Wiz
Principal Solutions Engineer - Application Security
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Wiz
Wiz is an Israeli-American cloud security company founded in January 2020 and headquartered in New York City, with engineering teams primarily in Tel Aviv, Israel. The company specializes in a comprehensive cloud security platform that offers deep visibility, risk prioritization, and protection across cloud environments without the need for agents. This allows organizations to secure their cloud infrastructure effectively from development through runtime. Wiz's Cloud-Native Application Protection Platform (CNAPP) integrates various cloud security capabilities, including agentless visibility, runtime protection, and threat detection. Key features include continuous detection of cloud misconfigurations, attack path analysis, and cloud threat intelligence. The platform supports multiple cloud providers and hybrid environments, making it suitable for security, development, and operations teams. Wiz serves a significant portion of Fortune 100 companies, highlighting its strong presence in the market.
Security at Wiz
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Wiz publicly frames AppSec as unified, code-to-cloud security: integrating code, CI/CD/pipelines, IaC, images and runtime into a single, context-rich, risk-driven program.
- Their emphasis is on prioritizing exploitable, business-impacting risks (not raw finding counts), shifting security left into developer workflows while maintaining continuous runtime visibility, and automating evidence, root-cause analysis, ownership mapping and remediation to reduce handoffs and accelerate response.
Security Team
- Public material does not disclose Wiz's internal org chart or named AppSec leaders.
- The operating model Wiz describes is cross-functional: AppSec engineers, CloudSec/CSPM teams, DevSecOps, developers, SOC/IR teams and security engineers are the primary actors.
- Wiz's products are designed to map issues to repository/dev owners and enable collaborative remediation rather than rely on a siloed AppSec group [3][4][5].
Key Initiatives
- Key public priorities and product-driven initiatives: 1) Prioritize exploitable, high-impact risks by combining exploitability, runtime reachability and data sensitivity.
- 2) Shift-left adoption—IDE/PR/CI integrations and one-click fixes—to shorten detection-to-remediation.
- 3) Reduce alert fatigue via graph-based context enrichment and automated ownership mapping.
- 4) Enforce consistent policies/guardrails across commit-to-runtime through a single policy engine.
- 5) Provide continuous runtime monitoring, automated blast-radius/root-cause analysis and forensics to improve incident response.
- 6) Deliver Application Security Posture Management (ASPM) unifying signals across SDLC and production [1][2][3][4][5][6][7][8].
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.