Senior Security Engineer - Container & Cloud Security
Cloud Native Security
Cloud Native Workload Protection
Cloud Platforms
Cloud Security
Cloud Workload Protection Platform
Container Image Security
Container Security
Data Security
DevSecOps
Engineer
Incident Response
Information Security
InfoSec
Security
Security As Code
Security Automation
Security Compliance
Security Detection
Security Engineer
Security Operations
Security Standards
Software Supply Chain
Job Description
Sr. Security Engineer on a policy-as-code team focused on automating container and cloud security governance across Azure and GCP with Wiz.
Responsibilities
- Design, implement, and maintain cloud-native container security controls for Kubernetes platforms including AKS, GKE, and EKS.
- Develop, tune, and maintain container threat detection rules to identify malicious activity, anomalous behavior, and indicators of compromise.
- Monitor runtime security events, investigate alerts, and support triage and incident response for container and Kubernetes workloads.
- Deploy and optimize Wiz Defend/CWPP capabilities, including runtime sensors, workload protection, and attack path analysis.
- Create and automate security guardrails using Infrastructure as Code (Terraform, Helm) and GitOps, including admission controller policies and preventative controls.
- Strengthen container software supply chain with image scanning, SBOM validation, image signing, and registry security.
- Identify, prioritize, and remediate container vulnerabilities and misconfigurations using risk-based exposure analysis.
- Develop and maintain Compliance-as-Code policies aligned to CIS, NIST, and STIG security benchmarks.
- Route Wiz findings and threat intelligence into ServiceNow and enterprise vulnerability management workflows.
- Partner with Security Operations, Cloud Engineering, DevSecOps, and application teams to improve detection coverage and cloud security posture.
- Conduct threat hunting and proactive analysis to improve detection logic and enhance runtime protection capabilities.
- Support post-incident reviews with root cause analysis, corrective action recommendations, and continuous improvement of detection and response.
Requirements
- Strong cloud security knowledge across AI/ML platforms, model pipelines, data layers, IAM, networking, and logging.
- Hands-on Wiz CNAPP expertise (CSPM, CIEM, DSPM, CWPP), including applying it to AI workloads, model hosting, and data pipelines.
- Experience designing preventive and detective security controls across model, data, and platform layers.
- Compliance-as-Code fluency, including mapping Wiz findings to STIGs, native cloud policies, CI/CD, and governance workflows.
- Ability to interpret Wiz risk graphs and communicate risk-based exposure analysis for model misuse, data leakage, privilege escalation, and blast radius.
- Kubernetes experience across AKS, GKE, and EKS.
- Working knowledge of Terraform, Helm, and GitOps-based pipelines.
Technologies
- Wiz, Wiz Defend, CWPP, CSPM, CIEM, DSPM
- Kubernetes, AKS, GKE, EKS
- Terraform, Helm, GitOps, Azure, GCP
- CIS, NIST, STIG
- ServiceNow
- Container image scanning, SBOM, image signing, registry security
- Admission controller, Infrastructure as Code, CI/CD
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Paid time off
- Retirement plan
- Vision insurance
Nice to have
- Direct, hands-on Wiz platform experience is a significant plus.
- Container image/repository scanning experience.
- Deeper Terraform or IaC pipeline background.
- Open to strong, trainable candidates with somewhat less hands-on experience, as long as foundational cloud and container security skills are solid.
Contract details
- Duration: 6 months initial; strong intent to convert to full-time
- Engagement length: engagements on this team have extended up to 4 years
- Schedule: full-time, approximately 3 days/week onsite
- Pay: USD 65 per hour
Location & work authorization
- Work location: Hybrid remote in New York, NY 10001
- Primary location: New York, NY (hybrid)
- Secondary location: NY tri-state area (NJ, Philadelphia, NYC) considered
- Strong preference: Toronto, ON
- Work authorization: GC or USC only
Interview process
- Panel interview with the Hiring Manager and two technical leads