Security Engineer
HybridMiami, Florida, United States or Atlanta, Georgia, United States
Job Summary
Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure, triaging findings and tracking remediation with engineering and IT owners. Monitor and report on remediation SLAs, escalate aging or high-severity issues, and maintain documentation and metrics. Harden AWS environments by configuring IAM, security groups, S3, CloudTrail, GuardDuty, and Security Hub, while investigating alerts and implementing guardrails. Support SAST, DAST, and dependency scanning in the CI/CD pipeline, review findings, and participate in secure code reviews and threat modeling. Triage and resolve security tickets within defined SLAs, taking ownership of incidents through resolution. Lead security initiatives including tool rollouts, control implementations, and audit prep while collaborating with engineering, IT, and compliance. Work in-office three days per week with optional on-call coverage.
Required Qualifications
- 2–4 years of experience in a security engineering, security analyst, or related role
- Hands-on experience with AWS security services and concepts (IAM, VPC, GuardDuty, Security Hub, CloudTrail)
- Practical experience with vulnerability management tools and remediation workflows
- Working knowledge of application security concepts (OWASP Top 10, SAST/DAST, dependency scanning)
- Experience managing a ticket queue against SLAs, with strong ownership and follow-through
- Strong written and verbal communication skills; comfortable working cross-functionally
- Solid analytical and troubleshooting skills, with the ability to prioritize under competing deadlines
- Comfortable working in-office 3 days per week
- Able to work independently as a self-starter while collaborating across teams
- Willing to participate in on-call or escalation coverage as needed
Desired Qualifications
- AWS certification (Security Specialty or equivalent)
- Experience with tools such as Wiz, Tenable, Qualys, or Snyk
- Scripting experience (Python or bash) for automation and tooling
- Exposure to compliance frameworks such as SOC 2
- Experience with Jira, Linear, or similar ticketing/project tools
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.