Posted
Security Engineer - Product
by Wiz, Inc.
- Cybersecurity
- Cloud Computing
I’m interested
Free account · stay hidden from your current employer
Your interest is shared with employers only as an anonymized demand signal.
Introduction
Wiz is looking for a Security Engineer for Product & Production Infrastructure who has experience performing security reviews, vulnerability management, and detection and response operations in cloud-native environments. You'll get to collaborate with our software development and DevOps teams to secure Wiz's products, CI/CD infrastructure, and production infrastructure. You'll also have the opportunity to influence our product roadmap by utilizing Wiz-for-Wiz to assess, monitor, and harden our environments.
Tasks
- Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
- Build automation, policy-as-code, and security tooling that enables development teams to "shift left" and integrate end-to-end security into their workflows.
- Design and implement secure baselines for cloud resources and Kubernetes based infrastructure.
- Drive vulnerability management and remediation efforts – prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
- Extend our detection and response capabilities – building scalable solutions to identify malicious activity, triage alerts, and investigate and remediate incidents.
- Build deep functional partnerships with Wiz's engineering and operations teams – helping them deliver secure-by-design solutions.
Requirements
- 7+ years of experience in security engineering or security operations work in cloud environments.
- Experience with AWS cloud security (or equivalent experience in Azure and GCP with some level of AWS experience).
- Experience with cloud native Kubernetes services (EKS/GKE/AKS) and container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews of products and architectures, conducting threat modeling exercises, and translating findings into actionable security controls.
- Practical understanding of web application security concepts (such as OWASP Top-10 and similar).
- Hands-on experience with IaC and related tools (Terraform, CloudFormation, Helm, Pulumi).
- Experience with automation and tooling development in one or more of the following: Python, Go, Shell, HCL, Rego.
- Bachelor's degree in computer science or a related field, and/or equivalent job experience in lieu of a degree.
- Experience working with remote, globally distributed teams.
- Experience working in organizations that develop software and/or operate managed infrastructure and technology services for their own customers.
- Experience with CNAPP, CSPM, or CIEM solutions.