Kelly Services logo

IaC Security Engineer – Wiz / OPA / Rego

Kelly Services

CHARLOTTE, NC · HybridContract$89.34–100.66/hrSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$89.34–100.66/hr
Location
CHARLOTTE, NCHybrid
Schedule
Contract
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

A long‑term contract role in Charlotte, NC for a well‑known financial services firm seeking an IaC Security Engineer. The position is hybrid and involves consulting on complex security challenges, designing and tuning policy‑as‑code rules, and integrating Wiz tooling across CI/CD pipelines.

Skills & qualifications

RequiredNice to have

Skills

TerraformKubernetesWizOPARegoCI/CDGitServiceNowJIRAVs CodeAzureAWSGCPTerraform AssociateCKACKADPythonBashPowerShellAzure DevOpsGitHubGitLabJenkinsCloudFormationARM/BicepHelmJSONSARIF

Qualifications

7+ Years Engineering Experience8+ Years AppSec/Cloud Sec/DevSecOps Experience

Full job description

$89.34 - $100.66

Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for a Engineer in Charlotte, NC (Hybrid).

Work with the brightest minds at one of the largest financial institutions in the world. This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today's digital age. If you want to work for a company that is not only a household name, but also truly cares about satisfying customers' financial needs and helping people succeed financially, apply today.

Contract Duration: 6 Months

Required Skills & Experience

  • 7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work or consulting experience, training, military experience, education.

  • 8+ years in AppSec/Cloud Sec/DevSecOps with hands on Terraform and Kubernetes security.

  • Practical experience operating Wiz (or similar) for IaC in CI/CD.

  • Policy as Code skills (e.g., OPA/Rego) or equivalent rule tuning experience.

  • CI/CD fluency and Git workflows; strong triage/routing at scale; clear written/verbal communication for developer enablement.

Desired Skills & Experience

  • ServiceNow AVR/CVR/ITSM integration experience; JIRA/defect tracker routing.

  • VS Code/IDE enablement for developer workflows.

  • Cloud certifications (Azure/AWS/GCP), Terraform Associate, CKA/CKAD.

  • Scripting (Python/Bash/PowerShell) for automation and reporting.

What You Will Be Doing

  • Consult as an expert to develop or influence initiatives and resources for highly complex business and technical needs across Engineering.

  • Consult on the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, and advanced analytical and inductive thinking.

  • Provide expertise to client senior leadership on innovative Engineering business solutions.

  • Strategically engage with client personnel.

  • Design, implement, and tune custom IaC rules in Rego/OPA to extend Wiz beyond built?in checks; codify internal guardrails and compliance mappings; maintain versioned policy packages.

  • Build automated regression tests for rules (sample repos, TF plans, K8s manifests); measure quality and iteratively reduce false positives prior to enforcement (report ? warn ? block).

  • Perform pipeline health checks, triage failed scans and monitor tool availability to minimize developer friction.

  • Validate severity, de duplicate/mark false positives, and route issues to the right owners at repo/service level; drive high signal to noise at scale.

  • Tune IaC policies/rules (including policy as code), version changes, align to internal standards/frameworks, and roll out safely with staged enforcement (report ? warn ? block).

  • Integrate Wiz CLI into pipelines; implement gating thresholds; publish artifacts (JSON/SARIF) for traceability; optimize run time and concurrency.

  • Deploy and maintain Wiz DevOps extensions and/or Wiz Scanner plugin; standardize pipeline templates with block/warn logic across services.

  • Leverage Wiz VCS integrations to surface PR/MR feedback and ownership context across GitHub, GitLab, and Azure Repos.

  • Enable local/PR scanning and IDE workflows (Wiz VS Code extension); deliver “how?to?fix” guidance, sample modules, and office hours to accelerate remediation.

  • Partner with platform teams to embed scanning in golden pipelines/modules and drive consistent adoption.

  • Run office hours and Slack/Teams support; explain failures with actionable fix guidance; promote local/PR/IDE scanning; review PRs/modules.

  • Own tool health and upgrades: Wiz CLI updates, policy bundle refreshes, CI/CD plugin versions, and regression tests; document rollback and “warn?mode” fallbacks.

  • Work with Wiz support/product to escalate defects, track roadmap, and schedule change windows; align integrations using the official Wiz integrations ecosystem.

  • Triage findings at scale; validate severity, de?dupe/suppress noise, and auto?route to owners; maintain exception ledger with expiries and compensating controls.

  • Integrate with ServiceNow (AVR/CVR/ITSM) for ticket synchronization and SLA tracking; ensure bidirectional status updates and reporting.

  • Support publish monthly dashboards (coverage, block rates, MTTR, exception aging, false?positive rate); prepare audit evidence (policy mappings, change logs, access reviews).

  • Tools & Technologies

  • Wiz for IaC scanning and CI/CD policy enforcement.

  • IaC stacks: Terraform, CloudFormation, ARM/Bicep, Kubernetes/Helm.

  • Pipelines/VCS: Azure DevOps/GitHub/GitLab/Jenkins.

  • Ticketing/Governance: ServiceNow workflows for finding lifecycle and exceptions.

Motion Recruitment Partners (MRP) is an Equal Opportunity Employer. All applicants must be currently authorized to work on a full-time basis in the country for which they are applying, and no sponsorship is currently available. Employment is subject to the successful completion of a pre-employment screening. Accommodation will be provided in all parts of the hiring process as required under MRP’s Employment Accommodation policy. Applicants need to make their needs known in advance.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.