Information Security Engineer
Role details
Job location
Tech stack
Job description
We are seeking an experienced Information Security Engineer to join the Cloud Workload Lifecycle Security (CWLS) team within the Vulnerability & Patch Management organization. This role will support a strategic cloud security initiative focused on the migration from Prism Cloud Enterprise to Wiz CNAPP (Cloud Native Application Protection Platform).
The successful candidate will play a key role in managing cloud security findings, vulnerability data, compliance monitoring, and remediation efforts across public and private cloud environments. This position requires a combination of cloud security expertise, data analytics, automation, and stakeholder collaboration. Responsibilities
- Configure, support, and optimize the Wiz CNAPP platform, with emphasis on Findings Management.
- Define, operationalize, and maintain cloud security alerts and findings.
- Analyze findings generated from Cloud Workload Protection Platform (CWPP) and Cloud Security Posture Management (CSPM) capabilities.
- Build and maintain reporting dashboards and visualizations using tools such as Power BI or Tableau.
- Develop automation solutions and utility scripts to improve operational efficiency.
- Create Python-based pipelines to collect, enrich, merge, and analyze security and cloud datasets.
- Partner with engineering and application teams to drive remediation of cloud security risks and vulnerabilities.
- Support automation initiatives related to findings reduction and risk remediation.
- Contribute to cloud security governance, vulnerability management, and compliance monitoring efforts.
- Work within Agile delivery environments utilizing Scrum or Kanban methodologies.
Requirements
- 5+ years of experience in Information Security, Cloud Security, Cybersecurity Engineering, or a related field.
- 1+ year of hands-on experience with Wiz.
- Experience managing cloud security findings, vulnerabilities, compliance issues, or security operations workflows.
- Strong Python scripting and automation experience.
- Experience building dashboards and reporting solutions using Power BI, Tableau, or similar tools.
- Knowledge of cloud-native security concepts, including container and Kubernetes security.
- Experience working with Azure, Google Cloud Platform (Google Cloud Platform), AWS, or multi-cloud environments.
- Strong analytical and problem-solving skills with the ability to operate independently.
- Excellent written and verbal communication skills.
- Experience managing multiple priorities in a fast-paced environment.
- Proficiency with Microsoft Office tools including Excel, PowerPoint, Outlook, Teams, and SharePoint.
- Experience working on Agile Scrum or Kanban teams., * Experience supporting enterprise cloud migrations or cloud security transformation initiatives.
- Experience with MongoDB or similar databases.
- Familiarity with Microsoft Defender, Microsoft Sentinel, Google Security Command Center, Aqua Security, or HashiCorp Sentinel.
- Knowledge of incident management and change management processes within large organizations.
- Understanding of security frameworks and standards such as:
- NIST
- CIS Benchmarks
- Cloud Security Alliance (CSA)
- Experience within highly regulated industries such as financial services, healthcare, utilities, or government.
- Professional security certifications, including:
- CISSP
- CISM
- CISA
- CRISC
- CCSK
- GIAC Certifications
- Azure and/or Google Cloud certifications.
- Certified Kubernetes Security Specialist (CKS) certification.
Additional Notes
- This role supports a focused migration effort and is expected to remain a 6-month engagement.
- Candidates must be comfortable discussing and demonstrating their technical experience during interviews.
- Use of AI-assisted responses during interviews is not permitted.
- All candidates must be submitted through Beeline. Please do not send resumes directly to the hiring team.
Primary Location Preference: Charlotte, NC (Hybrid, 3 days onsite weekly)