Security Engineer (Barcelona)

Security Engineer (Barcelona)

15 ago
|
Doist
|
Barcelona

15 ago

Doist

Barcelona

We are: Wizeline, a global AI-native technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a general community of innovators, we foster a culture of growth, collaboration, and impact. With the right people and the right ideas, there’s no limit to what we can achieve. Are you a fit? Sounds awesome, right? Now, let’s make sure you’re a good fit for the role:Key Responsibilities- AppSec & Offensive Testing: Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to surface business logic flaws and complex vulnerabilities.- Hands‑on Vulnerability Remediation: Prioritize risks using CVSS and business context, then directly execute code‑level patches and infrastructure configuration fixes across .NET, Java, and React stacks in live production and legacy environments.- AppSec Tooling Management: Configure, manage, and optimize enterprise security scanners—including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP—to minimize noise and maximize actionable findings.- DevSecOps & Pipeline Automation: Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates directly into GitHub Actions CI/CD pipelines to enforce "shift-left" security.- Governance & Threat Modeling: Conduct architecture security reviews and threat modeling based on OWASP SAMM principles to align hybrid environments with compliance standards (e.G., PCI-DSS, HIPAA, GDPR).- Cloud & Infrastructure Hardening: Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure.Must-Have Skills- Offensive & Defensive AppSec: Proven expertise in penetration testing, red teaming, manual code reviews,



and dynamic analysis using tools like Burp Suite Professional and OWASP ZAP.- AppSec Tooling Expertise: Hands‑on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms.- Code‑Level Remediation: Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top10 vulnerabilities.- DevSecOps & Secrets Management: Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management (AWSKMS, HashiCorpVault, IAM).- SecurityFrameworks: Strong command of OWASP Top10, OWASPSAMM, threatmodeling methodologies, and SoftwareBillofMaterials (SBOM) tracking.- AWS & HybridSecurity: Demonstrated trackrecord securingAWScloudenvironments, IAMpolicies, networkcontrolsandhybrid/on‑preminfrastructure.Nice-to-Have Skills- Industry Certifications: Relevantsecuritycertificationssuch asOSCP, OSWE, CISSP, GWAPT, orAWSCertifiedSecurity–Specialty.- Healthcare&PaymentCompliance: DeepfamiliaritynavigatingregulatoryframeworkslikeHIPAA,HITRUSTandPCI-DSS withinhealthcare or fin-techenvironment.- Legacy Systems Refactoring: Practical experience untangling and securing legacy monolithic architectures without causing operational downtime.- Advanced Container Security: Experience securing containerized ecosystems (Docker, Kubernetes/EKS) and runtime security monitoring.- Nice-to-have: AI Tooling Proficiency : Leverage one or more AI tools to optimize and augment day-to-day work, including drafting, analysis, research, or process automation. Provide recommendations on effective AI use and identify opportunities to streamline workflows.- Familiarity with cloud-based infrastructure and services (e.G., AWS and GCP), Docker, and the Git version control system- Familiarity with consuming and integrating APIs in a reliable and secure manner.What we offer:- A High-Impact Environment- Commitment to Professional Development- Flexible and Collaborative Culture- Global Opportunities- Vibrant Community- Total Rewards- *Specific benefits are determined by the employment type and location.Find out more about our culture here .#J-18808-Ljbffr

📌 Security Engineer (Barcelona)
🏢 Doist
📍 Barcelona

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: security engineer (barcelona) / barcelona