IT Security Engineer
Summary
Worth AI is seeking a Security Engineer to manage vulnerability scanning, harden AWS infrastructure, and integrate security into the CI/CD pipeline. The role involves project-based security initiatives and daily ticket management in a hybrid, Miami-based environment.
At Worth AI, we're building technology that transforms how financial decisions are made and we're doing it with precision, security, and speed. As we scale, we're looking for a hands-on Security Engineer to strengthen our vulnerability management program, harden our AWS environment, and help build application security into how we ship software.
This role is project-driven: you'll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You'll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.
Responsibilities
- Vulnerability Management (Primary Focus)
- Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
- Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
- Monitor and report on remediation SLAs; escalate aging or high-severity findings
- Maintain vulnerability management documentation, metrics, and recurring reporting
- Identity Management
- Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.
Cloud Security (AWS)
- Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
- Implement and maintain security guardrails and baseline configurations across AWS accounts
- Investigate and respond to cloud security alerts and incidents
- Support least-privilege access reviews and cloud configuration audits
Application Security
- Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
- Review and triage AppSec findings with engineering teams and track remediation to closure
- Participate in secure code reviews and threat modeling for new features and services
- Help maintain secure development guidelines and AppSec tooling
Security Operations & Ticketing
- Triage and resolve security tickets and requests within defined SLAs
- Take ownership of incidents and requests through to resolution, escalating when needed
- Maintain clear, accurate documentation of decisions, incidents, and remediation status
- Project & Cross-Functional Work
- Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
- Collaborate with engineering, IT, and compliance to embed security into everyday workflows
- Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders
Requirements
- 2–4 years of experience in a security engineering, security analyst, or related role
- Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub,
CloudTrail)
- Practical experience with vulnerability management tools and remediation workflows
- Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
- Experience managing a ticket queue against SLAs, with strong ownership and follow-through
- Strong written and verbal communication skills; comfortable working cross-functionally
- Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines
Preferred
- AWS certification (Security Specialty or equivalent)
- Experience with tools such as Wiz, Tenable, Qualys, or Snyk
- Scripting experience (Python or bash) for automation and tooling
- Exposure to compliance frameworks such as SOC 2
- Experience with Jira, Linear, or similar ticketing/project tools
Additional Requirements
- Comfortable working in-office 3 days per week
- Able to work independently as a self-starter while collaborating across teams
- Willing to participate in on-call or escalation coverage as needed
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance
- Flexible Paid Time Off
- 9 paid Holidays
- Family Leave
- Remote
- Hybrid work (for Orlando Associates)
- Free Food & Snacks (Orlando)
- Wellness Resources
As published by workable
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, LinkedIn, Cover letter
- Are you eligible to work in the United States? yes / no
- Are you able to work in the U.S. WITHOUT any need for visa or employment sponsorship, now or in the future? yes / no
- How many years experience do you have as a Security Engineer? written answer
- Do you have experience in FinTech? yes / no
- Were you referred by a current employee? If so, who?
- What is your desired base salary requirement?