🧙 Why I'm Joining Wiz
Jan 27, 25Last week, I started a new role: Principal Security Researcher at Wiz. I’ve been closely connected to Wiz for years. As the leading cloud security startup and the fastest growing software company in history, Wiz has been blazing a trail. I’m thrilled to join the team.
Experience Compounds
When I first dove into cloud security, it was as a Security Consultant at NCC Group. That’s where I got involved with ScoutSuite—one of the earliest and most comprehensive open-source CSPMs. My most impactful contribution was a series of PRs that updated the documented rationale and references for AWS and GCP findings. To this day, it’s one of the highest-leverage things I’ve done.
Since those early days:
- CSPMs have been displaced by CNAPPs.
- Cloud security has become a cornerstone of modern security programs.
- Attackers are now far more cloud-literate.
- Cloud services have exploded in complexity, yet still lack secure defaults.
Why Wiz
Team
I already know many incredible “Wizards.” Not only is the research team stacked with talent (Scott, Amitai, Alon, Nir, Itay, Shay, Yaara, Danielle, Andres, Sagi, and many more), but I’ve been impressed by the work done by the product, engineering, marketing, and yes - even sales (shoutout Laura) teams! This role might be worth it just to experience the Wiz Vegas booth next year.
Values
Fundamentally, I’ve seen Wiz take a value-additive approach. The cloud security jobs board and CTFs are just a couple examples of free, public initiatives. And in the research organization, there is a clear focus on making resources (the Cloud Threat Landscape, Cloud IOCs) publicly accessible, while ensuring the product integrates these results and gives customers immediate benefit.
Product
It’s simple: I’m excited by Wiz. I spent the past year speaking with dozens of cloud security engineers and startups. I have voraciously read everything about Wiz (Wiz will be bigger than CrowdStrike and Palo Alto, How Wiz Became the Fastest Software Company to Hit $500M & Its Path to $1B, Wiz Defend-ing Their Flank).
A few things are clear.
- Wiz is well positioned as a best in class platform, already serving 45% of Fortune 100 companies, and working with incredible partners (like friends here in the Nordics at O3 Cyber)
- Context is the key to effective cloud security. Wiz architected for this early with their Security Graph, and further empowers customers through data portability with integrations like Snowflake. Wiz continues to add compounding data through new data sources, powering higher signal on toxic combinations. Beyond that, Wiz and I are aligned that effective security requires getting everyone in the company involved. Security should be visible and easy to act on. Over 50% of Wiz users are developers, and the product continues to evolve to empower your whole business, not just the security team.
- Despite massive growth and market success, Wiz continues to just ship. The pace is incredible. Since I started interviewing, Wiz has: launched Wiz Defend, expanded Wiz Remediation and Response to Azure and GCP, acquired Dazz, and extended to support both Okta and Snowflake.
My Goal
For many years, patio11 would say he “worked for the internet, at Stripe.” I find that aspirational. I hope to work for the security industry, at Wiz.
What does that mean practically?
- I’ll be working with other researchers at Wiz to produce and amplify knowledge that can serve the broader industry and be baked into the Wiz platform to benefit our customers.
- I’ll continue producing impartial content on security. Expect more like my past work on how to tackle new domains like AI, navigate the technical and social aspects of identity security, and scale cloud security programs. I also hope to find ways to talk about the Wiz vision for security.
- I’m looking forward to connecting with and learning from as many customers and cloud security programs as possible, especially outside my “US scale-up” bubble. I want to learn what the challenges look, to make sure Wiz continues to build against customer needs.
Time to get to work.