Quick Overview
Job Description
Description
TEKsystems is seeking a Wiz Administrator to own the day-to-day operation, tuning, and continuous improvement of our Wiz cloud-native application protection platform (CNAPP) across AWS, Google Cloud, Azure, Kubernetes, and container workloads. This is a hands-on technical role for someone who wants to be the single accountable owner of a security platform end to end. The successful candidate does more than watch a dashboard.
You will configure and maintain the Wiz deployment, triage and tune the findings it surfaces, drive issues to closure with the cloud, application, and infrastructure teams that own the underlying resources, and steadily reduce the organization's cloud attack surface. You will translate Wiz Security Graph findings into prioritized, actionable remediation work - and where possible, automate that work away entirely.
KEY RESPONSIBILITIES
Platform Administration & Configuration
Own the Wiz tenant end to end: cloud account and subscription connectors, projects, folders, scoping, role-based access control, SSO/SCIM integration, and license utilization. Deploy and maintain Wiz collection components including the Wiz Sensor for runtime visibility, admission controllers for Kubernetes clusters, outposts for data scanning, and container registry connectors. Onboard new cloud accounts, subscriptions, projects, clusters, and code repositories as the environment grows; validate coverage and remediate scanning gaps.
Maintain platform hygiene: connector health, ingestion failures, permission drift, agent/sensor version currency, and scheduled maintenance windows. Manage upgrades, feature enablement, and vendor release evaluation; maintain the Wiz relationship alongside IT vendor management. Alerting, Detection & Triage
Design, build, and tune Wiz alert rules, policies, and controls so that alerts are high-signal, correctly routed, and owned by a named team.
Serve as first-line triage for Wiz findings: validate severity, eliminate false positives, confirm exploitability and blast radius using the Wiz Security Graph, and escalate genuine risk quickly. Integrate Wiz alerting into existing operational channels - ITSM ticketing, Slack, email, SIEM, and on-call escalation - so findings land where work actually gets done. Establish and maintain severity definitions, SLA targets, and escalation paths for toxic combinations, publicly exposed assets, exposed secrets, and critical vulnerabilities.
Participate in cloud security incident response, supplying Wiz-derived context on affected resources, identity paths, and lateral movement potential. Vulnerability & Risk Remediation
Drive findings to closure by partnering with cloud engineering, DevOps, application development, and infrastructure teams; track remediation to completion rather than handing off and moving on. Maintain a prioritized cloud risk backlog and run recurring remediation reviews with the accountable owning teams.
Analyze recurring findings for root cause and push fixes upstream into golden images, Terraform modules, Helm charts, and CI/CD pipeline gates. Manage the exception process: document accepted risks, compensating controls, expiration dates, and periodic re-review. Review cloud entitlements (CIEM) findings and partner with IAM to reduce excessive and unused permissions. Automation & Integration
Build automation rules and workflows in Wiz to auto-create tickets, notify owners, apply resource tags, and where appropriate auto-remediate low-risk misconfigurations.
Develop and maintain scripts and integrations against the Wiz API and GraphQL endpoints for reporting, bulk operations, and data export. Integrate Wiz Code / IaC scanning and secrets detection into source control and CI/CD pipelines so issues are caught before deployment. Feed Wiz data into enterprise reporting and observability platforms to support unified risk visibility. Reporting, Compliance & Governance
Produce recurring executive and operational reporting on cloud security posture, risk trend, remediation velocity, and SLA attainment.
Map and maintain Wiz compliance frameworks to CWGS obligations including PCI DSS, SOX IT CIS Benchmarks, and internal security standards. Supply evidence and control artifacts to internal audit, external auditors, and cyber insurance reviews. Document platform configuration, runbooks, triage procedures, and remediation playbooks; keep them current. Continuous Improvement & Enablement
Continuously refine policies and controls to reduce alert volume while increasing detection of material risk.
Train and enable cloud, application, and infrastructure teams to self-serve within Wiz for their own projects and scopes. Benchmark posture over time and recommend platform, process, and architectural improvements to leadership. Stay current on cloud attack techniques, CNAPP capabilities, and Wiz product roadmap; pilot new capabilities before broad rollout.
REQUIRED QUALIFICATIONS
5+ years in cloud security, cloud infrastructure engineering, security operations, or vulnerability management.
2+ years of hands-on administration of a CNAPP or cloud security posture management platform (Wiz strongly preferred; Prisma Cloud, Orca, Lacework, Microsoft Defender for Cloud, or Aqua considered). Working proficiency across at least two major cloud providers (AWS, Google Cloud, Azure), including IAM models, networking, and native security services.
Demonstrated ability to triage security findings, assess real-world exploitability, and prioritize based on business risk rather than raw severity score. Hands-on experience with containers and Kubernetes, including cluster security concepts and workload scanning. Scripting and automation ability (Python, PowerShell, or Bash) and comfort working with REST/GraphQL APIs. Familiarity with infrastructure as code (Terraform preferred) and CI/CD pipelines. Strong written communication and the interpersonal skill to drive remediation with teams that do not report to you.
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
PREFERRED QUALIFICATIONS
Direct Wiz administration experience, including sensor deployment, automation rules, custom controls, and API usage. Cloud or security certifications such as AWS/Azure/Google Cloud Platform Security Specialty, CKS, CISSP, or GIAC Cloud Security. Experience supporting PCI DSS and SOX ITcontrol environments in a public company. Experience retail, multi-site, or high-transaction e-commerce environments. Experience integrating security tooling with SIEM, SOAR, ITSM, and observability platforms.
Exposure to data security posture management (DSPM) and sensitive data discovery in cloud data stores. KEY COMPETENCIES
Ownership mindset - treats the platform and the findings it produces as their responsibility through to resolution. Signal discipline - relentless about tuning out noise so that an alert means something. Pragmatic risk judgment - distinguishes theoretical exposure from material, exploitable risk. Influence without authority - builds credibility with engineering teams and gets fixes prioritized. Bias toward automation - solves the same problem once, then makes it not recur.
Clear communication - explains cloud risk in terms an engineer can act on and an executive can understand. FIRST-YEAR MILESTONES
First 90 Days
Complete a full audit of Wiz deployment coverage; identify and close every gap in cloud account, cluster, and repository onboarding. Establish a baseline of current findings by severity, category, and owning team, and publish the first posture report. Define severity tiers, remediation SLAs, and escalation paths, and socialize them with owning teams.
Six Months
Reduce open critical and high findings against the baseline, with documented remediation of all publicly exposed and toxic-combination issues. Automate ticket creation and owner routing for all high-severity findings into the enterprise ITSM workflow. Implement IaC and secrets scanning in CI/CD for priority repositories, with agreed pipeline gating criteria. Twelve Months
Demonstrate sustained downward trend in cloud risk with measurable improvement in mean time to remediate. Deliver a mature compliance reporting capability mapped to PCI DSS and SOX ITwith audit-ready evidence.
Enable owning teams to self-serve in Wiz, shifting the role from central bottleneck to platform owner and advisor. Skills
Systems engineering, wiz, platform administrator, cloud security engineer, Information security, Azure, kubernetes, triage, cicd, terraform, python, bash, powershell, Automation
Top Skills Details
Systems engineering,wiz,platform administrator,cloud security engineer,Information security,Azure,kubernetes,triage,cicd,terraform
Job Type & Location
This is a Contract position based out of Lincolnshire, IL. Pay and Benefits
The pay range for this position is $65.00 - $80.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms.
If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Lincolnshire,IL. Application Deadline
This position is anticipated to close on Sep 1, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
Similar jobs
- SW
Sr. Java J2EE Developer
NewSTS Worldwide Inc.
Wilmington, DE🇺🇸On-site22 hours agoMicroservicesShellSpring+13Technology - UT
AWS Data Architect with strong experience in Devops and CICD. 100 % Onsite in Baltimore MD
NewUnisoft Technology Inc
Woodlawn, MD🇺🇸On-site22 hours agoAWSRedshiftTechnology - NG
Software Engineer / User Experience Applications with Security Clearance
Northrop Grumman
San Diego, CA🇺🇸$75.1k - $137.6k/yrOn-site6 weeks agoDockerMicroservicesMongoDB+19Technology - AI
In-Home Sales & Tech Support (Part Time)
NewAsurion Insurance Services
Wilmington, North Carolina🇺🇸$22/hrOn-site2 hours agoTechnology - MT
Data Center Technician IC1
NewMilestone Technologies, Inc.
GA🇺🇸Hybrid22 hours agoTechnology - NG
Cyber Systems Engineer with Security Clearance
NewNorthrop Grumman
Melbourne, FL🇺🇸$87.2k - $130.8k/yrOn-site22 hours agoSplunkActive DirectoryHTTP+2Technology