Wiz Administrator (Cloud Security Platform Engineer)

Insight Global
Lincolnshire, IL, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$114,400.0 - $145,600.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Build Automation Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Database Cloud Engineering Cyber Security Continuous Integration Data Discovery
+23 more
Data Security DevOps Identity and Access Management Python (Programming Language) PCI Data Security Standards Performance Tuning Windows PowerShell Role-Based Access Control Security Information and Event Management Software Engineering Software Vulnerability Management Software Repository Google Cloud IT General Controls (ITGC) Kubernetes Helm Charts Kubernetes Information Technology Graphql CIS Benchmarks Terraform Prisma Cloud Platform Software Version Control Security Orchestration, Automation & Response

Job description

A large retailer is seeking a Wiz Administrator to own the day-to-day operation, tuning, and continuous improvement of our Wiz cloud-native application protection platform (CNAPP) across AWS, Google Cloud, Azure, Kubernetes, and container workloads. This is a hands-on technical role for someone who wants to be the single accountable owner of a security platform end to end.

The successful candidate does more than watch a dashboard. You will configure and maintain the Wiz deployment, triage and tune the findings it surfaces, drive issues to closure with the cloud, application, and infrastructure teams that own the underlying resources, and steadily reduce the organization’s cloud attack surface. You will translate Wiz Security Graph findings into prioritized, actionable remediation work - and where possible, automate that work away entirely., Platform Administration & Configuration

  • Own the Wiz tenant end to end: cloud account and subscription connectors, projects, folders, scoping, role-based access control, SSO/SCIM integration, and license utilization.

  • Deploy and maintain Wiz collection components including the Wiz Sensor for runtime visibility, admission controllers for Kubernetes clusters, outposts for data scanning, and container registry connectors.

  • Onboard new cloud accounts, subscriptions, projects, clusters, and code repositories as the environment grows; validate coverage and remediate scanning gaps.

  • Maintain platform hygiene: connector health, ingestion failures, permission drift, agent/sensor version currency, and scheduled maintenance windows.

  • Manage upgrades, feature enablement, and vendor release evaluation; maintain the Wiz relationship alongside IT vendor management.

Alerting, Detection & Triage

  • Design, build, and tune Wiz alert rules, policies, and controls so that alerts are high-signal, correctly routed, and owned by a named team.

  • Serve as first-line triage for Wiz findings: validate severity, eliminate false positives, confirm exploitability and blast radius using the Wiz Security Graph, and escalate genuine risk quickly.

  • Integrate Wiz alerting into existing operational channels - ITSM ticketing, Slack, email, SIEM, and on-call escalation - so findings land where work actually gets done.

  • Establish and maintain severity definitions, SLA targets, and escalation paths for toxic combinations, publicly exposed assets, exposed secrets, and critical vulnerabilities.

  • Participate in cloud security incident response, supplying Wiz-derived context on affected resources, identity paths, and lateral movement potential.

Vulnerability & Risk Remediation

  • Drive findings to closure by partnering with cloud engineering, DevOps, application development, and infrastructure teams; track remediation to completion rather than handing off and moving on.

  • Maintain a prioritized cloud risk backlog and run recurring remediation reviews with the accountable owning teams.

  • Analyze recurring findings for root cause and push fixes upstream into golden images, Terraform modules, Helm charts, and CI/CD pipeline gates.

  • Manage the exception process: document accepted risks, compensating controls, expiration dates, and periodic re-review.

  • Review cloud entitlements (CIEM) findings and partner with IAM to reduce excessive and unused permissions.

Automation & Integration

  • Build automation rules and workflows in Wiz to auto-create tickets, notify owners, apply resource tags, and where appropriate auto-remediate low-risk misconfigurations.

  • Develop and maintain scripts and integrations against the Wiz API and GraphQL endpoints for reporting, bulk operations, and data export.

  • Integrate Wiz Code / IaC scanning and secrets detection into source control and CI/CD pipelines so issues are caught before deployment.

  • Feed Wiz data into enterprise reporting and observability platforms to support unified risk visibility.

Reporting, Compliance & Governance

  • Produce recurring executive and operational reporting on cloud security posture, risk trend, remediation velocity, and SLA attainment.

  • Map and maintain Wiz compliance frameworks to CWGS obligations including PCI DSS, SOX ITGC, CIS Benchmarks, and internal security standards.

  • Supply evidence and control artifacts to internal audit, external auditors, and cyber insurance reviews.

  • Document platform configuration, runbooks, triage procedures, and remediation playbooks; keep them current.

Continuous Improvement & Enablement

  • Continuously refine policies and controls to reduce alert volume while increasing detection of material risk.

  • Train and enable cloud, application, and infrastructure teams to self-serve within Wiz for their own projects and scopes.

  • Benchmark posture over time and recommend platform, process, and architectural improvements to leadership.

  • Stay current on cloud attack techniques, CNAPP capabilities, and Wiz product roadmap; pilot new capabilities before broad rollout.

Requirements

  • 5+ years in cloud security, cloud infrastructure engineering, security operations, or vulnerability management.

  • 2+ years of hands-on administration of a CNAPP or cloud security posture management platform (Wiz strongly preferred; Prisma Cloud, Orca, Lacework, Microsoft Defender for Cloud, or Aqua considered).

  • Working proficiency across at least two major cloud providers (AWS, Google Cloud, Azure), including IAM models, networking, and native security services.

  • Demonstrated ability to triage security findings, assess real-world exploitability, and prioritize based on business risk rather than raw severity score.

  • Hands-on experience with containers and Kubernetes, including cluster security concepts and workload scanning.

  • Scripting and automation ability (Python, PowerShell, or Bash) and comfort working with REST/GraphQL APIs.

  • Familiarity with infrastructure as code (Terraform preferred) and CI/CD pipelines.

  • Strong written communication and the interpersonal skill to drive remediation with teams that do not report to you.

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience. * Direct Wiz administration experience, including sensor deployment, automation rules, custom controls, and API usage.

  • Cloud or security certifications such as AWS/Azure/GCP Security Specialty, CKS, CISSP, or GIAC Cloud Security.

  • Experience supporting PCI DSS and SOX ITGC control environments in a public company.

  • Background in retail, multi-site, or high-transaction e-commerce environments.

  • Experience integrating security tooling with SIEM, SOAR, ITSM, and observability platforms.

  • Exposure to data security posture management (DSPM) and sensitive data discovery in cloud data stores.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all