
Real job — pulled straight from Wizeline’s careers page · Verified August 14, 2026 · No reposts.
Job description
Wizeline is hiring a Security Engineer — a full-time, based in Barcelona role. Apply directly on Wizeline's careers page below.
Security Engineer
Location: Barcelona
Department: Security and IT
We are:
Wizeline, a global AI-native technology solutions provider, develops cutting-edge, AI-powered digital products and platforms. We partner with clients to leverage data and AI, accelerating market entry and driving business transformation. As a global community of innovators, we foster a culture of growth, collaboration, and impact.
With the right people and the right ideas, there’s no limit to what we can achieve.
Are you a fit?
Sounds awesome, right? Now, let’s make sure you’re a good fit for the role:
Key Responsibilities
-
AppSec & Offensive Testing: Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, penetration testing, and manual code reviews on live applications and APIs to surface business logic flaws and complex vulnerabilities.
-
Hands-on Vulnerability Remediation: Prioritize risks using CVSS and business context, then directly execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks in live production and legacy environments.
-
AppSec Tooling Management: Configure, manage, and optimize enterprise security scanners—including Wiz, Snyk, Qualys, Burp Suite Enterprise/Pro, and OWASP ZAP—to minimize noise and maximize actionable findings.
-
DevSecOps & Pipeline Automation: Embed automated SAST/SCA scanning, dynamic secret management, and compliance gates directly into GitHub Actions CI/CD pipelines to enforce "shift-left" security.
-
Governance & Threat Modeling: Conduct architecture security reviews and threat modeling based on OWASP SAMM principles to align hybrid environments with compliance standards (e.g., PCI-DSS, HIPAA, GDPR).
-
Cloud & Infrastructure Hardening: Secure and harden hybrid architecture spanning AWS cloud environments, containerized workloads, and on-premise infrastructure.
Must-Have Skills
-
Offensive & Defensive AppSec: Proven expertise in penetration testing, red teaming, manual code reviews, and dynamic analysis using tools like Burp Suite Professional and OWASP ZAP.
-
AppSec Tooling Expertise: Hands-on experience configuring and operating Wiz, Snyk, Qualys, SonarQube, and automated DAST platforms.
-
Code-Level Remediation: Ability to read, refactor, and patch vulnerable code across .NET, Java, and React stacks to remediate OWASP Top 10 vulnerabilities.
-
DevSecOps & Secrets Management: Experience embedding security into GitHub Actions pipelines and implementing dynamic secrets management (AWS KMS, HashiCorp Vault, IAM).
-
Security Frameworks: Strong command of OWASP Top 10, OWASP SAMM, threat modeling methodologies, and Software Bill of Materials (SBOM) tracking.
-
AWS & Hybrid Security: Demonstrated track record securing AWS cloud environments, IAM policies, network controls, and hybrid/on-prem infrastructure.
Nice-to-Have Skills
-
Industry Certifications: Relevant security certifications such as OSCP, OSWE, CISSP, GWAPT, or AWS Certified Security – Specialty.
-
Healthcare & Payment Compliance: Deep familiarity navigating regulatory frameworks like HIPAA, HITRUST, and PCI-DSS within healthcare or fin-tech environments.
-
Legacy Systems Refactoring: Practical experience untangling and securing legacy monolithic architectures without causing operational downtime.
-
Advanced Container Security: Experience securing containerized ecosystems (Docker, Kubernetes/EKS) and runtime security monitoring.
Nice-to-have:
- AI Tooling Proficiency: Leverage one or more AI tools to optimize and augment day-to-day work, including drafting, analysis, research, or process automation. Provide recommendations on effective AI use and identify opportunities to streamline workflows.
- Familiarity with cloud-based infrastructure and services (e.g., AWS and GCP), Docker, and the Git version control system
- Familiarity with consuming and integrating APIs in a reliable and secure manner.
What we offer:
- A High-Impact Environment
- Commitment to Professional Development
- Flexible and Collaborative Culture
- Global Opportunities
- Vibrant Community
- Total Rewards
*Specific benefits are determined by the employment type and location.
Find out more about our culture here.
Get Security Engineer jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs

Senior Software Backend Engineer, Market Pricing


Senior Software Engineer, Apps & Behaviors Interfaces

Frequently asked questions
What skills are required for Security Engineer at Wizeline?
The required skills for Security Engineer at Wizeline include: AWS, IAM, Docker, Kubernetes, Git, API, PCI DSS, HIPAA, GDPR, GitHub Actions, .NET, Java, React, CISSP.
What is the seniority level for Security Engineer at Wizeline?
Security Engineer at Wizeline is a Mid Level / Senior level position.
How do I apply for Security Engineer at Wizeline?
You can view the full description and apply for Security Engineer at Wizeline on EchoJobs: https://echojobs.io/job/wizeline-security-engineer-v91m8.