Enhancing Cloud Security with AI and Wiz OS | swampUP 2025
Jiong Liu, VP of Product Marketing with WIZ, talks about how security teams often struggle to connect artifact vulnerabilities detected in development with runtime exposure and real-world risks. Jiong discusses best practices for DevSecOps to overcome this and achieve faster, more effective vulnerability management.
Transcript
Hey everyone. We're back here at Jfr Swamp up in beautiful Napa Valley at the Meritage. We've had a great day of talking to some really great people, and we're ending it with a really smart lady.
I'm gonna introduce you to here in a second. Her name is Jung Lu, and Jung is with Wiz. And beyond that, Jung, I'm gonna leave it to you.
So talk to our audience, tell them a little about yourself. Sure. Thank you so much, Alan, for having me.
Um, so Wiz, a little bit about Wiz. We do cloud security and our goal is really to help organizations adopt cloud as well as AI as fast as possible. And I'm the VP of product marketing, so I'm responsible for product go to market strategy as well as execution at Wiz.
Love it. Um, our audience is very familiar with Wiz. Obviously we've been following them for a long time.
Um, I wanted to ask about you though, because people are saying, wow, great, she's, you know, she's got a great job over there. But give people a little bit of sense of your journey in, in the, uh, industry. Yeah.
So I will say I grew up in Silicon Valley. Both of my parents were engineers and, um, I fully rebelled. They expected me to go and be an engineer as well.
I started going down the computer science path, realized I hated it. Uh, and so I fully rebelled into finance. Okay.
Um, and did that for a bit before I saw the error of my ways and realized I need to come back to technology. What's core to me is building cool stuff, right? That actually makes an impact rather than necessarily helping rich people stay rich or get richer.
Oh. Um, and so that, uh, ultimately ended up taking me back into technology, back to Silicon Valley. I was incredibly fortunate to land at Okta, and so really saw actually for the first time how it became an enabler of the business, right?
Because this was the wave where we had sas, right? And it could really enable that. And this was also the time when organizations were really thinking about how authentication, um, can be actually an enabler again, of the applications that they are building for their customers.
When you think about identity being so central to the journey that you wanna take a customer on. So that was a phenomenal journey. Uh, ended up seeing Okta grow from about 400 people to 6,000 people.
Very large company at that point. Nice. Decided it was time to get back to that builder route.
Um, and Wiz was just by far and away crushing it, such an incredible vision that they had as well. Absolutely. Absolutely.
Um, you know, I always said identity, IAM was the killer security app for the clout, right? So I, I grew up in the security before the clout and, you know, and for us it was the Molten Castle era, right? And cloud changed all that, but IAM became kind of paramount until the Wiz came along.
Well, cloud, cloud, Well, cloud, well, cloud made i A or cloud development, right? Yeah, exactly. But Wiz came and, and we started looking at cloud security, container security mm-hmm.
Cloud native security in, in a different light. Um, you are here, we're at Jfr, obviously you presented today. If you wouldn't mind share with the audience a little bit about what you presented on.
Yeah, So I think one of the key challenges that we see is there's actually been multiple generations of cloud at this point, right? Yeah. We've had cloud for 20, some 25 years.
Yeah. Or 2005 or four. And I think really in the early days, it was a lot more of the lift and shift, right?
We could take our on-prem approaches, we could take our workloads, move them into virtual machines. And really a lot of that has, um, dramatically changed, right? It's changed with cloud native development where every team, every organization is trying to move faster and faster and faster.
We have developers that are writing application code, we have infrastructure folks writing infrastructures code, and all of that is being shipped every single day. So development is incredibly agile and continuous, but the challenge that we have long had in security is our org structures, our workflows, even the tools that we have, right? They're still very vertical and siloed.
So application security teams, they run code scanners that look for vulnerabilities just in code, right? And then we have Dev SecOps teams now that run scanners and pipeline that just look for issues in the pipeline, evolved data infrastructure as code scanning in cloud. We have organizations using tools like Wiz that evolved data CSPM tools that are primarily used by cloud security teams, but increasingly developers.
And then in SecOps we have like a whole other completely different Yeah. Landscape of tools for the runtime. And so all of this is very disjointed, right?
It's very fragmented. How do I actually understand a vulnerability here in code that my SAS tool found actually is deployed into production and is running on a privileged container in my environment? It's actually very difficult to understand.
And I think, you know, when we look at CISOs, when we look at business leaders, even, they ask these horizontal questions like, where are the container images? Where am I exposing sensitive data of my customer facing applications? What, where, where's my risk?
Where's my exposure? And it's very difficult for security to answer those questions today because it is so silent. So really what I was presenting on is how do we flip that model, right?
How does security become horizontal so that we can move at the pace that our development teams and DevOps teams expect for us? And really the key to do that is in our view, context, right? Understand what's running in the cloud, give you the context for the code that created it, as well as the owner that is responsible, and then give you runtime context, right?
What's actually in use, what's loaded into memory that we should prioritize? I love it. You know, what you just said in a lot of words was why we have 7,600 venture back public security companies because it is so fragmented and so siloed and so specialized.
Everybody's a specialist. And you know, when the average, not even big enterprise, when the average, like SME enterprise, I forgot what the number was, 18, 17 different security vendors in a relatively small company. This is, you just hit it on the head, right?
You, you imagine, you know, you're a CISO and you're responsible for 17 different security vendors and you gotta make those all work together, right? It's, it's enough to drive you to drink is what it is. But, and, and we, we, we try to, we're trying to consolidate, but at the same time, the pressure to keep up with the pace of innovation, with the pace of, of ai, with the pace of how much code we're churning out right now, it's like, you know, it was mission impossible before.
This is mission impossible squared. Um, But what I would answer, well, but what I would argue is I think we overly focus on tool consolidation, right? Tool consolidation is an outcome.
But I would say the issue is we have a lot of data mm-hmm. But we don't know how to turn it into something that we can action, right? Every organization, you go to them, they've got their expel Excel spreadsheet of millions of vulnerabilities, right?
It's not that we have a problem with finding vulnerabilities. We have a problem with prioritizing and then getting someone to actually fix it. So I, context for us is how do we really get the insight out of all of this pool of data that we have on what's most critical, and then let's break the silos between our teams so we can actually work together to fix them.
Music to my ears, I mean, I'm thinking back, so I, I started a company called Still Secure in 2001. In 2003, we came out with a vulnerability scanner long time ago. And that, that what you just described was exactly the state of the art.
In 2003, people scanned about once a year they printed out a telephone book and it was like job security, right? Because you, it took you a year to go through that book and just in time for the next scan for the new book. Um, we've, we've tried to got getting better.
You, you're right. com primarily because I thought it was a better shot at security. Like we could correct some, you know, original sins built into security, really pushed for the whole DevSecOps thing, like an RSA conference.
We did the first DevSecOps conferences there and everything. We've come a long way. But one of the lessons we learned is that developers are not security people.
They wanna develop quality code. Like I've never met a developer who says, I want to develop insecure code. Yes.
Right? They all wanna do, but I think one of the mistakes that we've made as an industry is thinking that if I only could make them a security person, they develop better code. They're never, they could be a security champion, they have pride in their product, but you still need security people at some level doing the security and helping them.
Yes, I agree with that. But I think, again, for developers, it's not like there was a lack of data. Like no, you know, we tell them all the time, look at all these vulnerabilities.
Um, but the issue is what should I prioritize? Yes. Right?
Again, it's what is the insight? What's the needle in the haystack out of this very long list that you've given to me, security team? And how do we start giving them that prioritization actually again, through context.
Yeah. Right? Instead of saying, Hey, developer, did you know you have hundreds, maybe thousands of exposed secrets or secrets that have to be rotated?
Um, instead of saying that, we can say, actually of all of these, this is the one secret that I need you to focus on, because I actually know that it leads to an admin in our cloud environment that has access to sensitive data, right? We give that developer that information, they're really, they get it, right? So how Do we get the, is that information derived using AI or some sort of automated means?
Or does that take the security pro saying that's the one? So I think it's two things, right? One is you have to correlate the signals together, right?
So your secret scanner has to talk to what, uh, the entitlements and the identities that you have in the cloud, right? So your Kim solution, and they have, you have to be able to correlate that together. So a tool can do that.
Security teams can also help you to do that as well. And they can provide the signal of this is what's most important for you to go fix. Then we can actually use AI to accelerate that path to remediation, right?
Because there's actually a number of ways to resolve that particular issue. You could delete the key might be a little aggressive, you could rotate the key, right? It's kind of shooting the patient to save them, but okay.
Yeah, No, sometimes Uhhuh. Um, but we can offer all of the different paths to remediation. Absolutely.
And the developer, again, they know what is best for their applications for the, um, repositories that they are working on. So you can give them that and AI can help them actually take, okay, I think this is the best path to then actually getting to a fix. So I've spoken to a lot of security companies recently who are saying Nirvana is, we automate this, we automate prioritization and remediation.
Now look, from my time on the other side of the camera, selling automated remediation was not an easy sell. People are scared to death of that, right? But have we come or are we coming to maybe a point where we can convince a developer or an ops team that hey, it, for, you know, 80% of the garden variety stuff, we see what automated remediation is the way to go?
I think that is a nirvana. Maybe it's not that far off, but from what we've seen, organizations want to automate everything around a decision point and an action that still requires a human in the loop. Um, especially because we started in cloud, right?
Automated mediation and cloud is a very aggressive, right. If we, it's, It's aggressive everywhere. Believe me, it's true.
I I, I, that's why I'm still doing this and I'm not retired, but yeah, uh, it people just don't want, you know, they're afraid that you're gonna break something. Rightfully so. Yeah, though, like you could be taking down production workloads, you can, taking down production customer applications, it is, it, it requires you to, to feel that like impact.
And so that's why we think there is a human in the loop still, but as much of everything around it that we can automate as possible, we should. And I think that does allow us to really start getting out of the continuous patching game and really start burning down these backlogs that we've had forever. Absolutely.
Pat patching is, is unfortunately a losing prop. That's again, something that we've been remediating since 2000 and or trying to do since 2003 and has never gone on. Let me pivot a little bit.
We're here at Jfr Swamp Up. You did present, as I mentioned, and we've been talking about that. What's the connection with Jfr?
Let's talk about that. Yeah, so I'd say overall we share very similar visions, right? When we think about how do we secure development that is happening faster and faster every day, it requires security to move faster, and it requires every team within security to also work together as well.
So at Wiz, um, from actually the pretty early days, we have scanned Jfr Artifactory to bring in their understanding of container images and artifacts into Wiz to give that complete understanding of the cloud environment. Now, what is coming next is we're deepening our integrations because we both believe in that open security ecosystem in order to share context that empowers all of our teams. And so from a Wiz perspective, we have a lot of understanding about the risks associated with cloud.
We understand runtime context, the code context as well. And so we're bringing that prioritization, bringing the risks, and all of that back to Jfr oog. And similarly, JFR has very deep understandings of packages, right?
And so we can take their reachability analysis that, um, acceptability as well, and we can layer that into Wiz and use that context to also further enrich our prioritization as well as the, uh, the move to actually getting to a fix. I love it. Last question, or last area I want to talk on, you know, you can't take two steps without tripping over AI here.
What's the AI angle behind all this? Yeah, well, so when we look at ai, there are really two sides of the coin. One is how do we actually secure the AI infrastructure?
And a lot of it is being built on top of cloud. And so for us, it is actually a very natural extension of what we know about cloud environments, right? We need to understand the configuration, the control plane.
We need to understand identities that are associated with it, or non-human identities. In this case, we need to understand the workload layer or the data layer that's being used to train the models and do a complete assessment of the risks that are there. And from there, we can enable now AI teams bring them into the full, break the walls and silos with them so that they can actually take ownership and help us to secure those elements of their environment.
The other side is around how AI can actually empower all of our defenders, um, to be much smarter to do, to secure things, to take action with less resources. And so we're actually seeing such incredible results there. Um, as an example, we released a new product today called Wiz Os.
It's all about hardened container images. So you can start secure. And what we're seeing is we can actually use AI to immediately point out to teams.
These are the most impactful places for you to start deploying this so that you really start getting value right off the bat. And by the way, here's a migration plan, right? Here's everything automated delivered into the hands of that DevOps team or DevSecOps team so that they can get going on that journey.
Let's talk about that. I'm, I'm sorry, I know I said the last thing, but I, we got some questions here. So how many, how big is the library, if you will, of these hardened container images, if we can call it that?
Yeah, so for us, we are starting with the set that our customers primarily require. So it's all of the major languages. We've got Ruby, Python, right?
We also have FIPs compliant images as well. Oh, we expect to, um, grow the catalog as we continue seeing customer adoption. But the question that we get from customers, or what we've found through our product development is it's not the number of images, right?
Again, it's like the impactfulness, right? Help me cover the most important components of my containerized environment and then help me actually adopt it. Because that's been one of the key challenges.
There are so many container images in an organization. Security oftentimes is very little visibility even into where are all of my container images? Which ones are validated in runtime, right?
Mm-hmm. Which is probably where we should start to focus first. So we're layering on this element of the product with the overall end-to-end container security approach to help organizations again, prioritize and then actually then swap in where you will have the biggest impact in reducing the number of CBEs.
And this was released today, which, so this is not live. People will be watching this ah, in the next couple days. Yes.
But as of September 9th, correct? It's, it's out right Now. It, it is out in public preview, which means every single one of our customers has access to it and can start adopting it today.
I love it. Wiz os Wiz os You heard it here on Text Shock. Oh.
Um, well, John, thank you so much. I thank you. I know it's kind of the end of the day and you were nice enough to come in.
I, Oh no, thank, thank you for having me. But keep up the great work, man. Wiz is doing exciting things in this cloud security and security space in general, so it's great to have you on come back.
We do this all the time remotely in person. We'd love to have you back. Thank you.
I appreciate that. Thank you. Jang Lu, uh, with Wiz here at Jfr Swamp Up.
That's gonna wrap up our day one coverage here at Jfr. We'll be back tomorrow. We've got a full day starting, I think at 11 or something, so stay tuned then.
But until then, this is Alan Shimo for Techstrong tv. Thanks everyone.