> Markdown version of [/jobs/ext/2132636-security-architect-senior-security-engineer-wizeline](https://www.wearedevelopers.com/jobs/ext/2132636-security-architect-senior-security-engineer-wizeline). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect / Senior Security Engineer - Wizeline - **Company:** Wizeline - **Location:** Santiago de Compostela, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Business Analytics Applications, Business Logic, Software System Penetration Testing, Burp Suite, Cloud Computing, Cloud Computing Security, Code Review, Dynamic Program Analysis, Github, Identity and Access Management, Key Management, Network Security, Open Web Application Security, PCI Data Security Standards, Red Team (Cyber Security), Service Pack, SonarQube, Software Vulnerability Management, ReactJS, Sonatype, Software Security, Containerization, Tenable Nessus, Hashicorp, Enterprise Integration, Hardware Infrastructure, Devsecops, Qualys, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 19, 2026 - **Apply:** https://www.buscojobs.com.es/security-architect-senior-security-engineer-wizeline-en-santiago-de-compostela-ID-367785293 ## About the Role Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP. AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments. Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across . NET, Java, and React application stacks. DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles). Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management. Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups. ## Description We are:Wizeline, a global AI-centric technology solutions provider, develops cutting-edge,AI-powereddigital products and platforms.We partner with clients to leverage data and AI, accelerating market entry and driving business transformation.As a global community of innovators, we foster a culture ofgrowth, collaboration,andimpact.With the right people and the right ideas, there's no limit to what we can achieveAre you a fit?Sounds awesome, right?Now, let's make sure you're a good fit for the role:Responsibilities:Application Security & Offensive Testing:Conduct dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to uncover business logic flaws and vulnerabilities beyond automated scanner capabilities.Vulnerability Remediation & Triage:Establish risk-based prioritization criteria (CVSS, exploitability, business context) and directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks without disrupting operational continuity.AppSec & Security Tooling Management:Manage, configure, and optimize primary scanning tools, focusing on Wiz, Snyk, Qualys, and dynamic analysis tools (Burp Suite Enterprise/Pro, OWASP ZAP).DevSecOps & Pipeline Integration:Embed automated security checks, SAST/SCA scanning, and compliance gates directly into GitHub CI/CD pipelines for continuous verification and shift-left security.Governance & Architecture Alignment:Perform threat modeling and architecture security reviews based on OWASP SAMM principles, ensuring existing solutions meet organizational security baselines and compliance requirements (e.g., PCI-DSS, HIPAA, GDPR).Hybrid & Cloud Security:Secure and harden hybrid architecture spanning primary AWS cloud environments, containerized workloads, and on-premise infrastructure.Must-have SkillsTo be successful in this role, you must have:Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP.AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments.Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across .NET, Java, and React application stacks.DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles).Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management.Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.What we offer:Competitive compensation & total rewardsHealth benefits & wellness programsSavings & retirement plansGlobal mobility opportunitiesFlexible work policy and remote-friendly approachHappy hours, gaming tournaments, sports activities & moreContinuous learning & training programs with WizeAcademyFree certifications in cloud technologies and coding languagesFind out more about our culture here. ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)