Yoummday GmbH

Senior Security Engineer (m/f/d)

Sofia · Posted 1h ago

salary not listedseniorpermanenthybridDept: CISO
AzureDefender for CloudMicrosoft SentinelLog AnalyticsTerraformPythonDjangoPowerShellEntra IDRBACPIMClaude Code

Job Description

Your mission Do you want to do more than just write security concepts - and put your decisions into practice directly? Do you see cloud security not as a compliance checklist, but as the combination of threat modeling, Infrastructure as Code, and genuine hands-on engineering? Then we are looking for you to join our CISO team as a Senior Security Engineer (m/f/d) in a hybrid working model in Sofia, Bulgaria . You will join a three-person team where responsibility is genuinely shared: no ticket queues and no “that’s not my area.” We plan together, cover for one another, and usually implement and operate the security controls we design ourselves. This means you will see the impact of your work immediately - not at some point in the distant future. Your Responsibilities Security Architecture & Cloud Guardrails: You will take technical ownership of the security architecture and controls across our Azure environment - from Defender for Cloud and Microsoft Sentinel to Log Analytics. You will build and maintain the corresponding guardrails directly in Terraform. Detection Engineering: You will develop and continuously improve our detections in close collaboration with our Security Analyst, who is responsible for day-to-day SIEM monitoring and triage. You will work as a well-coordinated team rather than in separate silos. Vulnerability Management: You will further develop our vulnerability management and monitoring across a hybrid environment. This includes our growing cloud landscape as well as the existing on-premises stack for as long as the migration is ongoing. Security Beyond the Cloud: You will contribute your expertise beyond cloud security, including identity, endpoint security, application security, incident response, and AI. Using your security engineering skills, you will, for example, develop tooling for AI-assisted penetration testing within our team and translate it into practical, scalable processes. AI-Assisted Engineering: You will use tools such as Claude Code to build and maintain internal security tools and automations. At the same time, you will help us identify AI-specific risks early—from the secure use of AI coding assistants to prompt injection. Your skillset Azure Security & Certifications: You have at least five years of experience in security engineering and several years of hands-on experience implementing Azure security. You hold an AZ-500 certification or have equivalent practical expertise. SC-100, CISSP, CCSP, or Security+ certifications are a plus. Infrastructure & Automation: You can confidently read, write, and further develop security-related Terraform code. Experience with Python, Django, PowerShell, or AI-assisted development is a plus. Identity & Detection: You have practical experience with Entra ID, RBAC, and PIM, as well as solid knowledge of network security, SIEM, and detection engineering. Offensive Security & Vulnerability Management: Ideally, you have experience with traditional or AI-assisted penetration testing and with tools such as Tenable or Microsoft Defender Vulnerability Management. Hands-On Mindset: You do not just design security controls -you implement and operate them in practice. When you identify a problem, you do not wait for a ticket; you take ownership and develop a solution. Collaboration & Communication: You share knowledge and responsibility and work closely with the team on areas of joint ownership. You communicate confidently and professionally in English. German is a plus, but not a requirement. Experience with an ongoing cloud migration and AI/LLM security is welcome, but not essential. What matters to us is what you can genuinely do - substance beats buzzword bingo. Your winning deal Your Benefits: In addition to 25 days of annual leave, we offer food vouchers, a subsidized MultiSport Card, medical and dental coverage, as well as fantastic team and company events. Your Workplace: You will work in a flexible, hybrid model and can also take advantage of two weeks of “workation” within the EU each year. *This applies only to employees holding an EU passport. Your Footprint: You will join a profitable company that gives you the freedom and trust to actively shape its future and work with us on the future of work. You will help secure the use of modern AI technologies in a company that applies AI not only within its products, but also in its own security automation. What you build will have a direct impact - not someday, but now. Our Values: We offer an open and authentic culture and a high-performing team with a great sense of humor. Your future colleagues are already looking forward to making bold decisions with you, exploring new approaches, and turning them into sustainable success. Responsibility is genuinely shared here. You will work in a small team with short decision-making paths, honest communication, and colleagues who support and cover for one another. Your Opportunity: We are at the beginning of our Azure cloud migration. You will not