
Security Engineer – Product & Production Infrastructure
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Conduct security evaluations, manage vulnerabilities, and execute detection and response operations within cloud-native settings.
• Work in conjunction with software development and DevOps teams to safeguard Wiz's products, CI/CD frameworks, and production environments.
• Utilize Wiz-for-Wiz to evaluate, oversee, and enhance environments while influencing the product development roadmap.
• Spearhead threat modeling and security assessments across products and cloud infrastructure.
• Recognize attack surfaces and formulate scalable mitigation tactics.
• Develop automation, policy-as-code, and security tools to seamlessly integrate end-to-end security within development workflows.
• Create and implement secure baselines for cloud assets and Kubernetes-based systems.
• Lead vulnerability management and remediation throughout the software supply chain from development to production.
• Expand detection and response capabilities to pinpoint malicious activities, triage alerts, investigate incidents, and address them.
• Partner with the Wiz Federal team to extend DevSecOps and Product Security practices to the FedRAMP environment.
• Forge collaborations with engineering and operations teams to provide secure-by-design solutions.
• Over 7 years of experience in security engineering or security operations within cloud environments.
• Proficiency in AWS cloud security, or equivalent experience with Azure and GCP, complemented by some level of AWS knowledge.
• Familiarity with cloud-native Kubernetes services such as EKS, GKE, or AKS, along with a solid understanding of container security principles.
• Experience in securing IAM and cloud identities on a large scale.
• Proven track record leading technical security evaluations of products and architectures, conducting threat modeling sessions, and converting findings into actionable security measures.
• Practical knowledge of web application security principles such as OWASP Top-10 and similar frameworks.
• Experience with Infrastructure as Code (IaC) and tools like Terraform, CloudFormation, Helm, or Pulumi.
• Background in automation and tool development using Python, Go, Shell, HCL, or Rego.
• Bachelor’s degree in computer science or a related discipline, or equivalent professional experience in lieu of a degree.
• Experience collaborating with remote, globally distributed teams.
• Familiarity with organizations that develop software and/or provide managed infrastructure and technology services for their own clients.
• Experience with CNAPP, CSPM, or CIEM solutions.
• Candidates must have the legal authorization to work in the country where the position is located without requiring visa sponsorship.
• Competitive base salary, bonus, equity, and comprehensive benefits.
• Google benefits.
• Bonus compensation opportunities.
• Equity participation.
• Additional benefits.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.