# IT Security Engineer

**Company:** [Worth AI](https://hotfix.jobs/companies/worth-ai)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 2+ years
**Skills:** AWS, Amazon Iam, Amazon Vpc, Amazon Guardduty, Aws Security Hub, Aws Cloudtrail, Aws Config, S3, Vulnerability Management, Owasp Top 10, SAST, DAST, Python, Bash, SOC 2
**Posted:** 2026-08-25

> The Security Engineer will own vulnerability management while hardening AWS environments, improving identity controls, and integrating application security into CI/CD. The role requires 2–4 years of security experience, hands-on AWS security knowledge, remediation workflow expertise, and strong cross-functional communication.

## Job Description

## Responsibilities

### Vulnerability Management
- Own vulnerability scanning across endpoints, servers, and cloud infrastructure.
- Triage, prioritize, and track findings through remediation with engineering and IT owners.
- Monitor and report on remediation SLAs; escalate aging or high-severity findings.
- Maintain vulnerability management documentation, metrics, and recurring reports.

### Identity Management
- Improve identity management configurations and automations to strengthen security and user experience.

### Cloud Security
- Monitor and harden AWS environments, including IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, and Config.
- Implement and maintain security guardrails and baseline configurations across AWS accounts.
- Investigate and respond to cloud security alerts and incidents.
- Support least-privilege access reviews and cloud configuration audits.

### Application Security
- Support SAST, DAST, and dependency/SCA scanning in CI/CD pipelines.
- Review and triage AppSec findings with engineering teams and track remediation to closure.
- Participate in secure code reviews and threat modeling.
- Help maintain secure development guidelines and AppSec tooling.

### Security Operations and Projects
- Triage and resolve security tickets and requests within defined SLAs.
- Own incidents and requests through resolution, escalating when needed.
- Maintain documentation of decisions, incidents, and remediation status.
- Lead or contribute to tooling rollouts, control implementations, and audit and compliance preparation.
- Collaborate with engineering, IT, and compliance to embed security into workflows.
- Communicate risk, status, and trade-offs to technical and non-technical stakeholders.

## Requirements
- 2–4 years of experience in security engineering, security analysis, or a related role.
- Hands-on experience with AWS security services and concepts, including IAM, VPC, GuardDuty, Security Hub, and CloudTrail.
- Practical experience with vulnerability management tools and remediation workflows.
- Working knowledge of OWASP Top 10, SAST/DAST, and dependency scanning.
- Experience managing a ticket queue against SLAs with strong ownership and follow-through.
- Strong written and verbal communication skills.
- Solid analytical and troubleshooting skills with the ability to prioritize competing deadlines.
- Comfortable working in-office 3 days per week.
- Able to work independently while collaborating across teams.
- Willing to participate in on-call or escalation coverage as needed.

## Nice-to-Haves
- AWS Security Specialty certification or equivalent.
- Experience with Wiz, Tenable, Qualys, or Snyk.
- Python or Bash scripting for automation and tooling.
- Exposure to SOC 2 or similar compliance frameworks.
- Experience with Jira, Linear, or similar ticketing and project tools.

## Benefits
- Health care plan covering medical, dental, and vision.
- Retirement plan, including 401(k) or IRA.
- Life insurance.
- Flexible paid time off.
- 9 paid holidays.
- Family leave.
- Remote/hybrid work for Orlando associates.
- Free food and snacks in Orlando.
- Wellness resources.

## Similar jobs

- [Security Software Engineer](https://hotfix.jobs/jobs/224cc3c2-74cd-4a03-869e-9e3f15a09f4c) - Hover - San Francisco, CA - $148k – $183k/yr
- [Product Engineer, Security](https://hotfix.jobs/jobs/53b78b5e-4db4-4541-90f1-36826a29b8fc) - Greptile - San Francisco, CA - $170k – $300k/yr
- [Threat Intelligence Platform Engineer](https://hotfix.jobs/jobs/4d005958-d28e-4873-a179-6fa03275091b) - Coinbase - Remote - $145k – $170k/yr
- [Cybersecurity Software Engineer - New Grad](https://hotfix.jobs/jobs/e6590524-c732-4954-a09c-e8a3a040ed8e) - Applied Intuition - Sunnyvale, CA - $130k – $158k/yr
- [Software Engineer, Security](https://hotfix.jobs/jobs/8bbd2781-fac5-4687-84a8-4fa6faaed51e) - Harvey - San Francisco, CA - $161k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/61d1918f-8542-4c73-bffb-988b23c75be7
**Canonical:** https://hotfix.jobs/jobs/61d1918f-8542-4c73-bffb-988b23c75be7