Findings Management Engineer / Posture Management Engineer / Containers/Kubernetes Engineer
2 days ago
Dallas
Please find details for this position below: Client: Banking/Financial Industry Title: Information Security Engineer / Findings Management Engineer / Posture Management Engineer / Containers/Kubernetes Engineer - 04 Openings Location: Charlotte, NC/Phoenix, AZ/Chandler, AZ/Dallas, TX/Irving, TX – Hybrid Roles Duration: 12-24+ Month (s) Extend or Convert based on performances Job Descriptions - 1 - Findings Management Engineer REQUIRED SKILLS: • 5+ years of Information Security Engineering experience, • 2+ years of experience with and strong understanding of Azure and Google public cloud – platforms, services, configurations, workloads, and hardening practices, • 1+ years of experience with Wiz or a similar cloud security or “CNAPP” product, • 1+ years of experience with scripting/automation languages such as Python, Bash, Terraform and/or PowerShell, • 1+ year of experience delivering integration between cloud security tools and other enterprise tools such as Splunk Cloud and ServiceNow, • 1+ year experience with data visualization/reporting tools such as PowerBI, Tableau or similar technologies, • Solid understanding of Identity & Access Management, as well as Information Protection concepts as they apply to monitoring and responding to related alerts/findings, • Strong verbal and written communication skills, • Proven ability to work independently, as well as having strong interpersonal skills to work effectively within a Team and with partners, • Strong analytical skills, proven critical thinking capabilities and ability to solve complex problems with minimal direct oversight, • Intermediate to advanced experience working with Microsoft Office products (e.g. Word, Excel, PowerPoint, Visio, Outlook, MS Teams, SharePoint), • Ability to handle multiple, high priority deliverables concurrently, • Ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with stakeholders and partners, • 1+ year experience working on teams practicing Agile Scrum or Kanban methodologies DESIRED QUALIFICATIONS: • Experience supporting Cloud implementation/migrations and/or Cloud Security engineering and/or operations, • Experience with databases such as MongoDB or similar, • Experience with Microsoft Defender, Google Security Command Center, Aqua Security, Microsoft Sentinel or HashiCorp Sentinel, • Experience with change and incident management practices in large enterprises, • Understanding of information security threats, trends and industry best practices and security tools, • Finance sector security experience or other regulated industry (e.g., utilities, health care, government), • Familiarity with various cloud security and related risk frameworks (Cloud Security Alliance (CSA), CIS, NIST, etc.), • Security certifications such as Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), or equivalent, CISA, CISM, CISSP, CRISC, CCSK, • Microsoft Azure and/or Google Cloud Certifications, • Kubernetes Security (CKS) certification Job Details 2 - Posture Management Engineer - 02 Openings: KEY RESPONSIBILITIES: • Leveraging your deep expertise with automation to “semi-automate” Rego Policy as Code development, leveraged to monitor for cloud resource misconfiguration/config. drift., • Engineering and support for the migration of CSPM capabilities from Palo Alto Prisma Cloud Enterprise to Wiz., • Act as the subject matter expert (SME) for Wiz capabilities, roadmap features, and best practices specific to CSPM., • Enable and tune Wiz detection for: o Public Cloud mis-configurations o Public Cloud config drift o Ad-hoc, on demand mis-config. scanning for Developers w/ IDE integration REQUIRED SKILLS: • 5+ years of Information Security Engineering experience, • 4+ years of Intermediate to Advanced experience with Terraform/automation, • 2+ years of practical experience and strong understanding of Azure & Google public cloud – platforms, services, configurations, workloads & hardening practices, • 1+ year of experience with Resource Query Language (RQL) and/or Rego policy dev, • Experience with extracting, transforming, and loading data via REST API endpoints, • Advanced experience with Python programming/automation, • Familiarity with CI/CD tools (GitHub Actions, GitLab CI, Jenkins, Azure DevOps), • Strong verbal and written communication skills, • Proven ability to work independently, as well as having strong interpersonal skills to work effectively within a Team and with partners, • Strong analytical skills, proven critical thinking capabilities and ability to solve complex problems with minimal direct oversight, • Intermediate to advanced experience working with Microsoft Office products (e.g. Word, Excel, PowerPoint, Visio, Outlook, MS Teams, SharePoint), • Ability to handle multiple, high priority deliverables concurrently, • Ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with stakeholders and partners, • 1+ year experience working on teams practicing Agile Scrum or Kanban methodologies DESIRED SKILLS: • 1+ year of deep Wiz experience, in either an engineering or support role, • Advanced experience with Rego policy automation, • Knowledge and understanding of DevSecOps and deployment automation to cloud environments, • Expertise and experience with API driven automation of policy creation, • Expertise and experience with Infrastructure as Code (IaC) and/or Policy as Code (Client) concepts/tools, • Expertise with automated testing, • Intermediate to advanced experience with Kubernetes, preferably AKS/GKE/OCP, • Familiarity with various cloud security and related risk frameworks (Cloud Security Alliance (CSA), CIS, NIST, etc.), • Experience with change and incident management practices in large enterprises, • Security certifications such as Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), or equivalent, CISA, CISM, CISSP, CRISC, CCSK, • Microsoft Azure and/or Google Cloud Certifications Job Details - 3 - Lead Containers/Kubernetes Engineer: KEY RESPONSIBILITIES: • Implement, configure, and manage the Wiz CNAPP platform across multi cloud environments (AWS, Azure, GCP, Kubernetes)., • Onboard cloud accounts, subscriptions, projects, and Kubernetes clusters into Wiz., • Partner with DevSecOps and Platform teams to integrate Wiz into: o CI/CD pipelines o Container and Kubernetes workflows • Deploy and manage Wiz Sensor in large scale for enhanced workload and Kubernetes visibility, including host level telemetry, vulnerability detection, and configuration assessment., • Automate Wiz Sensor onboarding and lifecycle management to ensure consistent, repeatable deployments., • Enabling and operating Wiz Container Registry Scanning across enterprise container registries (e.g. ACR, GCR, Artifactory)., • Enable and tune Wiz detection for: o Vulnerabilities (Containers, serverless) o Container Security events o Network exposure and attack paths REQUIRED SKILLS: • 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education, • 4+ years of experience in Cloud Security/Engineering and DevSecOps, • 2+ years of practical experience and strong understanding of Azure & Google public cloud – platforms, services, configurations, workloads & hardening practices, • Hands on experience deploying &/or doing admin for Wiz in large environments, • Strong understanding of Azure/GCP architecture, Kubernetes and container security concepts, IAM, networking, and cloud-native services, • Advanced experience with Python programming/automation, • Familiarity with CI/CD tools (GitHub Actions, GitLab CI, Jenkins, Azure DevOps), • Strong verbal and written communication skills, • Proven ability to work independently, as well as having strong interpersonal skills to work effectively within a Team and with partners, • Strong analytical skills, proven critical thinking capabilities and ability to solve complex problems with minimal direct oversight, • Intermediate to advanced experience working with Microsoft Office products (e.g. Word, Excel, PowerPoint, Visio, Outlook, MS Teams, SharePoint), • Ability to handle multiple, high priority deliverables concurrently, • Ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with stakeholders and partners, • 1+ year experience working on teams practicing Agile Scrum or Kanban methodologies DESIRED SKILLS: • Experience integrating CNAPP tools with SIEM/SOAR platforms, • Background in vulnerability management or application security, • Experience supporting regulated or enterprise environments, • Experience with change and incident management practices in large enterprises, • Familiarity with various cloud security and related risk frameworks (Cloud Security Alliance (CSA), CIS, NIST, etc.), • Experience with change and incident management practices in large enterprises, • Security certifications such as Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), or equivalent, CISA, CISM, CISSP, CRISC, CCSK, • Microsoft Azure and/or Google Cloud Certifications, • Kubernetes Security (CKS) certification EEO: Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.