Application Security Product Analyst

Wiz Wiz · Enterprise · Tel Aviv, Israel · Product Management & Ops

This role operates an AI-driven DAST agent, innovates detection mechanisms for cloud-native technologies, and defines agent rules of engagement to simulate sophisticated attacks and classify the modern attack surface.

What you'd actually do

  1. Develop advanced detection algorithms to classify cloud technologies while fine-tuning the attack policies that define how our agents identify and exploit vulnerabilities.
  2. Analyze cloud services, APIs, and log payloads to review complex attack paths, reducing false positives and ensuring compliance with industry standards.
  3. Stay at the forefront of novel attack vectors and emerging cloud/API threats, translating new techniques into executable behaviors for the Wiz DAST engine.
  4. Collaborate directly with Research, Backend, and R&D teams to turn operational insights into feature requests, positioning Wiz as the market leader in vulnerability management.

Skills

Required

  • 1+ years of hands-on experience in AppSec or penetration testing
  • proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix
  • Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP)
  • Hands-on experience with Linux, Windows, Docker, Kubernetes
  • strong command of web protocols (HTTP/S, REST, GraphQL) and auth mechanisms (OAuth, SAML)
  • Proficiency in scripting languages such as Python, Bash, or Go
  • analytical mindset
  • ability to diagnose complex logs and scans
  • Self-motivated
  • ability to work collaboratively
  • communicate high-stakes security concepts effectively across teams

Nice to have

  • Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context
  • SaaS and cloud experience with familiarity in AWS, Azure, or GCP environments and modern cloud-native architectures
  • A red teaming background with experience in simulated adversarial attacks and bypassing standard WAF or security controls

What the JD emphasized

  • primary operator of our cutting-edge AI-driven Dynamic Application Security Testing (DAST) agent
  • innovating detection mechanisms
  • define the "rules of engagement" for our agents
  • effectively simulate sophisticated attacks
  • accurately classify the modern attack surface
  • Develop advanced detection algorithms
  • fine-tuning the attack policies
  • identify and exploit vulnerabilities
  • Analyze cloud services, APIs, and log payloads
  • review complex attack paths
  • reducing false positives
  • ensuring compliance with industry standards
  • Research Novel Threats
  • forefront of novel attack vectors
  • emerging cloud/API threats
  • translating new techniques into executable behaviors
  • Wiz DAST engine
  • Drive Product Evolution
  • Collaborate directly with Research, Backend, and R&D teams
  • turn operational insights into feature requests
  • positioning Wiz as the market leader in vulnerability management
  • 1+ years of hands-on experience in AppSec or penetration testing
  • proficiency with enterprise tools like Burp Suite, OWASP ZAP, or Acunetix
  • Solid knowledge of networking concepts, the OSI model, and cloud infrastructure (AWS, Azure, or GCP)
  • Hands-on experience with Linux, Windows, Docker, Kubernetes
  • strong command of web protocols (HTTP/S, REST, GraphQL) and auth mechanisms (OAuth, SAML)
  • Proficiency in scripting languages such as Python, Bash, or Go
  • automate security tasks
  • interact directly with the codebase
  • analytical mindset
  • ability to diagnose complex logs and scans
  • distinguish between tool failures, configuration issues, and valid security findings
  • Self-motivated
  • ability to work collaboratively
  • communicate high-stakes security concepts effectively across teams
  • Knowledge of AI/ML and how LLMs or reinforcement learning agents operate within a cybersecurity context
  • SaaS and cloud experience
  • familiarity in AWS, Azure, or GCP environments
  • modern cloud-native architectures
  • red teaming background
  • experience in simulated adversarial attacks
  • bypassing standard WAF or security controls

Other signals

  • AI-driven DAST agent
  • innovating detection mechanisms
  • simulated attacks
  • classify modern attack surface