Worth AI logo
Worth AI
Posted 23 days agoVerified live 1d ago

IT Security Engineer

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
AWS SecurityIdentity and Access Management (IAM)Vulnerability ManagementApplication SecurityOWASP Top 10SAST/DASTDependency ScanningPythonBashAWS Security Specialty CertificationWizTenableQualysSnykSOC 2Written and Verbal Communication

About the company

Worth AI logo
Worth AIworthai.com

Worth AI is a fintech platform that focuses on SMB onboarding and risk management, using AI algorithms to streamline financial processes.

Job description

Summary

Worth AI is building technology that transforms how financial decisions are made with precision, security, and speed. The Security Engineer will strengthen vulnerability management, harden AWS environments, support application security, manage security tickets, and lead security initiatives while collaborating with engineering, IT, and compliance.

Responsibilities

  • Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
  • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
  • Monitor and report on remediation SLAs; escalate aging or high-severity findings
  • Maintain vulnerability management documentation, metrics, and recurring reporting
  • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience
  • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
  • Implement and maintain security guardrails and baseline configurations across AWS accounts
  • Investigate and respond to cloud security alerts and incidents
  • Support least-privilege access reviews and cloud configuration audits
  • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
  • Review and triage AppSec findings with engineering teams and track remediation to closure
  • Participate in secure code reviews and threat modeling for new features and services
  • Help maintain secure development guidelines and AppSec tooling
  • Triage and resolve security tickets and requests within defined SLAs
  • Take ownership of incidents and requests through to resolution, escalating when needed
  • Maintain clear, accurate documentation of decisions, incidents, and remediation status
  • Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
  • Collaborate with engineering, IT, and compliance to embed security into everyday workflows
  • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

Skills

  • 2–4 years of experience in a security engineering, security analyst, or related role
  • Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub, CloudTrail)
  • Practical experience with vulnerability management tools and remediation workflows
  • Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
  • Experience managing a ticket queue against SLAs, with strong ownership and follow-through
  • Strong written and verbal communication skills; comfortable working cross-functionally
  • Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines
  • Comfortable working in-office 3 days per week
  • Able to work independently as a self-starter while collaborating across teams
  • Willing to participate in on-call or escalation coverage as needed
  • AWS certification (Security Specialty or equivalent)
  • Experience with tools such as Wiz, Tenable, Qualys, or Snyk
  • Scripting experience (Python or bash) for automation and tooling
  • Exposure to compliance frameworks such as SOC 2
  • Experience with Jira, Linear, or similar ticketing/project tools

Qualifications

Must Haves

  • 2–4 years of experience in a security engineering, security analyst, or related role
  • Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub, CloudTrail)
  • Practical experience with vulnerability management tools and remediation workflows
  • Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
  • Experience managing a ticket queue against SLAs, with strong ownership and follow-through
  • Strong written and verbal communication skills; comfortable working cross-functionally
  • Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines
  • Comfortable working in-office 3 days per week
  • Able to work independently as a self-starter while collaborating across teams
  • Willing to participate in on-call or escalation coverage as needed

Nice to Haves

  • AWS certification (Security Specialty or equivalent)
  • Experience with tools such as Wiz, Tenable, Qualys, or Snyk
  • Scripting experience (Python or bash) for automation and tooling
  • Exposure to compliance frameworks such as SOC 2
  • Experience with Jira, Linear, or similar ticketing/project tools

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance
  • Flexible Paid Time Off
  • 9 paid Holidays
  • Family Leave
  • Remote
  • Hybrid work (for Orlando Associates)
  • Free Food & Snacks (Orlando)
  • Wellness Resources

More jobs like this