21 ago
|
Enfint
|
Barcelona
Описание Wizeline is a integral AI-native technology solutions provider that develops AI-powered digital products and platforms. It partners with clients to leverage data and AI, accelerate market entry, and drive business transformation. Задачи - Perform SAST, DAST, SCA, red team exercises, penetration testing, and manual code reviews on live applications and APIs
- Prioritize risks using CVSS and business context, and execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks
- Configure, manage, and optimize enterprise security scanners, including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP
- Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates into GitHub Actions CI/CD pipelines
- Conduct architecture security reviews and threat modeling based on OWASP SAMM principles
- Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure
- Leverage AI tools to optimize and augment day-to-day work, provide recommendations on effective AI use, and identify opportunities to streamline workflows.
Требования - Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP
- Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms
- Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities;
Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM
- Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking
- Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure
- Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security - Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments;
experience securing legacy monolithic architectures without operational downtime;
experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration.
Условия - Commitment to professional development
- Flexible and collaborative culture
- Global opportunities
- Vibrant community
- Total Rewards
- Specific benefits are determined by the employment type and location.
📌 security engineer for web applications (Barcelona)
🏢 Enfint
📍 Barcelona