Security Architect / Senior Security Engineer - Donostia San Sebastián

Wizeline
Donostia / San Sebastián, Spain
1 day ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Business Analytics Applications Business Logic Software System Penetration Testing Burp Suite Cloud Computing Cloud Computing Security Code Review
+23 more
Dynamic Program Analysis Github Identity and Access Management Key Management Network Security Open Web Application Security PCI Data Security Standards Red Team (Cyber Security) Service Pack SonarQube Software Vulnerability Management ReactJS Sonatype Software Security Containerization Tenable Nessus Hashicorp Enterprise Integration Hardware Infrastructure Devsecops Qualys Static Application Security Testing Dynamic Application Security Testing

Job description

We are:Wizeline, a global AI-centric technology solutions provider, develops cutting-edge,AI-powereddigital products and platforms.We partner with clients to leverage data and AI, accelerating market entry and driving business transformation.As a global community of innovators, we foster a culture ofgrowth, collaboration,andimpact.With the right people and the right ideas, there’s no limit to what we can achieveAre you a fit?Sounds awesome, right?Now, let’s make sure you’re a good fit for the role:Responsibilities:Application Security & Offensive Testing:Conduct dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to uncover business logic flaws and vulnerabilities beyond automated scanner capabilities.Vulnerability Remediation & Triage:Establish risk-based prioritization criteria (CVSS, exploitability, business context) and directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks without disrupting operational continuity.AppSec & Security Tooling Management:Manage, configure, and optimize primary scanning tools, focusing on Wiz, Snyk, Qualys, and dynamic analysis tools (Burp Suite Enterprise/Pro, OWASP ZAP).DevSecOps & Pipeline Integration:Embed automated security checks, SAST/SCA scanning, and compliance gates directly into GitHub CI/CD pipelines for continuous verification and shift-left security.Governance & Architecture Alignment:Perform threat modeling and architecture security reviews based on OWASP SAMM principles, ensuring existing solutions meet organizational security baselines and compliance requirements (e.g., PCI-DSS, HIPAA, GDPR).Hybrid & Cloud Security:Secure and harden hybrid architecture spanning primary AWS cloud environments, containerized workloads, and on-premise infrastructure.Must-have SkillsTo be successful in this role, you must have:Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP.AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments.Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across .NET, Java, and React application stacks.DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles).Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management.Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.What we offer:Competitive compensation & total rewardsHealth benefits & wellness programsSavings & retirement plansGlobal mobility opportunitiesFlexible work policy and remote-friendly approachHappy hours, gaming tournaments, sports activities & moreContinuous learning & training programs with WizeAcademyFree certifications in cloud technologies and coding languagesFind out more about our culture here.

Requirements

Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP. AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments. Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across . NET, Java, and React application stacks. DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles). Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management. Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.

Benefits & conditions

Competitive compensation & total rewards Health benefits & wellness programs Savings & retirement plans Global mobility opportunities Flexible work policy and remote-friendly approach Happy hours, gaming tournaments, sports activities & more Continuous learning & training programs with WizeAcademy Free certifications in cloud technologies and coding languages Find out more about our culture here.

About the company

We are: Wizeline, a global AI-centric technology solutions provider, develops cutting-edge,AI-powereddigital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture ofgrowth, collaboration,andimpact. With the right people and the right ideas, there’s no limit to what we can achieve Are you a fit? Sounds awesome, right? Now, let’s make sure you’re a good fit for the role

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:21 min

Exploring the target application for front end tests

Anna Mcdougall · JS Congress

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:59 min

Introduction and transitioning into the tech industry

Anna Mcdougall · JS Congress

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all