
Sofia Stars · Sofia City
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Supp...
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored
solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh
tech and cultural understanding.
We are looking for an Access Administrator who will be responsible for managing user access to company systems and data, ensuring
security and compliance with information security requirements.
employees at all levels.
Grow fast, shine globally!
By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We are looking for an experienced Security Access Management Team Lead to join our Information Security team. This role combines hands-on access management expertise with team leadership responsibilities. Duties and Responsibilities: * Lead and manage the Access Administration team, including daily operations, task distribution, prioritization, and performance monitoring. * Track and ensure compliance with SLA and KPI requirements. * Manage user access lifecycle processes, including creating, modifying, reviewing, and removing user accounts and permissions. * Ensure that appropriate access levels are granted to employees based on their roles, responsibilities, and business needs. * Implement, maintain, and improve RBAC principles and access control policies. * Conduct regular access reviews and audits to identify excessive, outdated, or inappropriate access rights. * Monitor user access activities across internal systems, SaaS platforms, and business applications. * Analyze and respond to access-related incidents, violations, and security risks. * Investigate potential threats and vulnerabilities related to access management processes. * Escalate complex incidents to relevant teams when needed and coordinate response actions. * Maintain accurate documentation of access management activities, incidents, decisions, and process improvements. * Prepare reports on access audits, incidents, SLA/KPI results, and team performance. * Review and assess third-party SaaS services from an access management and security perspective. * Ensure that Information Security principles, least privilege, and proper approval workflows are followed across the organization. * Support continuous improvement of IAM/PAM processes, tools, and internal procedures. Role Requirements: * 5+ years of experience in Information Security. * At least 1 year of experience in management as a Team Lead. * Strong understanding of IAM, PAM, RBAC, least privilege, and access governance principles. * Hands-on experience with access management processes, user lifecycle management and access reviews. * Experience working with SaaS platforms and reviewing third-party services from a security/access perspective. * Good knowledge of InfoSec principles, security policies, incident handling, and audit requirements. * Experience with SLA/KPI tracking and operational team management. * Strong problem-solving skills and the ability to make decisions in complex or urgent situations. * Excellent communication and stakeholder management skills. * Ability to document processes, prepare reports, and drive continuous improvements. Nice to Have * Experience with Microsoft Entra ID, Okta, or similar IAM tools. * Experience with Salespoint or other access governance platforms. * Information Security certifications such as ISO 27001, CISM or similar. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a DevSecOps Engineer to join our team. Responsibilities: ✔️ Develop direction, create a roadmap and improve the DevSecOps culture in the company. ✔️ Help DevOps with secure Istio and ServiceMesh setup, Kubernetes (EKS) security setup. ✔️ Interaction with DevOps, transfer of services for their support and training in security principles. ✔️ Implementation of OPA and virtualisation configuration security analysers. ✔️ Setting up CI/CD security and improving the security of solutions that use DevOps - Terraform, Ansible, etc. ✔️ Implementing Security Scanners in Pipelines. ✔️ Automation of security processes. Requirements: ✔️ Knowledge of the basic principles of DevOps approaches (CI /CD). ✔️ Experience with Kubernetes or other orchestration tools. ✔️ Experience with Ansible/Terraform/Chef configuration management systems, etc. ✔️ Experience in web server and database administration. ✔️ Knowledge of the TCP/IP protocol stack and understanding of the OSI model. ✔️ Understanding the principles of microservice application architecture. ✔️ Experience with version control systems. ✔️ Cloud experience (AWS, GCP) Security. ✔️ Experience in infrastructure analysis for information security risks and their elimination / mitigation. ✔️ Experience in automating management processes and access control. ✔️ Experience in implementing Vault management systems and privileged user control systems. ✔️ Experience with Security scanners and implementation of their pipelines. ✔️ Understanding SSDLC (OSAMMv2) principles. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a Senior Penetration Tester to join our team. Main Responsibilities: ✔️ Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS). ✔️ Run red-team and assumed-breach operations - initial access, privilege escalation, lateral movement, persistence, exfiltration - including against fraud and detection stacks. ✔️ Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices. ✔️ Discover and exploit vulnerabilities across real-money flows - payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking. ✔️ Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls. ✔️ Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists. ✔️ Build and validate declarative threat models and contribute to "secure by design" practice. ✔️ Mentor mid and junior testers, review their engagement plans and reports. ✔️ Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories - translate them into concrete changes here. ✔️ Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions. ✔️ Serve as a trusted offensive-security advisor to product, engineering, and compliance teams. Role Requirements: ✔️ Minimum 4 years of hands-on penetration testing or offensive-security experience. ✔️ Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android). ✔️ OSCP or an equivalent in-the-box certification. ✔️ Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES. ✔️ Understanding of the data flow, MVC model. ✔️ Understanding of supply chain attacks. ✔️ Good reporting skills. ✔️ Comfortable scripting in Python plus Bash. ✔️ Knowledge at least one of major cloud provider's IAM model. ✔️ Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation). ✔️ Strong written and verbal communication in English. ✔️ Experience balancing security and business demands under release pressure. ✔️ Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR. PREFERRED QUALIFICATIONS: ✔️ One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE. ✔️ In-depth experience architecting secure services on Kubernetes and AWS. ✔️ Prior iGaming, fintech, or payments domain experience. ✔️ Public CVEs, advisories, write-ups, conference talks. ✔️ HTB Pro Lab completions, real CTF placements. ✔️ Open-source contributions to offensive or defensive tooling. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.