Full-Time
Cloud security platform for DevOps teams
No salary listed
Remote in UK
Remote
Eligible to work in the United Kingdom without visa sponsorship.
See people who can refer or advise you
Wiz.io provides a cloud security platform for security, development, and DevOps teams, sold as a subscription for enterprise customers. Its platform acts as a unified security command center that plugs into development workflows to protect containers, Kubernetes, and cloud environments from design to live operation, scanning IaC, container images, and VM images for vulnerabilities and misconfigurations, monitoring for threats, and enforcing automated compliance. It differentiates itself by delivering end-to-end coverage across IaC, containers, and cloud workloads in a self-service, scalable model tailored for large enterprises with real-time threat detection and data-exposure safeguards. Its goal is to help businesses run cloud-native applications securely and efficiently while preventing data breaches and simplifying regulatory compliance.
Company Size
1,001-5,000
Company Stage
Acquired
Total Funding
$1.9B
Headquarters
New York City, New York
Founded
2020
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Professional Development Budget
Micware & Wiz secure automotive AI clouds. 3h ago · 0:00 listen · Source: Quiver Quantitative Summary. Micware and Wiz have launched AI-driven cloud security solutions specifically for the automotive industry. This collaboration, led by Micware Navigations, aims to enhance safety for cloud environments as AI applications increase. The new solutions leverage Wiz's platform to provide comprehensive visibility and risk assessment across customer infrastructures. This allows for rapid deployment and proactive responses to threats. Micware Navigations will offer end-to-end services, including risk assessment, system design, and ongoing operations support. This is crucial for securing reliable cloud applications amidst evolving AI security risks. The bottom line is this partnership positions Micware to address critical security challenges in the automotive and mobility sectors, which impacts the safety of future vehicles. This is an AI-generated audio summary. Always check the original source for complete reporting.
Closing the API security gap: Postman and Wiz, better together. August 3, 2026 What do you get when you combine Postman's API platform with Wiz's cloud security intelligence? A single, unified view of every API your team owns, and the risk that comes with it. Wiz's runtime security is now embedded directly in the Postman API Catalog, so your team can see, understand, and fix API risk before it becomes a breach. The gap no one is talking about. Security teams have made real progress in understanding what's running in production. Tools like Wiz give CISOs and security engineers a powerful lens into deployed services, surfacing runtime risk, misconfigurations, and exposure across cloud environments. But there's a blind spot most organizations haven't fully addressed: the APIs that haven't shipped yet. APIs that are actively being designed, built, and reviewed, but haven't reached production, carry real risk. Today, they're largely invisible to security tooling. That's the gap Postman, Inc. is closing together with Wiz. How the current workflow breaks down. In the existing model, a security engineer using Wiz has to manually pull risk signals from the dashboard, translate those findings, and then track down the right developer to fix the issue, often across tools and teams. Context gets lost in Slack threads and email handoffs. Fixes happen slowly, if at all. The problem isn't visibility. It's where that visibility lives. When security signals exist outside the developer's workspace, the workflow breaks down at the handoff. The Postman API Catalog has always given teams a comprehensive view of their known APIs. Wiz has always excelled at highlighting risk in what's deployed. But until now, neither tool could see the other's picture completely. Before: Pull risk from Wiz, find the engineer, fix in real time. After: Risk surfaces in Postman, inside the API Catalog, in context. Integrating Wiz into Postman's API Catalog. One of the key value drivers for Postman customers has always been its commitment to API security, and the Wiz CISO dashboard has always been a core component of that. This new integration takes that a step further by embedding the Wiz dashboard right into the Postman platform through the Postman API Catalog. It's exactly what it sounds like: Wiz's security intelligence, embedded natively inside the Postman platform. By embedding the Wiz CLI and dashboard directly into Postman, teams get a unified scorecard with operational health and a complete inventory of every known service, all in one view. This matters because it fulfills the first mandate of any security program. If you have services, you need visibility into them before you can create and enforce policy. That visibility now lives in the tool your developers already use every day. Think of it as the intersection of Postman's API governance and Wiz's cloud security intelligence: every known service, its operational health, and its security posture, in a single, actionable view. Three capabilities that change the workflow. * See what Wiz can't see alone. APIs on the left side of the lifecycle, undeployed and in development, are invisible to runtime scanners. The API Catalog surfaces them and now flags risk before they ship. * Full-spectrum coverage. Deployed APIs get Wiz's runtime risk analysis. Undeployed APIs get policy and design-time checks. Current risk and future risk, in one place. * Embedded, not bolted on. The dashboard lives inside Postman, not as a separate tab to remember, but as part of the API Catalog workflow your team already uses. Shift left on security, for real. "Shift left" has become a cliche. The principle still holds: catching a security problem at design time is orders of magnitude cheaper than fixing it in production. The Wiz API Catalog dashboard makes that possible in a way that wasn't feasible before. When a developer opens an API in Postman, they'll see a scorecard alongside everything else, not because they went looking for it, but because the signal came to them. That's the model that actually changes behavior. "The new dashboard shows risks based on APIs that aren't deployed yet, before they become a problem. That's how we move from reactive to preventive." Get started today. The Wiz API Catalog dashboard is available now for customers on Postman's Enterprise plan. To turn on the integration, go to your API Catalog settings or reach out to your Postman account team. Postman, Inc. is just getting started. Expect deeper workflows, expanded coverage, and more customer stories in the weeks ahead. In the meantime, Postman, Inc.'d love to hear how your team is using it. Resources. In this post. Sam Chehab
Coalfire has joined the Wiz Partner Alliance to combine cybersecurity services with cloud security technology. The partnership will integrate Wiz's platform into Coalfire's cloud posture assessment, exposure management, and compliance management services. The collaboration aims to connect security and compliance for cloud customers in regulated industries. Coalfire brings compliance expertise, cloud engineering, and managed security capabilities, whilst Wiz provides cloud-native visibility and risk analysis tools. "Exposure Management Powered by Wiz" will launch on the Google Marketplace. The partnership offers customers flexible options ranging from one-time cloud assessments to continuous compliance monitoring. Services will include managed posture analysis, attack path review, and drift governance, helping organisations transition from periodic manual reviews to ongoing operational support.
Everyone can find vulnerabilities now. Here is how to tell them apart. Winning at benchmark leaderboards is not the same as securing your applications in the real world. This is how to tell the difference. Jul 29, 2026 In the space of about seventy-two hours this month, a cloud security giant, a hyperscaler, a bug bounty platform, and a Y Combinator startup all announced that their AI can find real vulnerabilities in real software. If you buy security tooling, your inbox is about to get loud. Every one of those announcements uses the same three words: autonomous, validated, exploitable. They do not mean the same thing. So here is the field guide. What actually happened, what it signals, and the three questions that separate the products from the press releases. What happened. Wiz, now part of Google, announced Project Atlas, an agentic system for vulnerability research. It took the top spot on CyberGym with a 90.9 percent success rate and, per Wiz, has surfaced more than two hundred previously unknown vulnerabilities in open source code that has been fuzzed and reviewed for years. Days later Microsoft claimed 95.95 percent on the same benchmark with its own agent harness. Bugcrowd launched Savant Pathseeker, an agentic pentesting product for web applications and APIs, currently in early access. Nebula Security came out of Y Combinator with Vega, an AI agent built by members of a world champion CTF team, with a public catalog of over a thousand bugs found. And Aikido, having already acquired two autonomous pentesting companies and an AI code review company, bought another security startup outright. Four announcements. One conclusion, which Xint has been arguing for two years: AI can now find vulnerabilities that human experts find, at a speed and cost that human experts cannot match. That question is settled. Stop debating it. The interesting question is the one nobody is answering in their launch post. The crash test problem. Car manufacturers publish crash test ratings. Five stars is meaningful. It is also a controlled collision, at a known speed, into a known barrier, with sensors already positioned where the engineers expect the impact. Nobody confuses that with driving. Benchmarks work the same way. CyberGym, the benchmark everyone raced to the top of this month, hands a system a vulnerability that already exists. It provides the description. It provides the relevant code. Then it asks whether the system can produce a working proof of concept. That is a genuinely useful measurement, and the teams competing on it are doing serious engineering. But Wiz says this themselves, to their credit, in the same post announcing their score: reproducing a known vulnerability is a different and easier problem than discovering an unknown one. Real discovery starts from a blank page. No description. No pointer to the vulnerable function. A codebase that changes every day. That is the job. No public benchmark measures it yet. Which means the leaderboard is telling you something real about engineering quality and almost nothing about what the product will do to your codebase on a Tuesday. Xint has chosen not to optimize for that leaderboard. Not because Xint would do badly on it, but because tuning a product to score well on known-bug reproduction is a decision to get better at the easy half of the problem. Xint would rather be measured on what Xint find in your code that nobody has ever found before. Three questions worth asking any vendor. What did it start from? There is a wide gap between a system handed a vulnerability and asked to prove it, and a system handed a repository and asked what is wrong with it. Ask which one you are buying. Ask how many of the findings in the last customer report were previously unknown. What can it actually see? This one splits the market cleanly, and most buyers miss it. Some of these products test your running application from the outside. They send traffic, watch responses, and reason about behavior. They cannot read your source code, because they do not have it. Others read your source code. They can trace a data flow across forty files and three services. They cannot tell you whether the endpoint is reachable in production behind your WAF. Both are legitimate. Neither is complete. An attacker does not respect that boundary, and the vulnerabilities that end careers usually live in the seam: a logic flaw that only makes sense when you can see the code and the running system at the same time. That seam is the reason Xint build both. Xint Code reads the source. Xint Web attacks the live application. They are converging into one platform because the interesting findings are the ones that need both halves. What does it hand you at the end? This is the question that actually determines whether you got value. A weakness is a pattern in code that could be dangerous. A vulnerability is a specific, exploitable path through your system, with the steps to reproduce it. Traditional SAST hands you thousands of the first and calls it coverage. Your engineers then spend their quarter deciding which ones are real. Xint built Xint around a simple constraint: if Xint cannot show you how to trigger it, Xint do not report it. Reproduction steps are not a nice feature on the finding detail page. They are the proof that the finding is real, and they are the difference between a report your engineers act on and a report your engineers argue with. That is also where the market is heading whether vendors like it or not. Regulators have started asking for demonstrated exploitability rather than a scanner output and a signature. Point-in-time attestation is on its way out. If your tooling cannot produce evidence, you are going to feel that within a year. What the incumbents are conceding. Read Bugcrowd's Pathseeker FAQ carefully. In the middle of a launch announcement, they state that agentic pentesting is not suited to complex business logic flaws, exploit chaining, or zero-days, and that it cannot satisfy compliance requirements on its own. That is an honest description of a product designed to raise a floor, with human researchers sold separately to reach the ceiling. It is a reasonable business. It is also a very different bet from ours. Xint think the ceiling is the product. Business logic, chained exploits, and previously unknown vulnerabilities are not the residue left over for humans after the machine has done the easy parts. They are the whole reason anyone pays for offensive security. Theori's team has spent a decade at Pwn2Own and in DARPA research proving that; the engine is built by the people who do that work, not around them. What to do with all this. Do not buy the benchmark. Ask what the system found last month that nobody had found before, and ask to see the reproduction steps. Do not buy half the picture. Ask whether the vendor can see your source code and your running application, or only one of them, and ask what they think lives in the gap. And do not let anyone sell you volume. The number of findings is the easiest metric in this industry to inflate and the least correlated with whether you are actually safer. There is a lot happening. Most of it is real. The question is not whether AI can find vulnerabilities anymore. It is who can prove the ones they find. If you want to see what that looks like against your own code, Xint will show you. Get vulnerability research and security insights from the Xint team, direct to your inbox.
Prisma Cloud vs Aqua vs Wiz vs Sysdig: CNAPP compared. Four serious CNAPP platforms, four different philosophies: agentless graphs, runtime detection, container lifecycle, and all-in-one breadth. Here is how to choose. Every cloud security vendor now calls itself a CNAPP, a Cloud-Native Application Protection Platform. The label is real: it means one product that folds together posture management, workload protection, entitlements, and increasingly runtime detection, instead of four separate tools. The problem is that Prisma Cloud, Aqua, Wiz, and Sysdig all wear the CNAPP badge while approaching the job from very different starting points. Pick based on the badge and you will overpay for capabilities you do not use, or miss the one that actually matters for your environment. Here is what each platform is genuinely good at, and who should choose which. What CNAPP has to cover. A complete CNAPP spans a few pillars: CSPM (cloud posture and misconfigurations), CWPP (workload and container protection), CIEM (cloud entitlements and identity), code and pipeline scanning, and CDR (cloud detection and response at runtime). No vendor is equally strong across all of them, and their origins tell you where their strength lies. Wiz: agentless-first, built for speed to value. Wiz grew fast for one reason: it reads your cloud through an agentless, snapshot-based scan and builds a graph of how risks connect. Instead of a flat list of thousands of findings, it surfaces attack paths, the toxic combinations of exposure, identity, and vulnerability that actually lead to a breach. Time to first value is short because there are no agents to roll out. The tradeoff is that a purely agentless model gives you less deep, continuous runtime visibility than an agent does, which is why Wiz has been adding runtime sensors. Sysdig: runtime detection is the whole point. Sysdig comes from the opposite direction. It was built by the creators of Falco, the open-source runtime security engine, and its strength is deep, real-time detection of what is actually happening inside running workloads. If your priority is catching an active attack in a container the moment it deviates from normal, and doing incident response with rich runtime forensics, Sysdig is the specialist. Its posture and agentless coverage exist, but runtime and cloud detection and response are the core. Aqua: full container and cloud-native lifecycle. Aqua is one of the original container security companies, and it covers the whole lifecycle from build to runtime. It has strong open-source roots as well: Trivy, the widely used vulnerability scanner, and Tracee both come from Aqua. Teams that are deeply container and Kubernetes-centric and want image scanning, supply-chain checks, and runtime protection under one roof gravitate here. Prisma Cloud: breadth over specialization. Prisma Cloud, from Palo Alto Networks, is the broad, mature, enterprise platform. Assembled partly from the Twistlock and RedLock acquisitions, it aims to cover every CNAPP pillar across code, cloud, and runtime in a single suite. Its strength is breadth and integration into a larger Palo Alto security stack. Its reputation for depth comes with a reputation for complexity and cost, so it fits large enterprises with the team to run it more than a lean startup. The honest comparison. | Platform | Core strength | Primary approach | Best fit | | Wiz | Agentless risk graph, attack paths | Agentless-first | Fast, broad visibility with minimal rollout | | Sysdig | Runtime detection and response | Agent / runtime (Falco) | Active-threat detection in running workloads | | Aqua | Container lifecycle security | Build-to-runtime | Container and Kubernetes-centric teams | | Prisma Cloud | All-pillar breadth | Comprehensive suite | Large enterprises wanting one platform | A note on pricing. None of these four publish simple public pricing, and all sell enterprise contracts negotiated on cloud footprint, workloads, and modules. Expect quotes to vary widely based on the number of accounts, workloads, and which pillars you turn on. When you evaluate, price the specific modules you will actually use rather than the full platform, and put the agentless-versus-agent operational cost into the comparison, not just the license. Which one should you choose? * You want fast, broad cloud visibility with minimal deployment: Wiz. The agentless graph and attack-path prioritization are why it spread so quickly. * Your priority is catching and responding to live runtime attacks: Sysdig, whose Falco heritage makes runtime detection its center of gravity. * You are container and Kubernetes-heavy and want full lifecycle coverage: Aqua. * You are a large enterprise standardizing on one broad platform, ideally alongside Palo Alto: Prisma Cloud. Many mature security teams end up running an agentless platform for coverage and a runtime-focused tool for depth, rather than forcing one product to do both jobs equally well. Frequently asked questions. What is a CNAPP? A Cloud-Native Application Protection Platform combines cloud posture management, workload and container protection, cloud entitlements, and runtime detection into one product, replacing several standalone tools. Wiz vs Prisma Cloud, what is the difference? Wiz is agentless-first and known for fast setup and attack-path prioritization. Prisma Cloud is a broader, more comprehensive enterprise suite with deeper runtime and code coverage, and correspondingly more complexity. Which CNAPP is best for runtime security? Sysdig, built by the creators of the open-source Falco engine, specializes in real-time runtime detection and cloud detection and response. Is agentless or agent-based CNAPP better? Agentless (Wiz) gives fast, broad coverage with no rollout, but less continuous runtime depth. Agent-based (Sysdig, Aqua) gives deeper runtime visibility at the cost of deployment. Many teams use both. Which CNAPP is best for containers and Kubernetes? Aqua, whose lineage is container security and whose open-source Trivy scanner is widely used, is the most container-lifecycle-focused of the four. Related reading. * Top 10 CNAPP solutions: the wider field beyond these four, with the full feature breakdown. * Alternatives to Wiz: if agentless is your starting point but Wiz is not the right fit. * AI vulnerability chaining: why attack-path thinking, not isolated findings, is where cloud security is heading.