Security Engineer
✨ AI Summary
Wizeline, a global AI-native technology solutions provider, is hiring a Security Engineer in Barcelona. The role focuses on AppSec, offensive testing, and DevSecOps, requiring hands-on expertise in penetration testing, code-level remediation across .NET, Java, and React, and tooling like Wiz, Snyk, Qualys, and Burp Suite. Must-have skills include AWS and hybrid infrastructure security, OWASP frameworks, and CI/CD pipeline automation with GitHub Actions. Nice-to-haves include certifications like OSCP or CISSP and experience with HIPAA/PCI-DSS; the company offers a flexible, collaborative culture and global opportunities.
We are:
Wizeline, a global AI-native technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture of growth, collaboration, and impact.
With the right people and the right ideas, there’s no limit to what we can achieve.
Are you a fit?
Sounds awesome, right? Now, let’s make sure you’re a good fit for the role:
Key Responsibilities
-
AppSec & Offensive Testing: Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to surface business logic flaws and complex vulnerabilities.
-
Hands-on Vulnerability Remediation: Prioritize risks using CVSS and business context, then directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks in live production and legacy environments.
-
AppSec Tooling Management: Configure, manage, and optimize enterprise security scanners—including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP—to minimize noise and maximize actionable findings.
-
DevSecOps & Pipeline Automation: Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates directly into GitHub Actions CI/CD pipelines to enforce "shift-left" security.
-
Governance & Threat Modeling: Conduct architecture security reviews and threat modeling based on OWASP SAMM principles to align hybrid environments with compliance standards (e.g., PCI-DSS, HIPAA, GDPR).
-
Cloud & Infrastructure Hardening: Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure.
Must-Have Skills
-
Offensive & Defensive AppSec: Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools like Burp Suite Professional and OWASP ZAP.
-
AppSec Tooling Expertise: Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms.
-
Code-Level Remediation: Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities.
-
DevSecOps & Secrets Management: Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management (AWS KMS, HashiCorp Vault, IAM).
-
Security Frameworks: Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) tracking.
-
AWS & Hybrid Security: Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure.
Nice-to-Have Skills
-
Industry Certifications: Relevant security certifications such as OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security – Specialty.
-
Healthcare & Payment Compliance: Deep familiarity navigating regulatory frameworks like HIPAA, HITRUST, and PCI-DSS within healthcare or fin-tech environments.
-
Legacy Systems Refactoring: Practical experience untangling and securing legacy monolithic architectures without causing operational downtime.
-
Advanced Container Security: Experience securing containerized ecosystems (Docker, Kubernetes/EKS) and runtime security monitoring.
Nice-to-have:
- AI Tooling Proficiency: Leverage one or more AI tools to optimize and augment day-to-day work, including drafting, analysis, research, or process automation. Provide recommendations on effective AI use and identify opportunities to streamline workflows.
- Familiarity with cloud-based infrastructure and services (e.g., AWS and GCP), Docker, and the Git version control system
- Familiarity with consuming and integrating APIs in a reliable and secure manner.
What we offer:
- A High-Impact Environment
- Commitment to Professional Development
- Flexible and Collaborative Culture
- Global Opportunities
- Vibrant Community
- Total Rewards
*Specific benefits are determined by the employment type and location.
Find out more about our culture here.
About the Company
Wizeline is a technology services company that helps top brands think bigger and perform to the power of AI. They are consultative doers, AI-biased, human-centric, capability-rich and opinionated partners. They offer productized industry and function-oriented AI solutions to launch faster and scale smarter, with a focus on outcome-centric engagements and proven frameworks. Their services span Industry AI, Workflows AI, and SDLC AI, operating through Studios, Agentic Pods, and Frontier Partnerships.
More jobs at WIZELINE
-
Android Senior Software Engineer
Barcelona · Hybrid · Oct 2, 2026
-
iOS Software Engineer
Barcelona (Hybrid) · · Oct 2, 2026
-
Android Software Engineer (Barcelona Hybrid)
Barcelona · Hybrid · Oct 2, 2026
-
Senior iOS Software Engineer - (Barcelona - Hybrid)
Barcelona · Hybrid · Oct 2, 2026
-
Lead Fullstack Software Engineer (Javascript - Barcelona)
Barcelona, Spain · · Sep 22, 2026