Security Architect / Senior Security Engineer

Wizeline

España

Híbrido

EUR 70.000 - 110.000

Jornada completa

hace 17 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Health benefits
Retirement plans
Global mobility
Remote-friendly policy
Happy hours & activities
Learning programs (WizeAcademy)
Free certifications in cloud tech &编语言

Descripción de la vacante

Wizeline is seeking an experienced Application Security professional to lead offensive and defensive AppSec efforts across live applications and APIs. You will implement secure SDLC practices, manage security tooling, and remediate vulnerabilities in multi‑stack environments.

In this role, you’ll engineer DevSecOps controls, conduct threat modeling, and ensure compliance with GDPR, PCI-DSS, and HIPAA, while securing hybrid AWS and on‑prem infrastructure.

Formación

  • Proven experience in Penetration Testing, Red Teaming, and manual code review.

Responsabilidades

  • Application Security & Offensive Testing across live applications and APIs.
  • Vulnerability remediation and triage with risk-based prioritization.
  • AppSec tooling management for Wiz, Snyk, Qualys, SonarQube, and DAST tools.
  • DevSecOps & pipeline integration into GitHub CI/CD pipelines.
  • Governance and architecture reviews based on OWASP SAMM and regulatory standards (PCI-DSS, HIPAA, GDPR).
  • Hybrid & cloud security for AWS, containers, and on‑premise infrastructure.

Conocimientos

Offensive AppSec
AppSec Tooling
Code Remediation
DevSecOps
Security Frameworks
Cloud Security

Herramientas

Wiz
Snyk
Qualys
SonarQube
Burp Suite
OWASP ZAP

Descripción del empleo

Wizeline, a global AI-centric technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture of growth, collaboration, and impact.

With the right people and the right ideas, there’s no limit to what we can achieve

Sounds awesome, right? Now, let’s make sure you’re a good fit for the role:

Responsibilities
  • Application Security & Offensive Testing: Conduct dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to uncover business logic flaws and vulnerabilities beyond automated scanner capabilities.
  • Vulnerability Remediation & Triage: Establish risk-based prioritization criteria (CVSS, exploitability, business context) and directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks without disrupting operational continuity.
  • AppSec & Security Tooling Management: Manage, configure, and optimize primary scanning tools, focusing on Wiz, Snyk, Qualys, and dynamic analysis tools (Burp Suite Enterprise/Pro, OWASP ZAP).
  • DevSecOps & Pipeline Integration: Embed automated security checks, SAST/SCA scanning, and compliance gates directly into GitHub CI/CD pipelines for continuous verification and shift-left security.
  • Governance & Architecture Alignment: Perform threat modeling and architecture security reviews based on OWASP SAMM principles, ensuring existing solutions meet organizational security baselines and compliance requirements (e.g., PCI-DSS, HIPAA, GDPR).
  • Hybrid & Cloud Security: Secure and harden hybrid architecture spanning primary AWS cloud environments, containerized workloads, and on-premise infrastructure.
Must-have Skills

To be successful in this role, you must have:

  • Offensive & Defensive AppSec: Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP.
  • AppSec Tooling Mastery (SAST / DAST / SCA): Deep hands‑on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments.
  • Code & Infrastructure Remediation: Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across .NET, Java, and React application stacks.
  • DevSecOps & Secret Management: Hands‑on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles).
  • Security Frameworks: Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management.
  • Cloud & Hybrid Infrastructure: Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.
What we offer
  • Health benefits & wellness programs
  • Savings & retirement plans
  • Global mobility opportunities
  • Flexible work policy and remote‑friendly approach
  • Happy hours, gaming tournaments, sports activities & more
  • Continuous learning & training programs with WizeAcademy
  • Free certifications in cloud technologies and coding languages
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Engineer
Security Engineer

Wizeline • Barcelona

Presencial
EUR 90.000 - 130.000
High-Impact Environment
Professional Development
Flexible Culture
+3
Site Reliability Engineer
Site Reliability Engineer

Wizeline • Barcelona

Híbrido
EUR 70.000 - 100.000
Health benefits
Wellness programs
Global mobility
+3
security engineer for web applications
security engineer for web applications

Enfint • Barcelona

Presencial
EUR 60.000 - 90.000
Commitment to professional development
Flexible and collaborative culture
Global opportunities
+2
AppSec Engineer: Pen Testing & DevSecOps
AppSec Engineer: Pen Testing & DevSecOps

Wizeline • Barcelona

Presencial
EUR 90.000 - 130.000
High-Impact Environment
Professional Development
Flexible Culture
+3
Security Architect / Senior AppSec Engineer - Remote-Ready
Security Architect / Senior AppSec Engineer - Remote-Ready

Wizeline • España

Híbrido
EUR 70.000 - 110.000
Health benefits
Retirement plans
Global mobility
+4
.NET Developer
.NET Developer

Wizeline • Barcelona

Híbrido
EUR 40.000 - 60.000
Health benefits & wellness programs
Savings & retirement plans
Global mobility opportunities
+2
Senior .NET Software Engineer
Senior .NET Software Engineer

wizeline • España

Presencial
EUR 60.000 - 90.000
A High-Impact Environment
Commitment to Professional Development
Flexible and Collaborative Culture
+3
Senior Site Reliability Engineer (AWS Cloud)
Senior Site Reliability Engineer (AWS Cloud)

Wizeline • España

Presencial
EUR 65.000 - 90.000
Senior Full-Stack Software Engineer & AI
Senior Full-Stack Software Engineer & AI

Wizeline • Barcelona

Presencial
Associate Security Engineer
Associate Security Engineer

Spendesk • Barcelona

Híbrido
EUR 40.000 - 70.000
Flexible on-site and remote policy
Latest Apple equipment
Access to Moka.care
+2