Security Engineer
Job description
About the role
You will lead application security initiatives for global clients as part of a high-performing, cross-functional security team. This role owns the end-to-end security posture of production applications and APIs through rigorous testing and validation. You will design and execute red team exercises that emulate sophisticated adversary tactics to uncover business logic flaws. You will partner closely with product and engineering teams to embed security into every phase of the delivery lifecycle. Your work will directly shape the security standards and tooling used across enterprise environments worldwide. You will mentor junior analysts on best practices for secure coding and threat analysis. You will translate complex technical findings into clear risk assessments and actionable remediation plans for stakeholders. This role thrives in fast-paced, ambiguous environments where ownership and impact are driven by expertise.
Key facts
What you'll do
Perform dynamic and static application security testing (SAST/DAST/SCA) against customer-facing applications and APIs to discover critical vulnerabilities.
Execute red team exercises and penetration tests that simulate advanced persistent threats against complex, multi-tier applications in production environments.
Prioritize and remediate security findings using CVSS scoring, business context analysis, and risk-based decision frameworks across .NET, Java, and React technology stacks.
Configure, tune, and optimize enterprise security toolsets including Wiz, Snyk, Qualys, Burp Suite Enterprise, and OWASP ZAP to reduce noise and surface true positive findings.
Embed security controls directly into CI/CD pipelines through GitHub Actions, implementing automated scanning, secret management, and compliance gating aligned with DevSecOps principles.
Conduct architecture-level security reviews and threat modeling sessions based on OWASP Software Assurance Maturity Model (SAMM) guidelines.
Harden hybrid cloud and on-premise infrastructure security across AWS environments, containerized workloads, and legacy systems.
Maintain compliance mappings for frameworks such as PCI-DSS, HIPAA, and GDPR through systematic security assessments and evidence collection.
Lead security investigations for escalated incidents, performing root cause analysis and recommending long-term defensive improvements.
Document security test procedures, attack paths, and remediation guidance to support audit activities and internal knowledge sharing.
Collaborate with product managers and engineering leads to define security acceptance criteria for new features and releases.
Mentor security analysts and engineers by sharing practical techniques, tooling tips, and lessons learned from live engagements.
Stay current with emerging offensive and defensive security research, integrating relevant findings into testing methodologies and standards.
Act as a technical authority for application security, influencing strategic decisions and shaping the Wizeline security practice.
Requirements
Demonstrate proven offensive and defensive application security skills with hands-on experience in penetration testing, red teaming, and manual code reviews.
Show advanced expertise in AppSec tooling, including configuration and optimization of Wiz, Snyk, Qualys, SonarQube, Burp Suite Professional, and OWASP ZAP.
Possess the ability to read, analyze, and remediate vulnerable code across .NET, Java, and React stacks to address OWASP Top 10 risks.
Exhibit strong understanding of secure software development lifecycle practices and how to operationalize security within hybrid cloud architectures.
Have experience conducting threat modeling and architecture security reviews aligned with industry frameworks and compliance requirements.
Hold a strong sense of ownership for driving security outcomes in ambiguous, deadline-driven environments.
Communicate complex technical risks clearly to both technical and executive audiences through written and verbal communication.
Demonstrate eagerness to continuously learn emerging attack techniques, defensive patterns, and security tooling capabilities.
Nice to have
Experience with cloud security platforms and infrastructure hardening on AWS environments.
Familiarity with security standards and certifications such as PCI-DSS, HIPAA, and GDPR.
Background in DevSecOps automation and CI/CD pipeline security integration.
Practical notes
This is a full-time position based in Barcelona.
No visa sponsorship is mentioned in the source information.
No specific travel requirements are outlined in the source material.
No explicit application deadline is provided in the source.