Join the best bank to work for in Bulgaria* Who we are: Do you want to join a well-established bank with a start-up culture? No, we’re not joking! We, at tbi, have been one of the most profitable banks for years and we are growing at a fast pace. We’re a bank with a long history of success that operates as a start-up, always on the lookout for new opportunities to grow our business. How do we do that? It’s all about our people - brave , passionate and caring people who don’t just want to follow the same path, but to transform tbi into a mobile-first, state-of-the-art lifestyle ecosystem. Our colleagues love working here - 70% of them would recommend tbi as an employer to their friends and family. Do you want to play a key role in our unique success story? We are looking for a strong, hands-on DevSecOps / Application Security Engineer to join our Information Security team. In this role you will embed security across the software development lifecycle - in our pipelines, our cloud and our applications - working closely with development, infrastructure and security teams to make secure delivery the default. This is a senior individual-contributor role focused on deep technical work rather than people management. We're looking to broaden the security expertise on our team - candidates coming from a security engineering, penetration testing or similar hands-on security background are especially encouraged to apply. What You’ll do: Take ownership of improving our Azure security posture - currently a priority area - covering identity and access (RBAC), network segmentation, logging and continuous misconfiguration detection (CSPM). Integrate, tune and operate SAST, DAST and Software Composition Analysis (SCA) tooling within the pipeline - reasoning about real exploitability and attack paths, not just running scans - to drive down false positives so developers trust the results. Partner hands-on with our DevOps team to build and harden our Infrastructure as Code (Terraform, Ansible or similar) from the ground up - embedding security by design, not just reviewing it after the fact. Integrate and manage security controls across CI/CD pipelines to enable secure software development and deployment. Implement and improve secrets management - detection, rotation and elimination of hardcoded credentials. Identify, assess and support remediation of vulnerabilities across applications, containers and infrastructure, helping stand up a structured vulnerability management program - asset inventory, scanning cadence and patch SLAs. Develop scripts and automation for security controls, compliance checks and policy enforcement. Support secure API development - authentication, authorization and secure configuration. Evaluate and help implement new application and cloud-security technologies, including emerging risks from AI-assisted ("vibe-coded") development. Support security incident investigation where application or pipeline security is involved. What you’ll need to succeed: Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity or a related field. Proven hands-on experience in application security, DevSecOps or offensive security (e.g. penetration testing), ideally in a financial institution, technology company or another highly regulated environment. Strong knowledge of: ◦ CI/CD processes and DevSecOps practices; ◦ SAST, DAST and SCA tooling; ◦ Infrastructure as Code (Terraform, Ansible or similar); ◦ Cloud security architecture and container security (Azure preferred) - identity, network design and segmentation, not only configuration scanning - and web and enterprise application architecture; ◦ Secure development, threat modeling and API security principles; ◦ Windows and Linux/UNIX operating systems. Experience with cloud security posture management (CSPM), secrets management or ASPM tooling is highly desirable. Scripting and automation skills. Strong analytical and problem-solving skills; excellent command of English (written and spoken). Professional certifications such as CompTIA Security+, CEH, CISSP, Azure/AWS Security, GIAC, ISC2 or equivalent are considered an advantage. What we offer: Take your career to the next level with real growth opportunities Work on exciting, meaningful projects that make an impact Be seen and appreciated for who you are and what you do Join a vibrant, international team of 23 nationalities who’ve got your back Stay covered with additional private health insurance Receive monthly food vouchers as part of your benefits package Enjoy exclusive perks & discounts – from Multisport cards to top retailers Benefit from special rates on our banking products Work in the heart of Sofia – steps away from the National Palace of Culture and South Park Bring your furry friend to work – because every office is better with paws Visit our Career Page to learn more about what makes us different. If this sounds like something you’d be interested in, we'd love to hear from you! To apply for this position, please send us your CV in English. We'd love to get back to everyone, but due to the number of applications we receive, we can only contact the shortlisted candidates. *We are ranked the top bank and top 4 employer to work for in Bulgaria according to WhereWeWork 2025 employer ranks. All applications are treated with utmost confidentiality. By submitting your job application to tbi bank , you confirm that you have read the document named “Information related to personal data processing for job applicants” publicly available on tbi Career page.
Security Engineer, Middle
Virtuozzo
Security Engineer – Detection & Identity
tbi bank
Senior Security Engineer
Cision
Senior Security Engineer, Identity
Bic
Senior Cybersecurity Engineer (REMOTE)
Recruitytalent
Security Automation Engineer
Aiopsgroup Ad