wiz.io - Application Security Product Analyst
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• 1+ years of hands-on experience in AppSec or penetration testing, including proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix. • Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP). • Hands-on experience with Linux, Windows, Docker, Kubernetes, and a strong command of web protocols (HTTP/S, REST, GraphQL) and auth mechanisms (OAuth, SAML). • Proficiency in scripting languages such as Python, Bash, or Go to automate security tasks and interact directly with the codebase. • An analytical mindset with the ability to diagnose complex logs and scans to distinguish between tool failures, configuration issues, and valid security findings. • Self-motivated with the ability to work collaboratively and communicate high-stakes security concepts effectively across teams. • Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context. • SaaS and cloud experience with familiarity in AWS, Azure, or GCP environments and modern cloud-native architectures. • A red teaming background with experience in simulated adversarial attacks and bypassing standard WAF or security controls. • Applicants must have the legal right to work in the country where the position is based, without the need for visa sponsorship. This role does not offer visa sponsorship.
Responsibilities
• Engineer Detection & Attack Logic: Develop advanced detection algorithms to classify cloud technologies while fine-tuning the attack policies that define how our agents identify and exploit vulnerabilities. • Validate Complex Findings: Analyze cloud services, APIs, and log payloads to review complex attack paths, reducing false positives and ensuring compliance with industry standards. • Validate Complex Findings: • Research Novel Threats: Stay at the forefront of novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for the Wiz DAST engine. • Research Novel Threats: • Drive Product Evolution: Collaborate directly with Research, Backend, and R&D teams to turn operational insights into feature requests, positioning Wiz as the market leader in vulnerability management. • Drive Product Evolution:
No credit card. Takes 10 seconds.