Full-Time

Manager – Solutions Support Engineering

Wiz

Wiz

1,001-5,000 employees

Cloud security platform for DevOps teams

Compensation Overview

$144k - $198k/yr

+ Bonus + Equity

No H1B Sponsorship

Remote in USA

Remote

Must reside in the contiguous United States; provides a US work eligibility note.

Category
Engineering Management (1)
Required Skills
Kubernetes
Microsoft Azure
AWS
Google Cloud Platform

Get referred to Wiz

See people who can refer or advise you

Requirements
  • Technical Leadership: 1+ years managing external technical support teams in a SAAS enviornment while serving as the hands-on, ultimate escalation anchor.
  • AI & Automation: Track record of writing scripts or building tools using AI APIs to automate operational workflows.
  • Cloud Infrastructure: 5+ years of hands-on experience deploying and maintaining AWS, Azure, or GCP infrastructure.
  • Kubernetes & Virtualization: Direct experience configuring and troubleshooting Kubernetes clusters and virtualized environments.
  • Security & Monitoring: Practical experience managing hybrid-cloud identity, security protocols, and monitoring/logging pipelines.
  • Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a “protected person”) and that they reside in the contiguous United States.
Responsibilities
  • Manage, develop, coach and mentor a team of Technical Support Engineers, who are responsible for technical customer support experience within the Wiz product
  • Act as the owner for your team’s accountability and performance - partnering closely with upper management to facilitate performance reviews, performance plans, and any employee relations issues for your direct reports
  • Ensure successful training and onboarding of new hires
  • Guide the team through technical-training and additional learning and development needs
  • Drive projects or initiatives to improve team productivity, process or procedure
  • Collaborate with internal teams and customers on high-priority escalations and act as a resource to resolve escalations from team members as necessary
  • Identify cases that require escalation (either technically or strategically)
  • Create, maintain, and coordinate incident management requests to product or engineering
  • Design and implement solutions that scale the support offering through automations
  • Coordinate with Customer Success Managers to address any technical issues impacting a customer's success
  • Create technical articles or knowledge base (e.g., edit or create news/ knowledge-based articles) that is internal or customer-facing for a better customer support experience
  • Be a customer advocate for timely resolution of the problems reported, understand the environment/network and impact on business

Wiz.io provides a cloud security platform for security, development, and DevOps teams, sold as a subscription for enterprise customers. Its platform acts as a unified security command center that plugs into development workflows to protect containers, Kubernetes, and cloud environments from design to live operation, scanning IaC, container images, and VM images for vulnerabilities and misconfigurations, monitoring for threats, and enforcing automated compliance. It differentiates itself by delivering end-to-end coverage across IaC, containers, and cloud workloads in a self-service, scalable model tailored for large enterprises with real-time threat detection and data-exposure safeguards. Its goal is to help businesses run cloud-native applications securely and efficiently while preventing data breaches and simplifying regulatory compliance.

Company Size

1,001-5,000

Company Stage

Acquired

Total Funding

$1.9B

Headquarters

New York City, New York

Founded

2020

Get referred to Wiz

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Google retained Wiz brand and open-cloud support across AWS, Azure, Oracle, and packaged apps.
  • Wiz Security Agents, Wiz Workflows, and Project Atlas expand AI-native threat detection.
  • June 2026 deals with Keeper, NordStellar, Coalfire, and Base44 widen distribution.

What critics are saying

  • Orca's Delaware patent suit still targets Wiz's agentless cloud monitoring core.
  • Google can fold Wiz into bundled security products, squeezing standalone pricing and hollowing the brand.
  • If Google prioritizes native cloud security, Wiz becomes a feature, not a company.

What makes Wiz unique

  • Agentless Security Graph spans AWS, Azure, GCP, Oracle, workloads, containers, and AI apps.
  • Google closed its thirty-two-billion-dollar acquisition on March 11, 2026, backing Wiz with hyperscale distribution.
  • Wiz Partner Alliance and WIN give enterprise buyers a broad services ecosystem.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

5%

1 year growth

5%

2 year growth

11%
Yahoo Finance
Aug 3rd, 2026
Coalfire joins Wiz Partner Alliance to merge cloud security with compliance management

Coalfire has joined the Wiz Partner Alliance to combine cybersecurity services with cloud security technology. The partnership will integrate Wiz's platform into Coalfire's cloud posture assessment, exposure management, and compliance management services. The collaboration aims to connect security and compliance for cloud customers in regulated industries. Coalfire brings compliance expertise, cloud engineering, and managed security capabilities, whilst Wiz provides cloud-native visibility and risk analysis tools. "Exposure Management Powered by Wiz" will launch on the Google Marketplace. The partnership offers customers flexible options ranging from one-time cloud assessments to continuous compliance monitoring. Services will include managed posture analysis, attack path review, and drift governance, helping organisations transition from periodic manual reviews to ongoing operational support.

Theori
Jul 29th, 2026
Everyone can find vulnerabilities now. Here is how to tell them apart.

Everyone can find vulnerabilities now. Here is how to tell them apart. Winning at benchmark leaderboards is not the same as securing your applications in the real world. This is how to tell the difference. Jul 29, 2026 In the space of about seventy-two hours this month, a cloud security giant, a hyperscaler, a bug bounty platform, and a Y Combinator startup all announced that their AI can find real vulnerabilities in real software. If you buy security tooling, your inbox is about to get loud. Every one of those announcements uses the same three words: autonomous, validated, exploitable. They do not mean the same thing. So here is the field guide. What actually happened, what it signals, and the three questions that separate the products from the press releases. What happened. Wiz, now part of Google, announced Project Atlas, an agentic system for vulnerability research. It took the top spot on CyberGym with a 90.9 percent success rate and, per Wiz, has surfaced more than two hundred previously unknown vulnerabilities in open source code that has been fuzzed and reviewed for years. Days later Microsoft claimed 95.95 percent on the same benchmark with its own agent harness. Bugcrowd launched Savant Pathseeker, an agentic pentesting product for web applications and APIs, currently in early access. Nebula Security came out of Y Combinator with Vega, an AI agent built by members of a world champion CTF team, with a public catalog of over a thousand bugs found. And Aikido, having already acquired two autonomous pentesting companies and an AI code review company, bought another security startup outright. Four announcements. One conclusion, which Xint has been arguing for two years: AI can now find vulnerabilities that human experts find, at a speed and cost that human experts cannot match. That question is settled. Stop debating it. The interesting question is the one nobody is answering in their launch post. The crash test problem. Car manufacturers publish crash test ratings. Five stars is meaningful. It is also a controlled collision, at a known speed, into a known barrier, with sensors already positioned where the engineers expect the impact. Nobody confuses that with driving. Benchmarks work the same way. CyberGym, the benchmark everyone raced to the top of this month, hands a system a vulnerability that already exists. It provides the description. It provides the relevant code. Then it asks whether the system can produce a working proof of concept. That is a genuinely useful measurement, and the teams competing on it are doing serious engineering. But Wiz says this themselves, to their credit, in the same post announcing their score: reproducing a known vulnerability is a different and easier problem than discovering an unknown one. Real discovery starts from a blank page. No description. No pointer to the vulnerable function. A codebase that changes every day. That is the job. No public benchmark measures it yet. Which means the leaderboard is telling you something real about engineering quality and almost nothing about what the product will do to your codebase on a Tuesday. Xint has chosen not to optimize for that leaderboard. Not because Xint would do badly on it, but because tuning a product to score well on known-bug reproduction is a decision to get better at the easy half of the problem. Xint would rather be measured on what Xint find in your code that nobody has ever found before. Three questions worth asking any vendor. What did it start from? There is a wide gap between a system handed a vulnerability and asked to prove it, and a system handed a repository and asked what is wrong with it. Ask which one you are buying. Ask how many of the findings in the last customer report were previously unknown. What can it actually see? This one splits the market cleanly, and most buyers miss it. Some of these products test your running application from the outside. They send traffic, watch responses, and reason about behavior. They cannot read your source code, because they do not have it. Others read your source code. They can trace a data flow across forty files and three services. They cannot tell you whether the endpoint is reachable in production behind your WAF. Both are legitimate. Neither is complete. An attacker does not respect that boundary, and the vulnerabilities that end careers usually live in the seam: a logic flaw that only makes sense when you can see the code and the running system at the same time. That seam is the reason Xint build both. Xint Code reads the source. Xint Web attacks the live application. They are converging into one platform because the interesting findings are the ones that need both halves. What does it hand you at the end? This is the question that actually determines whether you got value. A weakness is a pattern in code that could be dangerous. A vulnerability is a specific, exploitable path through your system, with the steps to reproduce it. Traditional SAST hands you thousands of the first and calls it coverage. Your engineers then spend their quarter deciding which ones are real. Xint built Xint around a simple constraint: if Xint cannot show you how to trigger it, Xint do not report it. Reproduction steps are not a nice feature on the finding detail page. They are the proof that the finding is real, and they are the difference between a report your engineers act on and a report your engineers argue with. That is also where the market is heading whether vendors like it or not. Regulators have started asking for demonstrated exploitability rather than a scanner output and a signature. Point-in-time attestation is on its way out. If your tooling cannot produce evidence, you are going to feel that within a year. What the incumbents are conceding. Read Bugcrowd's Pathseeker FAQ carefully. In the middle of a launch announcement, they state that agentic pentesting is not suited to complex business logic flaws, exploit chaining, or zero-days, and that it cannot satisfy compliance requirements on its own. That is an honest description of a product designed to raise a floor, with human researchers sold separately to reach the ceiling. It is a reasonable business. It is also a very different bet from ours. Xint think the ceiling is the product. Business logic, chained exploits, and previously unknown vulnerabilities are not the residue left over for humans after the machine has done the easy parts. They are the whole reason anyone pays for offensive security. Theori's team has spent a decade at Pwn2Own and in DARPA research proving that; the engine is built by the people who do that work, not around them. What to do with all this. Do not buy the benchmark. Ask what the system found last month that nobody had found before, and ask to see the reproduction steps. Do not buy half the picture. Ask whether the vendor can see your source code and your running application, or only one of them, and ask what they think lives in the gap. And do not let anyone sell you volume. The number of findings is the easiest metric in this industry to inflate and the least correlated with whether you are actually safer. There is a lot happening. Most of it is real. The question is not whether AI can find vulnerabilities anymore. It is who can prove the ones they find. If you want to see what that looks like against your own code, Xint will show you. Get vulnerability research and security insights from the Xint team, direct to your inbox.

BuildWithin
Jul 16th, 2026
Base44 and Wiz team up to catch 'shadow AI' before it ships.

Base44 and Wiz team up to catch 'shadow AI' before it ships. Base44 now scans AI-built apps with Wiz before they ship, targeting shadow AI, apps built inside a company without IT or security ever knowing they exist. BuilderWithin Editorial Team BuilderWithin What happened. Base44 partnered with Wiz, the Google Cloud security platform, to add security scanning directly into its app-building workflow. The stated target is "shadow AI," which Base44 defines as any AI tool, model, or AI-built app that people inside an organization use or create without IT or security's knowledge or approval. It's the AI-era version of shadow IT: tools adopted from the bottom up faster than anyone can track them. Base44 cites a Gartner projection that "by 2030, more than 40% of organizations will experience a security or compliance incident tied to shadow AI." That's a forecast, not a measured outcome, but it's the reasoning behind the partnership. Why it matters. AI app builders exist to let people without a software engineering background ship a working app in hours, complete with a database, logins, and access to real data. That speed is the entire point of a tool like Base44. It also means an app touching real user data can go live before anyone with security responsibility even knows it exists. Base44 frames the tradeoff plainly: an organization can "lock everything down and lose productivity, or let it run and lose visibility." The Wiz integration is an attempt at a third option: keep building fast, but check the app before it ships. Concretely, a builder can run a Wiz scan against an app's code. That scan checks the app against the organization's own existing Wiz security policy and flags things like vulnerable dependencies and risky code patterns. Findings appear inside Base44 so a builder can fix them without switching tools, and the same results also flow to the organization's Wiz dashboard, giving a security team visibility they didn't have before. Base44 also added two account-level controls: restricting which integrations an app is allowed to use, and role-based publishing, meaning an organization can define who is allowed to make an app live and to whom. Who should care. This is built for teams, not solo builders. If you build inside an organization that already has an IT or security function, and that organization uses Wiz, this closes a real gap. Someone can now see what AI-built apps exist and what they're exposed to before those apps reach real users. If you build alone with no security team behind you, the Wiz-specific tooling doesn't apply to you directly. The underlying risk still does. An app you build with a login and a database is only as safe as the access controls you actually set on it, whether or not anyone is scanning it. What builders should do next. If you build inside a Base44 workspace with security or IT oversight, ask whether Wiz is already connected. Base44's post doesn't give pricing or a specific settings path, it only points to its own documentation for connecting Wiz. If you have admin or publishing rights, use Base44's role-based publishing controls to decide who can make an app live and to whom, and restrict integrations to what an app genuinely needs rather than leaving everything open by default. If you're building solo, the practical lesson holds regardless of tooling: an app that quietly does something you didn't intend is still a risk, even with no organization or security team involved. Before you publish anything that touches real user data, check what integrations and login options are actually enabled, not just whether the feature works. End of article BuilderWithin Weekly · Free If you found this useful, subscribe free. Get BuilderWithin Weekly in your inbox. Daily briefings publish on the site, and the weekly roundup pulls together what mattered. Unsubscribe any time. BuilderWithin Weekly · Free · No spam Get BuilderWithin Weekly in your inbox. One weekly roundup in your inbox. Daily briefings publish on the site for people who ship products. Unsubscribe any time · Weekly email, always free

Business Insider
Jul 3rd, 2026
A VP of talent at Google's Wiz shares tips for getting hired at a late-stage startup.

A VP of talent at Google's Wiz shares tips for getting hired at a late-stage startup. Jul 3, 2026, 2:18 AM PT A blockbuster acquisition, IPO, or funding round can turn a startup into a hiring magnet. It can also change what it takes to land a job there. Earlier this year, Google completed its $32 billion acquisition of cybersecurity startup Wiz, marking the search giant's largest deal to date. Erin Gard, vice president of talent at Wiz, told Business Insider that the company has seen a significant jump in job applications since the deal was announced a little over a year ago. She also said Wiz, which has maintained its brand since the acquisition, is hiring for more than 100 open roles across sales, engineering, and field operations. "Startups are places that a lot of people want to be in, particularly right now, so our applications are quite high," said Gard. Early-stage startups can offer big upside before a major liquidity event or financing milestone, as Business Insider recently reported. Later-stage ventures have their own draw: more resources, greater job security, and additional room for advancement. Stiff competition isn't the only hurdle to getting a foot in the door, though. Gard said candidates need to show they're equipped to support the company's current and next stage of growth - not the scrappy startup it used to be. For job seekers hoping to join a mature venture like Wiz, she shared the following advice: Tailor your pitch to the company's current stage. The skills most prized at a startup can change as quickly as the company grows. Candidates should be ready to show how their experience aligns with the business at its current stage. When Gard started at Wiz in 2022, she said she kept tabs on candidates in a spreadsheet. Today, her job requires fluency with applicant-tracking systems that can bring order to a much larger hiring operation. "Being able to demonstrate an understanding of the specific chapter that an organization is in is really, really helpful," Gard said. "That shows you're ready for that stage of growth, and you're going to be able to plug in and help support us where we're at." Talk about the customer, not just the company. At a mature startup, candidates should be careful not to frame their interest around the company's newfound status. A stronger pitch focuses on how they can help sustain its momentum and drive its next stage of growth, said Gard. They should also show they understand the specific challenges it's trying to solve and explain how their experience would help address them, she added. Gard cited a solutions engineer candidate who, when asked "Why Wiz?," described how customers at his previous employer struggled to prioritize millions of security findings. He explained how Wiz could help solve that problem and how he would support customers in the role. "He immediately knew the value proposition," Gard said, adding that the candidate's explanation of how customers would use Wiz in the real world "was spot on." The candidate was hired and has since been promoted to a management role, she added. Build relationships with insiders before a position opens. Job seekers should thoughtfully engage with a startup's leaders and hiring managers on social media, such as by commenting on posts about product launches or asking insightful questions. Gard said that kind of engagement can signal genuine interest and help establish credibility before an application is submitted. That can be true no matter what stage company you're looking to join. Jesse Dwyer, Perplexity's chief communications officer and a hiring manager, previously told Business Insider that participating on a startup's social media channels can be especially effective, since these companies often have more flexibility in how they identify and engage with applicants. Don't focus only on successes. Many candidates avoid discussing failures, said Gard, but she argued that hiring managers often favor those who can talk about setbacks, pivots, and lessons learned. Because startups inevitably make mistakes and adapt quickly, she said that candidates who demonstrate resilience and self-awareness tend to come across as more credible. "Being able to show that you too have gone through your own journey, similar to how a startup has, resonates really, really well," said Gard. "It's something that I think a lot of people are really scared to do."

GlobeNewswire
Jun 30th, 2026
NordStellar partners with Wiz to deliver advanced intelligence and visibility into exposed authentication data.

NordStellar partners with Wiz to deliver advanced intelligence and visibility into exposed authentication data. June 30, 2026 08:00 ET | Source: NordStellar NEW YORK, June 30, 2026 (GLOBE NEWSWIRE) - The next-generation threat exposure management platform NordStellar proudly announces a partnership with cloud and AI security leader Wiz (now part of Google Cloud). Through this collaboration, NordStellar will provide Wiz customers with advanced intelligence on exposed authentication data stolen from infected machines. Visibility into hidden threats is essential for companies to stay ahead of cybercriminals and safeguard critical assets. Wiz customers will be able to utilize NordStellar's threat intelligence to obtain visibility into critical authentication data leaks, including cloud secrets/keys (AWS, Azure, GCP, and others), third-party secrets keys, as well as cloud and SSO credentials. "Leaked authentication tokens and credentials are a critical blind spot for many organizations. They can lead to high-impact attacks that are incredibly difficult to detect because threat actors using them often look just like legitimate users and create seemingly normal traffic," says Vakaris Noreika, head of product at NordStellar. "We are proud to partner with a cybersecurity giant like Wiz to help companies take control of their security posture and gain visibility into hidden threats before they escalate." Through this collaboration, NordStellar will monitor the deep and dark web for any exposed authentication data sourced from internal endpoint devices in an organization, providing Wiz with intelligence to share with its customers. When threats are identified, Wiz will alert impacted customers of secrets and cloud keys in their environment that have been stolen, allowing them to prioritize rotating the keys to prevent further misuse. "Authentication data leaks are a critical and often overlooked attack path in the cloud," says Amitai Cohen, attack vector intel lead at Wiz. "Partnering with NordStellar helps us surface those risks earlier, so our customers can take action before attackers do." ABOUT NORDSTELLAR NordStellar is a next-generation threat exposure management platform that enables companies to detect and respond to cyber threats before they escalate. It includes solutions like dark web and data breach monitoring, helping to prevent account takeovers, session hijacking, and other threats. NordStellar was created by Nord Security, a globally recognized company behind one of the world's most popular digital privacy tools, NordVPN. For more information, visit nordstellar.com.