> Markdown version of [/jobs/ext/2590746-sr-security-engineer-wiz](https://www.wearedevelopers.com/jobs/ext/2590746-sr-security-engineer-wiz). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer (WIZ) - **Company:** MatchPoint Solutions - **Location:** Maryland Heights, MO, United States (Remote available) - **Experience:** Expert - **Salary:** $124,800.0 - $135,200.0 - **Contract:** Temporary contract - **Skills:** Kubernetes Security, Artificial Intelligence, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Information Leak Prevention, Identity and Access Management, Azure Machine Learning, Software Vulnerability Management, Data Logging, Data Layers, Kubernetes, Terraform, Data Pipelines, Devsecops, Servicenow - **Published:** August 31, 2026 - **Apply:** https://www.careerjet.com/jobad/usce8709727d494036c90d6691945035f7 ## About the Role * Strong cloud security knowledge spanning AI/ML platforms, model pipelines, data layers, IAM, networking, and logging. * Hands-on Wiz CNAPP expertise (CSPM, CIEM, DSPM, CWPP), including experience applying it to AI workloads, model hosting, and data pipelines. * Experience designing security controls and architecture at the model, data, and platform levels - both preventive and detective. * Compliance-as-Code fluency, including mapping Wiz findings to STIGs, native cloud policies, CI/CD, and governance workflows. * Ability to interpret Wiz risk graphs and communicate risk-based exposure analysis: model misuse, data leakage, privilege escalation, and blast radius. * Kubernetes experience across AKS, GKE, and EKS. * Working knowledge of Terraform, Helm, and GitOps-based pipelines. * Nice to Have * Direct, hands-on Wiz platform experience is a significant plus. * Container image / repository scanning experience. * Deeper Terraform or IaC pipeline background. Open to strong, trainable candidates with somewhat less hands-on experience, provided their foundational cloud and container security skills are solid. ## Description * Design, implement, and maintain cloud-native container security controls across Kubernetes platforms (AKS, GKE, and EKS). * Develop, tune, and maintain container threat detection rules to identify malicious activity, anomalous behavior, and indicators of compromise across cloud environments. * Monitor runtime security events, investigate security alerts, and lead triage and incident response for container and Kubernetes workloads. * Deploy, configure, and optimize Wiz Defend/CWPP capabilities, including runtime sensors, workload protection, and attack path analysis. * Build and automate security guardrails, admission controller policies, and preventative controls using Infrastructure as Code (Terraform, Helm, GitOps). * Secure the container software supply chain through image scanning, SBOM validation, image signing, and registry security. * Identify, prioritize, and remediate container vulnerabilities and misconfigurations using risk-based exposure analysis. * Develop and maintain Compliance-as-Code policies aligned with CIS, NIST, and STIG security benchmarks. * Integrate security findings and threat intelligence into ServiceNow and enterprise vulnerability management workflows. * Partner with Security Operations, Cloud Engineering, DevSecOps, and application teams to strengthen detection coverage, incident response, and overall cloud security posture. * Conduct threat hunting and proactive analysis to identify emerging threats, improve detection logic, and enhance runtime protection capabilities. * Support post-incident reviews through root cause analysis, corrective-action recommendations, and continuous improvement of detection and response., Description: CarShield is seeking an experienced Network Engineer to join its growing Infrastructure team. In this role, you will design, implement, monitor, and manage the organ… + 1 day ago ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)