Security Engineer
WizelineBarcelonaFull TimeEngineering
Remotely
appsecsastdastscawizburp suitesnykowasp zap
Job Description
📋 Description
- AppSec & Offensive Testing: dynamic/static testing, red team exercises, penetration testing
- Hands-on Vulnerability Remediation: patch code and fix infra across .NET, Java, and React in live
- AppSec Tooling Management: configure and optimize scanners (Wiz, Snyk, Qualys, Burp Suite
- DevSecOps & Pipeline Automation: embed SAST/SCA scanning and dynamic secrets management into
- Governance & Threat Modeling: architecture reviews and threat modeling per OWASP SAMM for
- Cloud & Infrastructure Hardening: secure hybrid AWS/cloud, containerized workloads, and on‑prem
🎯 Requirements
- Offensive & Defensible AppSec: penetration testing, red team, manual code reviews, dynamic
- AppSec Tooling Expertise: Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms.
- Code-Level Remediation: patch vulnerable code in .NET, Java, and React to fix OWASP Top 10.
- DevSecOps & Secrets Management: security in GitHub Actions and dynamic secrets (AWS KMS, Vault
- Security Frameworks: OWASP Top 10, OWASP SAMM, threat modeling, SBOM tracking.
- AWS & Hybrid Security: securing AWS environments, IAM policies, network controls, and
Benefits
- A High-Impact Environment
- Commitment to Professional Development
- Flexible and Collaborative Culture
- Global Opportunities
- Vibrant Community
- Total Rewards
*Specific benefits depend on employment type and location.
Back to all jobs