; escalate aging or high-severity findings
  • Maintain vulnerability management documentation, metrics, and recurring reporting
  • Identity Management
  • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.

Cloud Security (AWS)

  • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
  • Implement and maintain security guardrails and baseline configurations across AWS accounts
  • Investigate and respond to cloud security alerts and incidents
  • Support least-privilege access reviews and cloud configuration audits

Application Security

  • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
  • Review and triage AppSec findings with engineering teams and track remediation to closure
  • Participate in secure code reviews and threat modeling for new features and services
  • Help maintain secure development guidelines and AppSec tooling

Security Operations & Ticketing

  • Triage and resolve security tickets and requests within defined SLAs
  • Take ownership of incidents and requests through to resolution, escalating when needed
  • Maintain clear, accurate documentation of decisions, incidents, and remediation status
  • Project & Cross-Functional Work
  • Lead or contribute to security initiatives - tooling rollouts, control implementations, audit and compliance prep
  • Collaborate with engineering, IT, and compliance to embed security into everyday workflows
  • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

Requirements

  • 2-4 years of experience in a security engineering, security analyst, or related role
  • Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub,

CloudTrail)

  • Practical experience with vulnerability management tools and remediation workflows
  • Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
  • Experience managing a ticket queue against SLAs, with strong ownership and follow-through
  • Strong written and verbal communication skills; comfortable working cross-functionally
  • Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines

Preferred

  • AWS certification (Security Specialty or equivalent)
  • Experience with tools such as Wiz, Tenable, Qualys, or Snyk
  • Scripting experience (Python or bash) for automation and tooling
  • Exposure to compliance frameworks such as SOC 2
  • Experience with Jira, Linear, or similar ticketing/project tools

Additional Requirements

  • Comfortable working in-office 3 days per week
  • Able to work independently as a self-starter while collaborating across teams
  • Willing to participate in on-call or escalation coverage as needed

Benefits & conditions

Pulled from the full job description

  • Food provided
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Family leave
  • Life insurance, * Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance
  • Flexible Paid Time Off
  • 9 paid Holidays
  • Family Leave
  • Remote
  • Hybrid work (for Orlando Associates)
  • Free Food & Snacks (Orlando)
  • Wellness Resources

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:08 min

Automating data collection and managing crowdsourced training image sets

Kris Howard · LIVE

Videos

See all

Related articles

See all