2 months ago
Remote, France or Paris, FranceSenior
Responsibilities
- Lead threat modeling and security reviews across products and cloud infrastructure, identifying attack surfaces and scalable mitigation strategies.
- Build automation, policy-as-code, and security tooling that integrates security into development workflows.
- Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure.
- Drive vulnerability management and remediation across software supply chains from development through production.
- Extend detection and response capabilities to identify malicious activity, triage alerts, investigate incidents, and implement remediation.
- Partner with engineering and operations teams to deliver secure-by-design solutions.
Requirements
- At least 7 years of experience in security engineering or security operations in cloud environments.
- Experience with AWS cloud security, or equivalent Azure and GCP experience with some AWS experience.
- Experience with cloud-native Kubernetes services such as EKS, GKE, or AKS and container security principles.
- Experience securing IAM and cloud identities at scale.
- Experience leading technical security reviews, conducting threat modeling, and translating findings into actionable controls.
- Practical understanding of web application security concepts, including OWASP Top 10.
- Hands-on experience with infrastructure as code and tools such as Terraform, CloudFormation, Helm, or Pulumi.
- Experience developing automation and tooling with one or more of Python, Go, Shell, HCL, or Rego.
- Bachelor's degree in computer science or a related field is preferred, with equivalent job experience accepted in lieu of a degree.
- Experience working with remote, globally distributed teams and with software or managed infrastructure organizations is preferred.
- Experience with CNAPP, CSPM, or CIEM solutions is preferred.
- Must have legal authorization to work in the position's country without visa sponsorship.
Tech Stack
Categories
About Wiz, Inc.
Wiz builds a cloud security platform (often described as CNAPP) for enterprises that maps risks across code, cloud infrastructure, identities, and runtime to prioritize remediation. It provides agentless scanning and graph-based context across AWS, Azure, GCP, and Kubernetes, sold as subscription SaaS. Founded in 2020 and headquartered in New York, the company focuses on securing complex multi-cloud environments for global enterprises.
