At Worth AI, we're building technology that transforms how financial decisions are made and we're doing it with precision, security, and speed. As we scale, we're looking for a hands-on Security Engineer to strengthen our vulnerability management program, harden our AWS environment, and help build application security into how we ship software.
This role is project-driven: you'll own initiatives end to end, from scoping a remediation effort to rolling out a new control, while also handling day-to-day security tickets against defined SLAs. You'll work closely with engineering, IT, and compliance, so clear communication and follow-through matter as much as technical depth.
Responsibilities
- Vulnerability Management (Primary Focus)
- Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure
- Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners
- Monitor and report on remediation SLAs; escalate aging or high-severity findings
- Maintain vulnerability management documentation, metrics, and recurring reporting
- Identity Management
- Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience.
Cloud Security (AWS)
- Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config
- Implement and maintain security guardrails and baseline configurations across AWS accounts
- Investigate and respond to cloud security alerts and incidents
- Support least-privilege access reviews and cloud configuration audits
Application Security
- Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline
- Review and triage AppSec findings with engineering teams and track remediation to closure
- Participate in secure code reviews and threat modeling for new features and services
- Help maintain secure development guidelines and AppSec tooling
Security Operations & Ticketing
- Triage and resolve security tickets and requests within defined SLAs
- Take ownership of incidents and requests through to resolution, escalating when needed
- Maintain clear, accurate documentation of decisions, incidents, and remediation status
- Project & Cross-Functional Work
- Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep
- Collaborate with engineering, IT, and compliance to embed security into everyday workflows
- Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders
Requirements
- 2–4 years of experience in a security engineering, security analyst, or related role
- Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub,
CloudTrail)
- Practical experience with vulnerability management tools and remediation workflows
- Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
- Experience managing a ticket queue against SLAs, with strong ownership and follow-through
- Strong written and verbal communication skills; comfortable working cross-functionally
- Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines
Preferred
- AWS certification (Security Specialty or equivalent)
- Experience with tools such as Wiz, Tenable, Qualys, or Snyk
- Scripting experience (Python or bash) for automation and tooling
- Exposure to compliance frameworks such as SOC 2
- Experience with Jira, Linear, or similar ticketing/project tools
Additional Requirements
- Comfortable working in-office 3 days per week
- Able to work independently as a self-starter while collaborating across teams
- Willing to participate in on-call or escalation coverage as needed
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance
- Flexible Paid Time Off
- 9 paid Holidays
- Family Leave
- Remote
- Hybrid work (for Orlando Associates)
- Free Food & Snacks (Orlando)
- Wellness Resources
Skills Required
- 2-4 years experience in security engineering, security analyst, or related role
- Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub, CloudTrail, Config)
- Practical experience with vulnerability management tools and remediation workflows
- Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
- Experience managing a ticket queue against SLAs with strong ownership and follow-through
- Strong written and verbal communication skills; comfortable working cross-functionally
- Analytical and troubleshooting skills with ability to prioritize under competing deadlines
- Comfortable working in-office 3 days per week
- Able to work independently as a self-starter while collaborating across teams
- Willing to participate in on-call or escalation coverage as needed
- AWS certification (Security Specialty or equivalent)
- Experience with Wiz, Tenable, Qualys, or Snyk
- Scripting experience (Python or bash) for automation and tooling
- Exposure to compliance frameworks such as SOC 2
- Experience with Jira, Linear, or similar ticketing/project tools
Worth Compensation & Benefits Highlights
-
Healthcare Strength — Medical, dental, and vision coverage appear consistently across company materials and third‑party profiles, with HSA/FSA and life insurance also cited. Employer‑verified benefits listings indicate core health coverage is formally in place.
-
Parental & Family Support — Parental leave is highlighted as generous on external profiles and shows up in employer‑verified benefits. Family‑oriented offerings complement the broader health and time‑off package.
-
Leave & Time Off Breadth — Unlimited/flexible PTO and paid holidays are repeatedly listed across postings and profiles. Flexible vacation language and family leave references point to broad time‑off availability.
Worth Insights
What We Do
Worth is the AI-powered platform that consolidates onboarding, underwriting, and risk monitoring for fintechs, lenders, payment processors, and financial institutions. Founded in 2023, we built Worth to replace slow, manual underwriting with a single system that verifies, scores, and monitors small and medium-sized businesses (SMBs) in real time. At the center of the platform is Crosswalking Technology. Our proprietary AI/ML models intelligently match businesses across disparate data sources, ensuring the highest level of accuracy and reliability in SMB entity resolution. By integrating multiple first- and third-party authoritative data sources into our crosswalk-matching logic, Worth ensures that businesses are correctly identified, even in cases of duplicate addresses, name variations, or incomplete records. This data moat spans 186 integrations and 25 global and local partners across 200+ countries and territories, resolving fragmented SMB signals into a database of 350M+ SMBs with a 98% data match rate. Our product suite — Worth Pre-Fill, Custom Onboarding, Case Management, Decisioning Engine, Perpetual Risk Monitoring, and Worth Wallet — is available via API, SDK, or fully white-labeled, enabling financial institutions to consolidate their entire onboarding and underwriting stack into one platform. Customers using Worth have increased approval rates by 37%+, reduced application abandonment by 43%+, cut vendor costs by 25%, and reduced time to revenue by 55%+. We're SOC 2 Type II certified and GDPR and CCPA compliant, and have raised $55M in funding to date. Today, 50+ customers rely on Worth to onboard and underwrite their SMB customers faster and more accurately.
Why Work With Us
We're solving a genuinely hard problem: turning fragmented SMB data into one durable, explainable identity that banks and lenders can trust. Backed by $55M in funding and already live with 50+ customers, we're a tight-knit team with real traction, where your work would help shape the roadmap.
Worth Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.