Overview
As a Security Engineer for Product & Production Infrastructure, you defend Wiz’s cloud and AI-enabled products by running security reviews, vulnerability management, and detection/response. You’ll partner with software and DevOps teams to secure CI/CD pipelines and production environments, while shaping the product roadmap with security insights. You’ll implement scalable defenses and shift security left across engineering workflows. You’ll work in a fast-growing, globally distributed company backed by Google, contributing to secure-by-design products that scale with customer needs.
Responsibilities
- Lead threat modeling and security reviews across Wiz’s products and cloud infrastructure, identifying attack surfaces and designing scalable mitigations.
- Build automation, policy-as-code, and security tooling to integrate security into developer workflows (shift left).
- Create and enforce secure baselines for cloud resources and Kubernetes-based infrastructure.
- Drive vulnerability management and remediation, implementing mitigations and preventative controls in software supply chains.
- Extend detection and response capabilities with scalable solutions for anomaly detection, alert triage, and incident remediation.
- Foster deep partnerships with engineering and operations to deliver secure-by-design solutions.
Key requirements
- 7+ years of security engineering or security operations in cloud environments.
- Experience with AWS security (or Azure/GCP with some AWS exposure).
- Experience with cloud-native Kubernetes services (EKS/GKE/AKS) and container security.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews, threat modeling, and translating findings into controls.
- Practical understanding of web application security concepts (OWASP Top-10).
- Hands-on experience with IaC tools (Terraform, CloudFormation, Helm, Pulumi).
- Experience with automation and tooling in Python, Go, Shell, HCL, or Rego.
- Strong collaboration across cross-functional teams
- Clear communication of security risks and mitigations
- Ability to work with remote, globally distributed teams
- AWS security (or Azure/GCP with AWS exposure)
- Kubernetes security (EKS/GKE/AKS)
- IAM and cloud identity management at scale
…
