IT Security Engineer

Worth AI

$90K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-4 years of experience in security engineering or a related field.
  • Hands-on experience with AWS security services (IAM, VPC, GuardDuty, Security Hub, CloudTrail).
  • Practical experience with vulnerability management tools and workflows.
  • Knowledge of application security concepts (OWASP Top 10, SAST/DAST).
  • Experience managing a ticket queue with strict SLAs.
  • Strong written and verbal communication skills for cross-functional collaboration.
  • Solid analytical skills and ability to prioritize tasks effectively.

Responsibilities

  • Lead vulnerability management efforts, focusing on scanning across various platforms.
  • Coordinate the vulnerability scanning program and collaborate with IT and engineering teams.
  • Monitor remediation processes and escalate issues as necessary.
  • Maintain detailed documentation and metrics for vulnerability management.
  • Enhance identity management configurations to improve security and user experience.
  • Monitor and strengthen AWS security configurations and incident responses.
  • Engage in application security processes including SAST/DAST integration and secure code reviews.

Benefits

  • Comprehensive Health Care Plan including Medical, Dental & Vision coverage.
  • Retirement Plan options including 401k and IRA.
  • Life Insurance coverage provided.
  • Generous Flexible Paid Time Off policy.
  • 9 paid Holidays each year.
  • Family Leave for personal and family needs.
  • Remote work options available.
  • Hybrid work arrangement for Orlando team members.
  • Free food and snacks available at the Orlando office.
  • Access to Wellness Resources for employee support.
Full Job Description
This role is project-driven: you'll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You'll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.

Responsibilities
  • Vulnerability Management (Primary Focus)
  • Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
  • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
  • Monitor and report on remediation SLAs; escalate aging or high-severity findings
  • Maintain vulnerability management documentation, metrics, and recurring reporting
  • Identity Management
  • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.

Cloud Security (AWS)
  • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
  • Implement and maintain security guardrails and baseline configurations across AWS accounts
  • Investigate and respond to cloud security alerts and incidents
  • Support least-privilege access reviews and cloud configuration audits

Application Security
  • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
  • Review and triage AppSec findings with engineering teams and track remediation to closure
  • Participate in secure code reviews and threat modeling for new features and services
  • Help maintain secure development guidelines and AppSec tooling

Security Operations & Ticketing
  • Triage and resolve security tickets and requests within defined SLAs
  • Take ownership of incidents and requests through to resolution, escalating when needed
  • Maintain clear, accurate documentation of decisions, incidents, and remediation status
  • Project & Cross-Functional Work
  • Lead or contribute to security initiatives - tooling rollouts, control implementations, audit and compliance prep
  • Collaborate with engineering, IT, and compliance to embed security into everyday workflows
  • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

Requirements
  • 2-4 years of experience in a security engineering, security analyst, or related role
  • Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub,

CloudTrail)
  • Practical experience with vulnerability management tools and remediation workflows
  • Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
  • Experience managing a ticket queue against SLAs, with strong ownership and follow-through
  • Strong written and verbal communication skills; comfortable working cross-functionally
  • Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines

Preferred
  • AWS certification (Security Specialty or equivalent)
  • Experience with tools such as Wiz, Tenable, Qualys, or Snyk
  • Scripting experience (Python or bash) for automation and tooling
  • Exposure to compliance frameworks such as SOC 2
  • Experience with Jira, Linear, or similar ticketing/project tools

Additional Requirements
  • Comfortable working in-office 3 days per week
  • Able to work independently as a self-starter while collaborating across teams
  • Willing to participate in on-call or escalation coverage as needed

Benefits
  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance
  • Flexible Paid Time Off
  • 9 paid Holidays
  • Family Leave
  • Remote
  • Hybrid work (for Orlando Associates)
  • Free Food & Snacks (Orlando)
  • Wellness Resources

Similar Jobs

More Jobs at Worth AI

More Information Technology Jobs

Find similar IT Security Engineer jobs: