Join the best bank to work for in Bulgaria* Who we are: Do you want to join a well-established bank with a start-up culture? No, we’re not joking! We, at tbi , have been one the most profitable banks for years and we are growing at a fast pace. We’re a bank with a long history of success that operates as a start-up and we’re always on the lookout for new opportunities to grow our business. How do we do that? It's all about our people . Our team is made up of brave, passionate and caring people who don’t just want to follow the same path – we want to transform into mobile-first, state-of-the-art lifestyle ecosystem. Our colleagues love working here – 70% of them would recommend tbi as an employer to their friends and family. Our people are engaged in challenging and meaningful work, inspired to grow their potential and career, encouraged to learn and empowered to take decisions. That’s not corporate babble, it’s what our people say. Do you want to play a key role in our unique success story? We are looking for a strong, hands-on Security Engineer to build and operate our detection and identity capabilities. You will implement and run our SIEM, identity and access management (IAM) and user behaviour analytics (UEBA), and lead security incident detection and response, working across security, infrastructure and fraud teams. This is a senior individual-contributor role focused on deep technical implementation rather than people management - we are looking for a builder, not only an operator. What You’ll do: Implement, configure and operate the Bank’s SIEM - log onboarding, correlation rules, detection use cases and alerting. Design and build detection content for threats including account abuse, enumeration, anomalous access and insider risk. Implement and improve identity and access management (IAM) controls - access governance, privileged access, joiner-mover-leaver and access reviews. Implement user and entity behaviour analytics (UEBA) and correlate activity to identities for risk-based detection. Configure monitoring for anomaly detection and automated response across cloud and hybrid environments. Coordinate and investigate information security incidents and lead technical incident response. Analyse large datasets and security logs from network, infrastructure and application sources. Develop scripts and automation for detection, enrichment and response (SOAR). Support the definition and control of access rights to information and critical systems. Evaluate and help implement new detection, identity and monitoring technologies. What you’ll need to succeed: Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity or a related field. Proven hands-on experience in security monitoring, detection or incident response, ideally in a financial institution, technology company or another highly regulated environment. Strong knowledge of: ◦ SIEM implementation and detection engineering; ◦ Identity and access management (IAM) and privileged access; ◦ User and entity behaviour analytics (UEBA) concepts; ◦ Incident detection, response and investigation; ◦ Network communications, enterprise application architecture and cloud technologies; ◦ Windows and Linux/UNIX operating systems. Experience with SIEM, EDR/XDR, UEBA, SOAR or vulnerability-management platforms is highly desirable. Ability to analyse large datasets and security logs; scripting and automation skills. Strong analytical and problem-solving skills; excellent command of English (written and spoken). Professional certifications such as CompTIA Security+, CEH, CISSP, GIAC (e.g. GCIA, GCIH), Azure/AWS Security, ISC2 or equivalent are considered an advantage. What we offer: Take your career to the next level with real growth opportunities Work on exciting, meaningful projects that make an impact Be seen and appreciated for who you are and what you do Join a vibrant, international team of 23 nationalities who’ve got your back Stay covered with additional private health insurance Receive monthly food vouchers as part of your benefits package Enjoy exclusive perks & discounts – from Multisport cards to top retailers Benefit from special rates on our banking products Work in the heart of Sofia – steps away from National Palace of Culture and South Park Bring your furry friend to work – because every office is better with paws Visit our Career Page to learn more about what makes us different. If this sounds like something you’d be interested in, we'd love to hear from you! To apply for this position, please send us your CV in English. We'd love to get back to everyone, but due to the number of applications we receive, we can only contact the shortlisted candidates. *We are ranked the top bank and top 3 employer to work for in Bulgaria according tо WhereWeWork 2025 employer ranks. All applications are treated with utmost confidentiality. By submitting your job application to tbi bank , you confirm that you have read the document named “Information related to personal data processing for job applicants” publicly available on tbi Career page.
Senior Site Reliability Engineer
GoDaddy
Senior Software Engineer (MLAI services)
Workato
Network Engineer | Bulgaria | Remote
Sutherland
Site Reliability Engineer
Experian
Junior Cloud Engineer
Mainstream
Premium Services Engineer - WLAN
Hpe