Global SaaS platform, ROLLER, achieves DevSecOps with Wiz

Helping people create and share joyful experiences through secure development

Roller

Industria

Tecnología

Región

Global

Plataformas en la nube

AWS
Azure
¿Listo para empezar?
Solicita una demo

Challenge

  • Limited visibility into cloud risks created inefficiencies, constant proof-of-concepts, and delayed remediation.

  • Security alerts lacked context, leading engineers to dismiss them as noise and slowing collaboration between security and development.

  • Fragmented tools and alerts made it difficult to detect and respond quickly to runtime threats.

Solutions

  • Wiz Cloud delivered unified visibility and contextual risk prioritization, reducing remediation time from days to minutes.

  • Wiz Code shifted security left, giving developers real-time feedback in their workflows and preventing vulnerabilities at the source.

  • Wiz Defend provided runtime detection and automated response, surfacing full attack context and enabling immediate action.

Lean team icon

Lean team

across engineering and security supporting global roll-out

Days down to minutes icon

Days down to minutes

to remediate risks in the cloud

Accelerated enterprise-level growth icon

Accelerated enterprise-level growth

with built-in compliance features

Democratizing Cloud Security with Wiz

ROLLER was built on a simple mission: to help people create and share joyful experiences. From family entertainment centers to museums and theme parks, the SaaS company provides an all-in-one platform that powers ticketing, e-commerce, and point-of-sale for more than 3,000 customers across 35 countries. For Sean Fernandez, ROLLER’s VP of Infrastructure and Security, that mission has always depended on a single principle: being customer obsessed. “We knew from day one that protecting customer data and delivering on compliance wasn’t optional — it was core to our mission,” Sean explained.

As the business scaled globally, ROLLER’s lean engineering and security teams began to face the familiar challenge of balancing innovation with protection. Shane Burnham, ROLLER’s Lead Security Engineer describes it as “the irresistible force versus the immovable object. Engineering wants to ship fast. Security wants to slow things down. The challenge is always not being the blocker.”

Despite strong endpoint and observability tools, ROLLER lacked visibility into cloud risk. “We spent far too much time doing proof of concepts on every log item or vulnerability just to figure out if it was worth fixing,” Shane explained. “By the time we got to remediation, it was a much greater burden on both engineering and security.”

Wiz Cloud: Clarity and Context from Day One

ROLLER turned to Wiz for a single pane of glass into its cloud environment. “It was like putting on glasses,” Shane recalled. “Our view of risk was blurry, but with Wiz, suddenly everything became clear.”

“Wiz was like putting on glasses — our view of risk was blurry, but with Wiz, suddenly everything became clear.” — Shane Burnham, Lead Security Engineer, ROLLER

Within minutes of onboarding, AWS was integrated; within a day, Wiz’s Security Graph surfaced critical issues with full context. 

“Other tools felt bolted together. Wiz was crafted as one vision. The context, the correlations, the UI — it is gold-standard, designed for true DevSecOps.” - Sean Fernandez, ROLLER’s VP of Infrastructure and Security

The impact was immediate. Engineers who had once dismissed alerts as noise were now empowered to act on relevant, contextual insights. Issues that previously took days to validate and fix were resolved in hours. “Before Wiz, remediation could take three or four days. Now, we can fix issues within 15 minutes if needed,” Sean shared.

By embedding into Jira, Slack, and developer IDEs, Wiz fit seamlessly into ROLLER’s workflows and reinforced its “SOC-less” approach. For Sean, “when we talk about security at ROLLER, we ask the team “who is in charge of Security" - and it’s a trick question - everyone is in charge of security. That mentality has defined how we approach security at Roller and one of the reasons our partnership with Wiz is so critical.” 

Wiz Code — Shifting Security Left into Development

By mapping cloud risks back to the source code, IaC templates, and dependencies that introduced them, Wiz Code enables ROLLER’s engineers to remediate issues before they ever reach production.

“Wiz Code gives our developers real-time feedback in the tools they already use. It means we can prevent vulnerabilities at the source, rather than firefighting after deployment.” — Shane Burnham, Lead Security Engineer, ROLLER

For leadership, Wiz Code represents a cultural shift — security is no longer something bolted on at the end, but built into how ROLLER ships code every day. Sean has been hyper-focussed on security culture and, by “embedding Wiz Code into our workflows, it's helped us scale securely while still moving fast. It’s driven accountability across teams and made security part of our DNA.”

Wiz Defend — Real-Time Detection & Response

As ROLLER matured its cloud security strategy, they needed to go beyond visibility and ensure they could detect and respond to runtime threats quickly and effectively. 

“Before Wiz, our teams were dealing with fragmented alerts that didn’t tell the whole story. With Wiz Defend, we can see the full context of a threat, understand the attack path, and respond quickly. It’s made our security operations far more effective.”

By installing sensors across containerized workloads and integrating with existing automation, ROLLER can now identify and act on threats the moment they arise. For Sean, “because we rely so heavily on automation, we’re alerted and able to address them straight away.”

“From an engineering perspective, the visibility Wiz Defend gives us at runtime is a game-changer. We’re not just finding out something’s wrong — we know exactly where to look and how to fix it” - Sean Fernandez, ROLLER’s VP of Infrastructure and Security

Today, ROLLER runs the full Wiz stack — Wiz Code, Wiz Cloud, Wiz Sensor, and Wiz Defend. Together, these capabilities allow them to secure the entire lifecycle, from code in development to workloads in production. “From shifting left with Wiz Code to detecting runtime threats with Wiz Defend, we cover the full lifecycle,” Sean said. “Wiz is our partner across it all.”

Looking ahead, ROLLER plans to double down on automation and broaden adoption across every team. For Sean, Wiz has become more than a tool; it’s a partner that shares ROLLER’s values. “At Roller, one of our core values is obsessing over customer success. Wiz shares that same value. That’s why the partnership works so well.” For Shane, it’s more simple: “I couldn’t live without Wiz. It’s been invaluable to our security team and has changed the way we operate”.

“I couldn’t live without Wiz. It’s been invaluable to our security team and has changed the way we operate”. — Shane Burnham, Lead Security Engineer, ROLLER

Obtén una demostración personalizada

¿Listo para ver a Wiz en acción?

"La mejor experiencia de usuario que he visto en mi vida, proporciona una visibilidad completa de las cargas de trabajo en la nube."
David EstlickCISO
"Wiz proporciona un panel único para ver lo que ocurre en nuestros entornos en la nube."
Adam FletcherJefe de Seguridad
"Sabemos que si Wiz identifica algo como crítico, en realidad lo es."
Greg PoniatowskiJefe de Gestión de Amenazas y Vulnerabilidades