Security Architect / Senior Security Engineer - Wizeline
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+23 more
Job description
We are:Wizeline, a global AI-centric technology solutions provider, develops cutting-edge,AI-powereddigital products and platforms.We partner with clients to leverage data and AI, accelerating market entry and driving business transformation.As a global community of innovators, we foster a culture ofgrowth, collaboration,andimpact.With the right people and the right ideas, there’s no limit to what we can achieveAre you a fit?Sounds awesome, right?Now, let’s make sure you’re a good fit for the role:Responsibilities:Application Security & Offensive Testing:Conduct dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to uncover business logic flaws and vulnerabilities beyond automated scanner capabilities.Vulnerability Remediation & Triage:Establish risk-based prioritization criteria (CVSS, exploitability, business context) and directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks without disrupting operational continuity.AppSec & Security Tooling Management:Manage, configure, and optimize primary scanning tools, focusing on Wiz, Snyk, Qualys, and dynamic analysis tools (Burp Suite Enterprise/Pro, OWASP ZAP).DevSecOps & Pipeline Integration:Embed automated security checks, SAST/SCA scanning, and compliance gates directly into GitHub CI/CD pipelines for continuous verification and shift-left security.Governance & Architecture Alignment:Perform threat modeling and architecture security reviews based on OWASP SAMM principles, ensuring existing solutions meet organizational security baselines and compliance requirements (e.g., PCI-DSS, HIPAA, GDPR).Hybrid & Cloud Security:Secure and harden hybrid architecture spanning primary AWS cloud environments, containerized workloads, and on-premise infrastructure.Must-have SkillsTo be successful in this role, you must have:Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP.AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments.Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across .NET, Java, and React application stacks.DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles).Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management.Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.What we offer:Competitive compensation & total rewardsHealth benefits & wellness programsSavings & retirement plansGlobal mobility opportunitiesFlexible work policy and remote-friendly approachHappy hours, gaming tournaments, sports activities & moreContinuous learning & training programs with WizeAcademyFree certifications in cloud technologies and coding languagesFind out more about our culture here.
Requirements
Offensive & Defensive AppSec:Proven experience in Penetration Testing, Red Teaming, manual code review, and dynamic application analysis using tools like Burp Suite Professional and OWASP ZAP. AppSec Tooling Mastery (SAST / DAST / SCA):Deep hands-on expertise with Wiz (primary), Snyk, Qualys, SonarQube, and automated DAST tools integrated into active environments. Code & Infrastructure Remediation:Demonstrated ability to refactor vulnerable code, apply security patches, and remediate OWASP Top 10 vulnerabilities across . NET, Java, and React application stacks. DevSecOps & Secret Management:Hands-on experience securing CI/CD pipelines (GitHub Actions) and implementing dynamic secret management (AWS KMS, HashiCorp Vault, IAM Roles). Security Frameworks:Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) management. Cloud & Hybrid Infrastructure:Solid experience securing AWS environments, IAM policies, network security controls, and hybrid setups.
Benefits & conditions
Competitive compensation & total rewards Health benefits & wellness programs Savings & retirement plans Global mobility opportunities Flexible work policy and remote-friendly approach Happy hours, gaming tournaments, sports activities & more Continuous learning & training programs with WizeAcademy Free certifications in cloud technologies and coding languages Find out more about our culture here.
About the company
We are: Wizeline, a global AI-centric technology solutions provider, develops cutting-edge,AI-powereddigital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture ofgrowth, collaboration,andimpact. With the right people and the right ideas, there’s no limit to what we can achieve Are you a fit? Sounds awesome, right? Now, let’s make sure you’re a good fit for the role
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 138 - Are you secure about this?
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.