Senior Security Engineer - Container & Cloud Security
_ECCO Select is a talent acquisition and consulting company specializing in people, process and technology solutions. We provide the talent behind the technology enabling our clients to achieve their goals. For more information about ECCO Select, visit us at www.eccoselect.com._
*Job Title: *Sr. Security Engineer (Container & Cloud Security)
*Duration: *6 months initial, strong intent to convert to full-time (engagements on this team have extended up to 4 years)
*Schedule: *Full-time, approximately 3 days/week onsite
*Location: *Toronto, ON strongly preferred; NY tri-state area (NJ, Philadelphia, NYC) considered as secondary
*Work Authorization: *GC or USC only
*What's Driving This Need*
This role sits within one of three agile pods on a policy-as-code team focused on automating security controls and governance across public cloud environments (Azure and GCP), with Wiz as the primary platform. The team also owns container security and scanning across the Kubernetes footprint.
*Job Description*
Pods run in sprints with daily standups and sprint planning, work is tracked in Jira, and each pod has a dedicated Scrum Master and Product Owner. Tech leads within each pod guide day-to-day technical direction, while the Hiring Manager sets overall team priorities.
*Key Responsibilities*
● Design, implement, and maintain cloud-native container security controls across Kubernetes platforms (AKS, GKE, and EKS).
● Develop, tune, and maintain container threat detection rules to identify malicious activity, anomalous behavior, and indicators of compromise across cloud environments.
● Monitor runtime security events, investigate security alerts, and lead triage and incident response for container and Kubernetes workloads.
● Deploy, configure, and optimize Wiz Defend/CWPP capabilities, including runtime sensors, workload protection, and attack path analysis.
● Build and automate security guardrails, admission controller policies, and preventative controls using Infrastructure as Code (Terraform, Helm, GitOps).
● Secure the container software supply chain through image scanning, SBOM validation, image signing, and registry security.
● Identify, prioritize, and remediate container vulnerabilities and misconfigurations using risk-based exposure analysis.
● Develop and maintain Compliance-as-Code policies aligned with CIS, NIST, and STIG security benchmarks.
● Integrate security findings and threat intelligence into ServiceNow and enterprise vulnerability management workflows.
● Partner with Security Operations, Cloud Engineering, DevSecOps, and application teams to strengthen detection coverage, incident response, and overall cloud security posture.
● Conduct threat hunting and proactive analysis to identify emerging threats, improve detection logic, and enhance runtime protection capabilities.
● Support post-incident reviews through root cause analysis, corrective-action recommendations, and continuous improvement of detection and response.
*Skills and Experience*
● Strong cloud security knowledge spanning AI/ML platforms, model pipelines, data layers, IAM, networking, and logging.
● Hands-on Wiz CNAPP expertise (CSPM, CIEM, DSPM, CWPP), including experience applying it to AI workloads, model hosting, and data pipelines.
● Experience designing security controls and architecture at the model, data, and platform levels — both preventive and detective.
● Compliance-as-Code fluency, including mapping Wiz findings to STIGs, native cloud policies, CI/CD, and governance workflows.
● Ability to interpret Wiz risk graphs and communicate risk-based exposure analysis: model misuse, data leakage, privilege escalation, and blast radius.
● Kubernetes experience across AKS, GKE, and EKS.
● Working knowledge of Terraform, Helm, and GitOps-based pipelines.
*Nice to Have*
● Direct, hands-on Wiz platform experience is a significant plus.
● Container image / repository scanning experience.
● Deeper Terraform or IaC pipeline background. Open to strong, trainable candidates with somewhat less hands-on experience, provided their foundational cloud and container security skills are solid.
*Technical Skills*
Wiz CNAPP (CSPM/CIEM/DSPM/CWPP), Wiz Defend, Kubernetes (AKS/GKE/EKS), Terraform, Helm, GitOps, Azure, GCP, CIS/NIST/STIG, ServiceNow, container image scanning, SBOM, image signing, registry security.
*A Day in the Life*
Working within an agile pod alongside a Scrum Master, Product Owner, and tech lead, tracking work in Jira through daily standups and sprint planning — balancing hands-on runtime detection/IR work, Wiz Defend/CWPP configuration, and IaC-driven guardrail automation, while partnering closely with Security Operations, Cloud Engineering, and DevSecOps.
*Resume Expectations*
Resume should clearly demonstrate hands-on Kubernetes security experience (AKS/GKE/EKS), cloud security architecture work, and ideally direct Wiz or comparable CNAPP platform experience. Candidates open to less hands-on Wiz time will still be considered if cloud/container security fundamentals are solid.
*Interview Process*
Panel interview with the Hiring Manager and two technical leads.
ECCO Select is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
EEOC Know Your Rights E-Verify Participation Poster
Pay: $65.00 per hour
Benefits:
* 401(k)
* 401(k) matching
* Dental insurance
* Health insurance
* Paid time off
* Retirement plan
* Vision insurance
Work Location: Hybrid remote in New York, NY 10001