About the Role
Wiz is seeking a Security Engineer for Product & Production Infrastructure to perform security reviews, vulnerability management, and detection and response operations in cloud-native environments. You will collaborate with software development and DevOps teams to secure Wiz’s products, CI/CD infrastructure, and production infrastructure, and influence the product roadmap by assessing, monitoring, and hardening environments using Wiz-for-Wiz.
Responsibilities
- Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies
- Build automation, policy-as-code, and security tooling that enables development teams to "shift left" and integrate end-to-end security into their workflows
- Design and implement secure baselines for cloud resources and Kubernetes based infrastructure
- Drive vulnerability management and remediation efforts – prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production
- Extend our detection and response capabilities – building scalable solutions to identify malicious activity, triage alerts, and investigate and remediate incidents
- Build deep functional partnerships with Wiz's engineering and operations teams – helping them deliver secure-by-design solutions
Requirements
- 7+ years of experience in security engineering or security operations work in cloud environments
- Strong AWS cloud security experience (Azure and GCP experience will also be considered with some AWS experience)
- Cloud native Kubernetes services (EKS/GKE/AKS) and strong container security principles
- Deep understanding of securing IAM and cloud identities at scale
- Proven ability to lead technical security reviews of products and architectures, conduct threat modeling exercises, and translate findings into actionable security controls
- Practical understanding of web application security concepts (such as OWASP Top-10 and similar)
- Hands-on experience with IAC and related tools (Terraform, CloudFormation, Helm, Pulumi)
- Experience with automation and tooling development in one or more: Python, Go, Shell, HCL, Rego
- Applicants must have the legal right to work in the country where the position is based, without the need for visa sponsorship. This role does not offer visa sponsorship.
Skills
- AWS cloud security
- Azure cloud security
- GCP cloud security
- Kubernetes
- Container security
- IAM
- Cloud identities
- Technical security reviews
- Threat modeling
- Web application security
- OWASP Top-10
- IAC
- Terraform
- CloudFormation
- Helm
- Pulumi
- Automation
- Tooling development
- Python
- Go
- Shell
- HCL
- Rego
- CNAPP
- CSPM
- CIEM
Experience Level
- 7+ years of experience
Education Level
- Bachelor's degree in computer science or a related field or equivalent job experience
About the Company
- The organization is redefining security for the AI era and is one of the fastest-growing startups ever.
- They enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context.
- Trusted by security teams worldwide, they have a proven track record of success and a culture that values world-class talent.
- The company is now powered by Google, offering customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations.
- Their Wizards protect customer infrastructure, including over 65% of the Fortune 100, scanning over 230 billion files daily.
- They are a leading player in a massive and growing market.
- Wiz offers the freedom to think creatively, dream big, and use a full range of skills to contribute to momentous growth.
- The company aims to help create secure cloud environments that allow companies to move faster.
Equal Opportunity
- Wiz is an equal opportunity employer.
- We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.
