# Security Engineer

**Company:** [Worth AI](https://hotfix.jobs/companies/worth-ai)
**Location:** Orlando, FL
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** AWS, IAM, vpc, guardduty, security hub, cloudtrail, SAST, DAST, owasp, Python, Bash, Jira, SOC 2, wiz, tenable
**Posted:** 2026-07-22

> Security Engineer owning vulnerability management, AWS cloud hardening, and application security scanning at Worth AI. Requires 2-4 years experience, hands-on AWS security, vuln remediation, and cross-functional collaboration in a hybrid Orlando setup.

## Job Description

## Responsibilities

**Vulnerability Management (Primary Focus)**
- Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
- Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
- Monitor and report on remediation SLAs; escalate aging or high-severity findings
- Maintain vulnerability management documentation, metrics, and recurring reporting

**Identity Management**
- Improve our identity management program through improvements in configurations and automations to simultaneously improve security and user experience

**Cloud Security (AWS)**
- Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
- Implement and maintain security guardrails and baseline configurations across AWS accounts
- Investigate and respond to cloud security alerts and incidents
- Support least-privilege access reviews and cloud configuration audits

**Application Security**
- Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
- Review and triage AppSec findings with engineering teams and track remediation to closure
- Participate in secure code reviews and threat modeling for new features and services
- Help maintain secure development guidelines and AppSec tooling

**Security Operations & Ticketing**
- Triage and resolve security tickets and requests within defined SLAs
- Take ownership of incidents and requests through to resolution, escalating when needed
- Maintain clear, accurate documentation of decisions, incidents, and remediation status

**Project & Cross-Functional Work**
- Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
- Collaborate with engineering, IT, and compliance to embed security into everyday workflows
- Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

## Requirements
- 2–4 years of experience in a security engineering, security analyst, or related role
- Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub, CloudTrail)
- Practical experience with vulnerability management tools and remediation workflows
- Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
- Experience managing a ticket queue against SLAs, with strong ownership and follow-through
- Strong written and verbal communication skills; comfortable working cross-functionally
- Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines

## Preferred
- AWS certification (Security Specialty or equivalent)
- Experience with tools such as Wiz, Tenable, Qualys, or Snyk
- Scripting experience (Python or bash) for automation and tooling
- Exposure to compliance frameworks such as SOC 2
- Experience with Jira, Linear, or similar ticketing/project tools

## Additional Requirements
- Comfortable working in-office 3 days per week
- Able to work independently as a self-starter while collaborating across teams
- Willing to participate in on-call or escalation coverage as needed

## Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance
- Flexible Paid Time Off
- 9 paid Holidays
- Family Leave
- RemoteHybrid work (for Orlando Associates)
- Free Food & Snacks (Orlando)
- Wellness Resources

## Similar roles

- [Junior Cybersecurity Analyst](https://hotfix.jobs/jobs/3fd35ee9-d333-43cf-82c8-98805a50eb27) - Agency - Richmond, VA - $31k – $42k/yr
- [GRC Team Intern](https://hotfix.jobs/jobs/3b4666f7-d60f-477e-846d-54f49750ec6b) - Cloudflare - Austin, TX
- [IT Security Operations Analyst](https://hotfix.jobs/jobs/3a492a05-9ad3-485e-8f86-9a23c7e1e9ae) - AlertMedia - Austin, TX
- [Cyber Security Intern](https://hotfix.jobs/jobs/11a72900-cc7b-48a2-aa7d-c1e8943ac4c0) - Labelbox - San Francisco, CA - $40 – $55/hr
- [Detection Engineer II](https://hotfix.jobs/jobs/bd254448-d347-417b-a32b-42ef4f1eff89) - Instacart - Remote - $142k – $181k/yr

**Apply:** https://hotfix.jobs/jobs/10147692-6e95-40ec-a92e-7fb5be4c651c
**Canonical:** https://hotfix.jobs/jobs/10147692-6e95-40ec-a92e-7fb5be4c651c