We are: Wizeline, a general AI-native technology solutions provider, develops cutting-edge, AI-powered digital products and platforms.
Todos los candidatos deben asegurarse de leer atentamente la siguiente descripción del puesto y la información antes de enviar su solicitud.
We partner with clients to leverage data and AI, accelerating market entry and driving business transformation.
As a global community of innovators, we foster a culture of growth, collaboration, and impact.
With the right people and the right ideas, there's no limit to what we can achieve.
Are you a fit?
Sounds awesome, right?
Now, let's make sure you're a good fit for the role: Key Responsibilities AppSec & Offensive Testing: Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to surface business logic flaws and complex vulnerabilities. Hands?on Vulnerability Remediation: Prioritize risks using CVSS and business context, then directly execute code?level patches and infrastructure configuration fixes across .
NET, Java, and React stacks in live production and legacy environments. App Sec Tooling Management: Configure, manage, and optimize enterprise security scanners—including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP—to minimize noise and maximize actionable findings. Dev SecOps & Pipeline Automation: Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates directly into Git Hub Actions CI/CD pipelines to enforce "shift-left" security. Governance & Threat Modeling: Conduct architecture security reviews and threat modeling based on OWASP SAMM principles to align hybrid environments with compliance standards (e.G., PCI-DSS, HIPAA, GDPR).
Cloud & Infrastructure Hardening: Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure. Must-Have Skills Offensive & Defensive App Sec: Proven expertise in penetration testing, red teaming, manual code reviews,
and dynamic analysis using tools like Burp Suite Professional and OWASP ZAP. App Sec Tooling Expertise: Hands?on experience configuring and operating Wiz, Snyk, Qualys, Sonar Qube, and automated DAST ?Level Remediation: Ability to read, refactor, and patch vulnerable code across .
NET, Java, and React stacks to remediate OWASP Top10 vulnerabilities. Dev SecOps & Secrets Management: Experience embedding security into Git Hub Actions pipelines and implementing dynamic secrets management (AWSKMS, Hashi Corp Vault, IAM).
Security Frameworks: Strong command of OWASP Top10, OWASPSAMM, threatmodeling methodologies, and Software Billof Materials (SBOM) tracking.AWS & Hybrid Security: Demonstrated trackrecord securingAWScloudenvironments, IAMpolicies, networkcontrolsandhybrid/on?preminfrastructure. Nice-to-Have Skills Industry Certifications: Relevantsecuritycertificationssuch asOSCP, OSWE, CISSP, GWAPT, orAWSCertified Security–Specialty. Healthcare&Payment; Compliance: DeepfamiliaritynavigatingregulatoryframeworkslikeHIPAA,HITRUSTandPCI-DSS withinhealthcare or fin-techenvironment. Legacy Systems Refactoring: Practical experience untangling and securing legacy monolithic architectures without causing operational downtime. Advanced Container Security: Experience securing containerized ecosystems (Docker, Kubernetes/EKS) and runtime security monitoring. Nice-to-have: AI Tooling Proficiency: Leverage one or more AI tools to optimize and augment day-to-day work, including drafting, analysis, research, or process automation.
Provide recommendations on effective AI use and identify opportunities to streamline workflows. Familiarity with cloud-based infrastructure and services (e.G., AWS and GCP), Docker, and the Git version control system Familiarity with consuming and integrating APIs in a reliable and secure manner.
xqysrnh What we offer:A High-Impact Environment Commitment to Professional Development Flexible and Collaborative Culture Global Opportunities Vibrant Community Total Rewards *Specific benefits are determined by the employment type and out more about our culture here.
#J-*****-Ljbffr
📌 Security Engineer (España)
🏢 Doist
📍 España