EngineerJobs.io
← Back to all jobs

Job Description

Ecco Select is hiring a Senior Security Engineer to support a policy-as-code security team focused on automating governance and security controls across Azure and GCP. In this contract role (hybrid in New York), you will help harden Kubernetes workloads, improve runtime detection and incident response, and implement container software supply chain protections using Wiz.

The position is centered on securing containers end to end, including Kubernetes platforms (AKS, GKE, and EKS), Wiz Defend/CWPP runtime capabilities, and Infrastructure-as-Code guardrails built with Terraform, Helm, and GitOps. You will also translate security outcomes into Compliance-as-Code aligned to CIS, NIST, and STIG benchmarks and connect findings to enterprise workflows in ServiceNow.

Responsibilities

  • Design, implement, and maintain cloud-native container security controls across Kubernetes platforms including AKS, GKE, and EKS.
  • Develop, tune, and maintain container threat detection rules to identify malicious activity, anomalous behavior, and indicators of compromise across cloud environments.
  • Monitor runtime security events, investigate security alerts, and lead triage and incident response for container and Kubernetes workloads.
  • Deploy, configure, and optimize Wiz Defend/CWPP capabilities, including runtime sensors, workload protection, and attack path analysis.
  • Build and automate security guardrails, admission controller policies, and preventative controls using Infrastructure as Code with Terraform, Helm, and GitOps.
  • Secure the container software supply chain through image scanning, SBOM validation, image signing, and registry security.
  • Identify, prioritize, and remediate container vulnerabilities and misconfigurations using risk-based exposure analysis.
  • Develop and maintain Compliance-as-Code policies aligned with CIS, NIST, and STIG security benchmarks.
  • Integrate security findings and threat intelligence into ServiceNow and enterprise vulnerability management workflows.
  • Partner with Security Operations, Cloud Engineering, DevSecOps, and application teams to strengthen detection coverage, incident response, and overall cloud security posture.
  • Conduct threat hunting and proactive analysis to identify emerging threats and improve detection logic and runtime protection capabilities.
  • Support post-incident reviews through root cause analysis, corrective-action recommendations, and continuous improvement of detection and response.

Requirements

  • Strong cloud security knowledge spanning AI/ML platforms, model pipelines, data layers, IAM, networking, and logging.
  • Hands-on Wiz CNAPP expertise (CSPM, CIEM, DSPM, CWPP), including experience applying it to AI workloads, model hosting, and data pipelines.
  • Experience designing security controls and architecture at the model, data, and platform levels, including preventive and detective controls.
  • Compliance-as-Code fluency, including mapping Wiz findings to STIGs, native cloud policies, CI/CD, and governance workflows.
  • Ability to interpret Wiz risk graphs and communicate risk-based exposure analysis for model misuse, data leakage, privilege escalation, and blast radius.
  • Kubernetes experience across AKS, GKE, and EKS.
  • Working knowledge of Terraform, Helm, and GitOps-based pipelines.

Technologies

  • Wiz, Wiz Defend, CWPP, CSPM, CIEM, DSPM
  • Kubernetes, AKS, GKE, EKS
  • Terraform, Helm, GitOps, Azure, GCP
  • CIS, NIST, STIG
  • ServiceNow
  • Container image scanning, SBOM, image signing, registry security
  • Admission controller, Infrastructure as Code, CI/CD

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Retirement plan
  • Vision insurance

Additional Details

  • Location: New York, NY (hybrid). Toronto, ON strongly preferred; NY tri-state area (NJ, Philadelphia, NYC) considered as secondary.
  • Schedule: Full-time, approximately 3 days/week onsite.
  • Work authorization: GC or USC only.
  • Interview process: Panel interview with the Hiring Manager and two technical leads.
  • Duration: 6 months initial, with strong intent to convert to full-time (engagements on this team have extended up to 4 years).
  • Pay: $65.00 per hour (USD 65 - 65 per hourly).
  • Work location: Hybrid remote in New York, NY 10001.

Similar Jobs