Skip to content
Worth AIWorth AI

IT Security Engineer

The Security Engineer will own vulnerability management while hardening AWS environments, improving identity controls, and integrating application security into CI/CD. The role requires 2–4 years of security experience, hands-on AWS security knowledge, remediation workflow expertise, and strong cross-functional communication.

About the job

Responsibilities

Vulnerability Management

  • Own vulnerability scanning across endpoints, servers, and cloud infrastructure.
  • Triage, prioritize, and track findings through remediation with engineering and IT owners.
  • Monitor and report on remediation SLAs; escalate aging or high-severity findings.
  • Maintain vulnerability management documentation, metrics, and recurring reports.

Identity Management

  • Improve identity management configurations and automations to strengthen security and user experience.

Cloud Security

  • Monitor and harden AWS environments, including IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, and Config.
  • Implement and maintain security guardrails and baseline configurations across AWS accounts.
  • Investigate and respond to cloud security alerts and incidents.
  • Support least-privilege access reviews and cloud configuration audits.

Application Security

  • Support SAST, DAST, and dependency/SCA scanning in CI/CD pipelines.
  • Review and triage AppSec findings with engineering teams and track remediation to closure.
  • Participate in secure code reviews and threat modeling.
  • Help maintain secure development guidelines and AppSec tooling.

Security Operations and Projects

  • Triage and resolve security tickets and requests within defined SLAs.
  • Own incidents and requests through resolution, escalating when needed.
  • Maintain documentation of decisions, incidents, and remediation status.
  • Lead or contribute to tooling rollouts, control implementations, and audit and compliance preparation.
  • Collaborate with engineering, IT, and compliance to embed security into workflows.
  • Communicate risk, status, and trade-offs to technical and non-technical stakeholders.

Requirements

  • 2–4 years of experience in security engineering, security analysis, or a related role.
  • Hands-on experience with AWS security services and concepts, including IAM, VPC, GuardDuty, Security Hub, and CloudTrail.
  • Practical experience with vulnerability management tools and remediation workflows.
  • Working knowledge of OWASP Top 10, SAST/DAST, and dependency scanning.
  • Experience managing a ticket queue against SLAs with strong ownership and follow-through.
  • Strong written and verbal communication skills.
  • Solid analytical and troubleshooting skills with the ability to prioritize competing deadlines.
  • Comfortable working in-office 3 days per week.
  • Able to work independently while collaborating across teams.
  • Willing to participate in on-call or escalation coverage as needed.

Nice-to-Haves

  • AWS Security Specialty certification or equivalent.
  • Experience with Wiz, Tenable, Qualys, or Snyk.
  • Python or Bash scripting for automation and tooling.
  • Exposure to SOC 2 or similar compliance frameworks.
  • Experience with Jira, Linear, or similar ticketing and project tools.

Benefits

  • Health care plan covering medical, dental, and vision.
  • Retirement plan, including 401(k) or IRA.
  • Life insurance.
  • Flexible paid time off.
  • 9 paid holidays.
  • Family leave.
  • Remote/hybrid work for Orlando associates.
  • Free food and snacks in Orlando.
  • Wellness resources.

Skills

AWS, Amazon Iam, Amazon Vpc, Amazon Guardduty, Aws Security Hub, Aws Cloudtrail, Aws Config, S3, Vulnerability Management, Owasp Top 10, SAST, DAST, Python, Bash, SOC 2

Hover

Hover

San Francisco, CA
Security Software Engineer
$148k+/yrHybrid1+ YOESecurity Engineering

Build foundational security services and automation protecting Hover’s applications, users, and cloud infrastructure. The role suits an early-career software engineer with strong programming fundamentals, a computer science background, and interest in secure development practices.

Greptile

Greptile

San Francisco, CA

Product Engineer, Security
$170k+/yrOn-site1+ YOESecurity Engineering

Build Greptile’s security product, including code scanning, vulnerability detection and reproduction, security-focused pull-request workflows, and agent infrastructure. The role requires a computer science degree, software or DevOps experience, JavaScript/TypeScript expertise, and hands-on security experience.

Coinbase

Coinbase

United States

Threat Intelligence Platform Engineer
$145k+/yrRemote2+ YOESecurity Engineering

Own and operate Vertex Synapse, integrating and modeling threat intelligence while delivering it to detections, blocklists, data pipelines, and security workflows. Requires at least two years of production threat-intelligence platform or security data-pipeline experience and software development skills in Python, Go, or Storm.

Applied Intuition

Applied Intuition

Sunnyvale, CA

Cybersecurity Software Engineer - New Grad
$130k+/yrOn-siteSecurity Engineering

Build security into embedded vehicle platforms through security assessments, secure boot implementation, and HSM integration. This new-grad role requires a relevant computer or electrical engineering degree, foundational cryptography knowledge, and proficiency in C, C++, or Python.

Harvey

Harvey

San Francisco, CA

Software Engineer, Security
$161k+/yrOn-site2+ YOESecurity Engineering

Build and operate foundational security services spanning identity, access, secrets, privileged access, and secure AI-agent infrastructure. The role requires at least two years of production software engineering experience, cloud expertise, and experience translating security requirements into reliable automated systems.