Security Engineer For Web Applications

Enfint
Madrid, Spain
4 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) .NET Framework Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software System Penetration Testing Burp Suite Code Review System Configuration Dynamic Program Analysis Github Identity and Access Management
+21 more
Information Systems Security Architecture Professional Key Management Open Web Application Security PCI Data Security Standards Red Team (Cyber Security) SonarQube Web Applications Google Cloud ReactJS Sonatype Git GWAPT Containerization Hashicorp Hardware Infrastructure Code Restructuring Api Management Qualys Docker Static Application Security Testing Dynamic Application Security Testing

Job description

????????Wizeline is a global AI-native technology solutions provider that develops AI-powered digital products and platforms.It partners with clients to leverage data and AI, accelerate market entry, and drive business transformation.??????Perform SAST, DAST, SCA, red team exercises, penetration testing, and manual code reviews on live applications and APIs; Prioritize risks using CVSS and business context, and execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks; Configure, manage, and optimize enterprise security scanners, including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP; Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates into GitHub Actions CI/CD pipelines; Conduct architecture security reviews and threat modeling based on OWASP SAMM principles; Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure; Leverage AI tools to optimize and augment day-to-day work, provide recommendations on effective AI use, and identify opportunities to streamline workflows.??????????Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP; Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms; Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities; Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM; Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking; Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure; Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security - Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments; experience securing legacy monolithic architectures without operational downtime; experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration.???????Commitment to professional development Flexible and collaborative culture Global opportunities Vibrant community Total Rewards Specific benefits are determined by the employment type and location.#J-*****-Ljbffr

Requirements

Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP; Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms; Ability to read, refactor, and patch vulnerable code across . NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities; Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM; Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking; Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure; Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security - Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments; experience securing legacy monolithic architectures without operational downtime; experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration. ??????? Commitment to professional development Flexible and collaborative culture Global opportunities Vibrant community Total Rewards Specific benefits are determined by the employment type and location.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all