When launching a new EC2 instance, you can specify the security group during the instance creation process. Alternatively, you can modify the security groups associated with an existing instance. Example using AWS CLI:
aws ec2 modify-instance-attribute --instance-id i-1234567890abcdef0 --groups sg-903004f8