14 ago
|
Wizeline
|
España
Experteer Overview
In this role you will drive application security across live apps and APIs, conducting both offensive and defensive testing to surface vulnerabilities and guide remediation.
You will work within a security-focused, cross-functional environment to harden cloud, on-prem, and hybrid systems, integrating security into CI/CD pipelines and governance practices.
You will shape secure software delivery by prioritizing risks, automating checks, and collaborating with teams to reduce business risk.
This is a high-impact opportunity to advance Wizeline’s secure software initiatives at scale.
Compensaciones / Incentivos
• Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs
• Prioritize risks using CVSS and business context, then implement code-level patches and infrastructure fixes across .NET, Java, and React stacks
• Configure, manage, and optimize enterprise security scanners (Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, OWASP ZAP)
• Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates into Git
Hub Actions CI/CD pipelines
• Conduct architecture security reviews and threat modeling based on OWASP SAMM to align with compliance standards (PCI-DSS, HIPAA, GDPR)
• Secure and harden hybrid architectures spanning AWS, containerized workloads, and on-premise infrastructure
Responsabilidades
• Penetration testing, red team, manual code reviews, and dynamic analysis experience
• Hands-on experience configuring and operating Wiz, Snyk, Qualys, Sonar
Qube, and automated DAST platforms
• Ability to read, refactor, and patch vulnerable code across .NET, Java, and React
• Experience embedding security into Git
Hub Actions pipelines and dynamic secrets management (AWS KMS, Hashi
Corp Vault, IAM)
• Strong knowledge of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking
• Experience securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure
Requisitos principales
• Total Rewards
• Flexible and Collaborative Culture
• Global Opportunities
• Professional Development
• High-Impact Environment
• Vibrant Community
📌 Security Engineer (España)
🏢 Wizeline
📍 España