3 months ago
Bengaluru, IndiaStaff+
Responsibilities
- Own AI and agentic security tooling, including Wiz AI Security Posture Management, AI Lens, runtime guardrails, and AI Bill of Materials visibility.
- Drive MCP and agent protection from visibility through active enforcement and integrate model and AI supply-chain scanning into CI/CD.
- Build and run an AI red-teaming program aligned with OWASP LLM and Agentic Top 10 and MITRE ATLAS.
- Operationalize Wiz CNAPP, CSPM, and DSPM capabilities and prioritize findings toward automated remediation.
- Build detection-as-code and SOAR workflows to automate alert triage, enrichment, assignment, and remediation.
- Own the risk-based vulnerability prioritization model, automated ticketing, and sprint assignment.
- Serve as the primary technical lead for the MXDR/MSSP relationship, including detection tuning, log onboarding, service delivery, budget, and performance metrics.
- Act as incident commander for major incidents, own incident response orchestration, maintain playbooks, run purple-team exercises, and drive post-incident remediation to closure.
- Report MTTD, MTTR, and SecOps metrics to leadership.
Requirements
- 8 to 10+ years of hands-on experience in security engineering or operations, with strong depth in security operations, incident response, and cloud security.
- Hands-on experience with cloud security posture and CNAPP tooling, with Wiz strongly preferred.
- Experience with detection engineering, SOAR, detection-as-code, Python scripting, and building toward automated remediation.
- Experience securing AI, ML, LLM, and agentic systems, or demonstrable ability to ramp quickly in guardrails, AI red teaming, MCP, and agent security.
- Experience managing third-party security partners, particularly MSSPs or MXDR providers.
- Expert knowledge of the incident response lifecycle, such as NIST, including experience acting as an incident commander and depth with SIEM and XDR.
- Preferred specialization in OWASP LLM and Agentic Top 10, MITRE ATLAS, AIBOM, and model scanning.
- Proficiency with SOAR and automation platforms and hands-on automated-remediation experience.
- Proven experience standing up or maturing a SecOps function through automation rather than headcount.
- Relevant certifications such as GCIH, GCFA, CISSP, or a cloud security certification.
- A degree in Computer Science, Information Security, or a related field.
Benefits
- Preferred location is Bangalore, India.
- The company is an equal opportunity employer committed to diversity in the workplace.
