> Markdown version of [/jobs/ext/2947316-security-engineer-for-web-applications](https://www.wearedevelopers.com/jobs/ext/2947316-security-engineer-for-web-applications). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer For Web Applications - **Company:** Enfint - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Java (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Burp Suite, Code Review, System Configuration, Dynamic Program Analysis, Github, Identity and Access Management, Information Systems Security Architecture Professional, Key Management, Open Web Application Security, PCI Data Security Standards, Red Team (Cyber Security), SonarQube, Web Applications, Google Cloud, ReactJS, Sonatype, Git, GWAPT, Containerization, Hashicorp, Hardware Infrastructure, Code Restructuring, Api Management, Qualys, Docker, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/security-engineer-for-web-applications-en-madrid-ID-370584181 ## About the Role Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP; Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms; Ability to read, refactor, and patch vulnerable code across . NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities; Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM; Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking; Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure; Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security - Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments; experience securing legacy monolithic architectures without operational downtime; experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration. ??????? Commitment to professional development Flexible and collaborative culture Global opportunities Vibrant community Total Rewards Specific benefits are determined by the employment type and location. ## Description ????????Wizeline is a global AI-native technology solutions provider that develops AI-powered digital products and platforms.It partners with clients to leverage data and AI, accelerate market entry, and drive business transformation.??????Perform SAST, DAST, SCA, red team exercises, penetration testing, and manual code reviews on live applications and APIs; Prioritize risks using CVSS and business context, and execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks; Configure, manage, and optimize enterprise security scanners, including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP; Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates into GitHub Actions CI/CD pipelines; Conduct architecture security reviews and threat modeling based on OWASP SAMM principles; Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure; Leverage AI tools to optimize and augment day-to-day work, provide recommendations on effective AI use, and identify opportunities to streamline workflows.??????????Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools such as Burp Suite Professional and OWASP ZAP; Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms; Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities; Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management with AWS KMS, HashiCorp Vault, and IAM; Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and SBOM tracking; Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure; Nice to have: OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security - Specialty; familiarity with HIPAA, HITRUST, and PCI-DSS in healthcare or fintech environments; experience securing legacy monolithic architectures without operational downtime; experience securing Docker and Kubernetes/EKS ecosystems and runtime security monitoring; familiarity with AWS, GCP, Docker, Git, and secure API integration.???????Commitment to professional development Flexible and collaborative culture Global opportunities Vibrant community Total Rewards Specific benefits are determined by the employment type and location.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)