
Sofia Stars · Sofia City
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Supp...
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored
solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh
tech and cultural understanding.
We are looking for a Security Automation Engineer who will focus primarily on building internal services and automation solutions
across security and risk management domains.
multi-account environments;
with secrets management (Vault, SOPS, or cloud-native solutions), experience integrating security tools into CI/CD (e.g.,
Slack, Jira);
Grow fast, shine globally!
By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. Responsibilities: * Demonstrated ability to collaborate with other teams to achieve complex objectives. * Responsible for security architecture design from cloud infrastructure to application through the implementation of "secure by design" principles. * Collaborate with product managers, architects, and developers on the implementation of the security controls platform ecosystem and products. * Proof security implementations within infrastructure and application deployment manifests and the CI/CD pipelines. * Define required policies, controls, and capabilities for the protection of products and environments. * Build and validate declarative threat models automation. * Participate in engineering teams’ product planning cycles and committees. * Oversee the product security aspects for migration of products and services from Data Center to public cloud, e.g., AWS. * Serve as a trusted cyber security advisor to product and application teams. Minimum Requirements: * Experience integrating security scanning/tooling into the development pipeline. * Experience in analysing and securing microservices and applications developed using JavaScript and Typescript. * Experience with CI/CD pipelines (such as Gitlab, Jenkins) and infrastructure-as-a-code models (such as Terraform, Helm, or CloudFormation). * Hands-on development experience in Python/shell scripting. * Strong understanding of supply chain security, software integrity, and secure software delivery. * Experience with Docker and mesh technologies (such as ISTIO). * Experience with architecture and security reviews, threat modelling, and application risk is highly desired. * Experience working with Agile methodologies. * Knowledge of privacy laws and regulations, such as GDPR desired. * Familiarity with industry regulations, frameworks, and practices. For example, PCI, ISO 27001, NIST, etc. PREFERRED QUALIFICATIONS: * In-depth experience with architecting secure services on Kubernetes. * Extensive experience with architecting secure services on AWS or on-prem data centers. * Security-related professional certifications e.g., CISSP, CISM, CCSK, CCSP, CEH, are highly desirable. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a DevSecOps Engineer to join our team. Responsibilities: ✔️ Develop direction, create a roadmap and improve the DevSecOps culture in the company. ✔️ Help DevOps with secure Istio and ServiceMesh setup, Kubernetes (EKS) security setup. ✔️ Interaction with DevOps, transfer of services for their support and training in security principles. ✔️ Implementation of OPA and virtualisation configuration security analysers. ✔️ Setting up CI/CD security and improving the security of solutions that use DevOps - Terraform, Ansible, etc. ✔️ Implementing Security Scanners in Pipelines. ✔️ Automation of security processes. Requirements: ✔️ Knowledge of the basic principles of DevOps approaches (CI /CD). ✔️ Experience with Kubernetes or other orchestration tools. ✔️ Experience with Ansible/Terraform/Chef configuration management systems, etc. ✔️ Experience in web server and database administration. ✔️ Knowledge of the TCP/IP protocol stack and understanding of the OSI model. ✔️ Understanding the principles of microservice application architecture. ✔️ Experience with version control systems. ✔️ Cloud experience (AWS, GCP) Security. ✔️ Experience in infrastructure analysis for information security risks and their elimination / mitigation. ✔️ Experience in automating management processes and access control. ✔️ Experience in implementing Vault management systems and privileged user control systems. ✔️ Experience with Security scanners and implementation of their pipelines. ✔️ Understanding SSDLC (OSAMMv2) principles. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We are looking for an Access Administrator who will be responsible for managing user access to company systems and data, ensuring security and compliance with information security requirements. Duties and Responsibilities: Access Management: * Manage user accounts, including creating, modifying, and deleting accounts. * Ensure appropriate access levels are granted to employees based on their roles and job responsibilities. * Conduct regular audits of user accounts to identify and eliminate excessive or outdated access rights. * Implement and maintain access control policies to enhance security. Monitoring and Analysis: * Continuously monitor user access activities to systems and data. * Analyze incidents related to access violations and respond promptly. * Identify and analyze potential threats and vulnerabilities in access management systems. Incident Response: * Respond to and investigate incidents related to access control violations. * Escalate incidents to other teams as necessary. * Assist in coordinating incident response efforts and provide documentation of incidents. Reporting, Documentation, and Continuous Improvement: * Maintain accurate and detailed records of access management actions and steps taken. * Prepare reports on incidents and access audits. * Suggest improvements to access management processes. * Participate in post-incident reviews and propose enhancements. Role Requirements: * 1-2 years of experience in access management, account administration, or information security roles. * Understanding of access management principles and best practices in information security. * Excellent written and verbal communication skills. Ability to clearly and effectively convey complex security concepts to employees at all levels. * Strong analytical and problem-solving skills. * Experience with identity and access management (IAM) systems and other security technologies. * Skills in working with access monitoring and management tools such as Active Directory, LDAP, and similar systems. Nice to Have: * A Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. * Knowledge of regulatory requirements and standards such as ISO27001, ISO27701, PCI DSS, GDPR, and others. * Experience in automating access management tasks and writing scripts to improve processes. * Certifications in access management or information security, such as CISSP, CISM, or similar. * Experience working with the Okta access management platform is a strong plus. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.