
Sofia Stars · Sofia City
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Supp...
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored
solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh
tech and cultural understanding.
design" principles.
and products.
CloudFormation).
Grow fast, shine globally!
By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We are looking for a Security Automation Engineer who will focus primarily on building internal services and automation solutions across security and risk management domains. Role Requirements: * Strong hands-on experience with Python (mid-level or higher, able to work independently); * Proven experience building automation services in security and/or risk management domains; * Solid experience with Bash / Shell scripting; * Experience with Git workflows (PRs, CI usage, version control best practices); * AWS (must-have): IAM (roles, policies, AssumeRole), EC2, S3, Lambda, VPC (networking fundamentals), experience with multi-account environments; * Infrastructure & Tools: Docker (build, optimization, debugging), Kubernetes, experience integrating security tools; * Security Knowledge: understanding of IAM misconfigurations, familiarity with OWASP Top 10, basic threat modeling, experience with secrets management (Vault, SOPS, or cloud-native solutions), experience integrating security tools into CI/CD (e.g., Slack, Jira); * Systems Knowledge: Linux (processes, networking, logs), Windows (AD basics, permissions); * English level: B2 or higher. Nice-to-Have: * Experience with Terraform / Infrastructure as Code (IaC); * Familiarity with cloud security tools (e.g., Prowler, ScoutSuite); * Experience with Cloudflare or edge security solutions; * Experience working with large-scale logging pipelines. Duties and Responsibilities: * Design, develop, and maintain security automation services using Python; * Build scalable tools to automate security and risk management processes across multiple departments; * Conduct technical security audits and identify vulnerabilities and improvement areas; * Develop integrations with internal systems and third-party security tools; * Create scripts and services for detecting, preventing, and mitigating security risks; * Integrate security checks and tooling into CI/CD pipelines; * Troubleshoot and debug infrastructure, applications, and automation workflows. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a DevSecOps Engineer to join our team. Responsibilities: ✔️ Develop direction, create a roadmap and improve the DevSecOps culture in the company. ✔️ Help DevOps with secure Istio and ServiceMesh setup, Kubernetes (EKS) security setup. ✔️ Interaction with DevOps, transfer of services for their support and training in security principles. ✔️ Implementation of OPA and virtualisation configuration security analysers. ✔️ Setting up CI/CD security and improving the security of solutions that use DevOps - Terraform, Ansible, etc. ✔️ Implementing Security Scanners in Pipelines. ✔️ Automation of security processes. Requirements: ✔️ Knowledge of the basic principles of DevOps approaches (CI /CD). ✔️ Experience with Kubernetes or other orchestration tools. ✔️ Experience with Ansible/Terraform/Chef configuration management systems, etc. ✔️ Experience in web server and database administration. ✔️ Knowledge of the TCP/IP protocol stack and understanding of the OSI model. ✔️ Understanding the principles of microservice application architecture. ✔️ Experience with version control systems. ✔️ Cloud experience (AWS, GCP) Security. ✔️ Experience in infrastructure analysis for information security risks and their elimination / mitigation. ✔️ Experience in automating management processes and access control. ✔️ Experience in implementing Vault management systems and privileged user control systems. ✔️ Experience with Security scanners and implementation of their pipelines. ✔️ Understanding SSDLC (OSAMMv2) principles. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a Senior Penetration Tester to join our team. Main Responsibilities: ✔️ Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS). ✔️ Run red-team and assumed-breach operations - initial access, privilege escalation, lateral movement, persistence, exfiltration - including against fraud and detection stacks. ✔️ Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices. ✔️ Discover and exploit vulnerabilities across real-money flows - payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking. ✔️ Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls. ✔️ Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists. ✔️ Build and validate declarative threat models and contribute to "secure by design" practice. ✔️ Mentor mid and junior testers, review their engagement plans and reports. ✔️ Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories - translate them into concrete changes here. ✔️ Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions. ✔️ Serve as a trusted offensive-security advisor to product, engineering, and compliance teams. Role Requirements: ✔️ Minimum 4 years of hands-on penetration testing or offensive-security experience. ✔️ Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android). ✔️ OSCP or an equivalent in-the-box certification. ✔️ Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES. ✔️ Understanding of the data flow, MVC model. ✔️ Understanding of supply chain attacks. ✔️ Good reporting skills. ✔️ Comfortable scripting in Python plus Bash. ✔️ Knowledge at least one of major cloud provider's IAM model. ✔️ Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation). ✔️ Strong written and verbal communication in English. ✔️ Experience balancing security and business demands under release pressure. ✔️ Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR. PREFERRED QUALIFICATIONS: ✔️ One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE. ✔️ In-depth experience architecting secure services on Kubernetes and AWS. ✔️ Prior iGaming, fintech, or payments domain experience. ✔️ Public CVEs, advisories, write-ups, conference talks. ✔️ HTB Pro Lab completions, real CTF placements. ✔️ Open-source contributions to offensive or defensive tooling. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.