Join the best bank to work for in Bulgaria*
Who we are:
Do you want to join a well-established bank with a start-up culture? No, we’re not joking!
We, at tbi, have been one of the most profitable banks for years and we are growing at a fast pace. We’re a bank with a long history of success that operates as a start-up, always on the lookout for new opportunities to grow our business. How do we do that?
It’s all about our people - brave, passionate and caring people who don’t just want to follow the same path, but to transform tbi into a mobile-first, state-of-the-art lifestyle ecosystem. Our colleagues love working here - 70% of them would recommend tbi as an employer to their friends and family.
Do you want to play a key role in our unique success story?
We are looking for a strong, hands-on DevSecOps / Application Security Engineer to join our Information Security team. In this role you will embed security across the software development lifecycle - in our pipelines, our cloud and our applications - working closely with development, infrastructure and security teams to make secure delivery the default. This is a senior individual-contributor role focused on deep technical work rather than people management.
We're looking to broaden the security expertise on our team - candidates coming from a security engineering, penetration testing or similar hands-on security background are especially encouraged to apply.
What You’ll do:
- Take ownership of improving our Azure security posture - currently a priority area - covering identity and access (RBAC), network segmentation, logging and continuous misconfiguration detection (CSPM).
- Integrate, tune and operate SAST, DAST and Software Composition Analysis (SCA) tooling within the pipeline - reasoning about real exploitability and attack paths, not just running scans - to drive down false positives so developers trust the results.
- Partner hands-on with our DevOps team to build and harden our Infrastructure as Code (Terraform, Ansible or similar) from the ground up - embedding security by design, not just reviewing it after the fact.
- Integrate and manage security controls across CI/CD pipelines to enable secure software development and deployment.
- Implement and improve secrets management - detection, rotation and elimination of hardcoded credentials.
- Identify, assess and support remediation of vulnerabilities across applications, containers and infrastructure, helping stand up a structured vulnerability management program - asset inventory, scanning cadence and patch SLAs.
- Develop scripts and automation for security controls, compliance checks and policy enforcement.
- Support secure API development - authentication, authorization and secure configuration.
- Evaluate and help implement new application and cloud-security technologies, including emerging risks from AI-assisted ("vibe-coded") development.
- Support security incident investigation where application or pipeline security is involved.