27 ago
|
Wizeline
|
Cataluña
We Are Wizeline, a global AI-native technology solutions provider, develops cutting-edge, impact.
We Are
Wizeline, a global AI-native technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture of growth, collaboration, and impact.
AppSec & Offensive Testing: Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to surface business logic flaws and complex vulnerabilities. Prioritize risks using CVSS and business context, then directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks in live production and legacy environments. Configure, manage, and optimize enterprise security scanners—including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP to minimize noise and maximize actionable findings.
Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates directly into GitHub Actions CI/CD pipelines to enforce "shift-left" security.
Governance & Threat Modeling: Conduct architecture security reviews and threat modeling based on OWASP SAMM principles to align hybrid environments with compliance standards (e.g., Cloud & Infrastructure Hardening:
Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure.
Offensive & Defensive AppSec: Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools like Burp Suite Professional and OWASP ZAP. Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms. NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities.
Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management (AWS KMS, HashiCorp Vault, IAM).
Security Frameworks: Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) tracking.
AWS & Hybrid Security: Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure.
Industry Certifications: Relevant security certifications such as OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security – Specialty.
Advanced Container Security: Experience securing containerized ecosystems (Docker, Kubernetes/EKS) and runtime security monitoring. Leverage one or more AI tools to optimize and augment day-to-day work, including drafting, analysis, research, or process automation. Familiarity with cloud-based infrastructure and services (e.g., AWS and GCP), Docker, and the Git version control system Commitment to Professional Development General Opportunities
📌 CCTV Security Engineer (Cataluña)
🏢 Wizeline
📍 Cataluña