Worth AI
Worth AI

IT Security Engineer

engineeringfull timeUnited States
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full time
INDUSTRY
ai
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

At Worth AI, we're building technology that transforms how financial decisions are made and we're doing it with precision, security, and speed. As we scale, we're looking for a hands-on Security Engineer to strengthen our vulnerability management program, harden our AWS environment, and help build application security into how we ship software.

This role is project-driven: you'll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You'll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.

Responsibilities

  • Vulnerability Management (Primary Focus)
  • Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
  • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
  • Monitor and report on remediation SLAs; escalate aging or high-severity findings
  • Maintain vulnerability management documentation, metrics, and recurring reporting
  • Identity Management
  • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.

Cloud Security (AWS)

  • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
  • Implement and maintain security guardrails and baseline configurations across AWS accounts
  • Investigate and respond to cloud security alerts and incidents
  • Support least-privilege access reviews and cloud configuration audits

Application Security

  • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
  • Review and triage AppSec findings with engineering teams and track remediation to closure
  • Participate in secure code reviews and threat modeling for new features and services
  • Help maintain secure development guidelines and AppSec tooling

Security Operations & Ticketing

  • Triage and resolve security tickets and requests within defined SLAs
  • Take ownership of incidents and requests through to resolution, escalating when needed
  • Maintain clear, accurate documentation of decisions, incidents, and remediation status
  • Project & Cross-Functional Work
  • Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
  • Collaborate with engineering, IT, and compliance to embed security into everyday workflows
  • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
IT Security Engineer at Worth AI — Remote