We are seeking a hands-on Security Engineer with proven experience integrating Wiz Code across source code repositories, CI/CD pipelines, and cloud environments. The role focuses on embedding security into the software development lifecycle, proactively identifying and remediating vulnerabilities, misconfigurations, hardcoded secrets, and data exposure risks. This position supports a regulated financial services environment with strong governance and security controls.
Key Responsibilities:
Key Responsibilities:
- Code & CI/CD Security Integration
- Integrate Wiz Code into source code repositories and CI/CD pipelines.
- Embed security scanning into build and deployment workflows.
- Enforce policy gates and automated remediation workflows.
- Integrate Wiz Code into source code repositories and CI/CD pipelines.
- Infrastructure as Code (IaC) & Cloud Mapping
- Scan and secure Terraform, CloudFormation, and other IaC templates.
- Map code-to-cloud relationships for risk visibility.
- Identify and remediate cloud misconfigurations.
- Scan and secure Terraform, CloudFormation, and other IaC templates.
- Secrets & Sensitive Data Protection
- Detect and remediate hardcoded secrets, credentials, and tokens.
- Prevent sensitive data exposure in code and pipelines.
- Implement secure secrets management best practices.
- Detect and remediate hardcoded secrets, credentials, and tokens.
- Vulnerability & Risk Management
- Triage and remediate vulnerabilities identified by Wiz.
- Work closely with development and DevOps teams to drive remediation.
- Support audit and compliance requirements within financial services.
- Triage and remediate vulnerabilities identified by Wiz.
- Hands-on experience implementing Wiz Code across repositories, pipelines, and cloud environments.
- Strong experience with CI/CD platforms (e.g., GitHub Actions, GitLab CI, Jenkins, Azure DevOps).
- Strong experience with cloud platforms, preferably GCP.
- Experience securing Infrastructure as Code (Terraform, etc.).
- Proven track record detecting and remediating:
- Code vulnerabilities
- Cloud misconfigurations
- Hardcoded secrets
- Sensitive data exposure risks
- Code vulnerabilities
- Strong understanding of DevSecOps principles and secure SDLC practices.