29 ago
|
Wizeline
|
Marzán
Wizeline, a global AI-centric technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture of growth, collaboration, and impact.
Now, let's make sure you're a good fit for the role: Responsibilities: Application Security & Offensive Testing: Conduct dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to uncover business logic flaws and vulnerabilities beyond automated scanner capabilities. Establish risk-based prioritization criteria (CVSS, exploitability, business context) and directly execute code-level patches and infrastructure configuration fixes across. NET, Java, and React stacks without disrupting operational continuity.
App Sec & Security Tooling Management: Manage, configure, and optimize primary scanning tools, focusing on Wiz, Snyk, Qualys, and dynamic analysis tools (Burp Suite Enterprise/Pro, OWASP ZAP). Embed automated security checks, SAST/SCA scanning, and compliance gates directly into Git Hub CI/CD pipelines for continuous verification and shift-left security. Perform threat modeling and architecture security reviews based on OWASP SAMM principles,
ensuring existing solutions meet organizational security baselines and compliance requirements (e.g., Hybrid & Cloud Security: Secure and harden hybrid architecture spanning primary AWS cloud environments, containerized workloads, and on-premise infrastructure.
Offensive & Defensive App Sec: Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP. Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across. NET, Java, and React application stacks.
Hands-on experience securing CI/CD pipelines (Git Hub Actions) and implementing dynamic secret management (AWS KMS, Hashi Corp Vault, IAM Roles).
Security Frameworks: Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management.
Cloud & Hybrid Infrastructure: Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups. Competitive compensation & total rewards Health benefits & wellness programs Savings & retirement plans Global mobility opportunities Versátil work policy and remote-friendly approach Happy hours, gaming tournaments, sports activities & more Continuous learning & training programs with Wize Academy Free certifications in cloud technologies and coding languages Find out more about our culture here.
📌 Security architect / senior security engineer (Marzán)
🏢 Wizeline
📍 Marzán