Do you want to do more than just write security concepts - and put your decisions into practice directly? Do you see cloud security not as a compliance checklist, but as the combination of threat modeling, Infrastructure as Code, and genuine hands-on engineering? Then we are looking for you to join our CISO team as a Senior Security Engineer (m/f/d) in a hybrid working model in Sofia, Bulgaria. You will join a three-person team where responsibility is genuinely shared: no ticket queues and no “that’s not my area.” We plan together, cover for one another, and usually implement and operate the security controls we design ourselves. This means you will see the impact of your work immediately - not at some point in the distant future.
🏢 About Yoummday GmbH
Yoummday GmbH is a profitable company that gives you the freedom and trust to actively shape its future and work with us on the future of work. We apply AI not only within our products, but also in our own security automation.
🎯 The Role
You will join our CISO team as a Senior Security Engineer (m/f/d) in a hybrid working model in Sofia, Bulgaria. You will work in a small team where responsibility is genuinely shared, and you will see the impact of your work immediately.
✅ Key Responsibilities
Security Architecture & Cloud Guardrails: Take technical ownership of the security architecture and controls across our Azure environment - from Defender for Cloud and Microsoft Sentinel to Log Analytics. Build and maintain the corresponding guardrails directly in Terraform.
Detection Engineering: Develop and continuously improve our detections in close collaboration with our Security Analyst, who is responsible for day-to-day SIEM monitoring and triage.
Vulnerability Management: Further develop our vulnerability management and monitoring across a hybrid environment, including our growing cloud landscape and the existing on-premises stack.
Security Beyond the Cloud: Contribute expertise beyond cloud security, including identity, endpoint security, application security, incident response, and AI. Develop tooling for AI-assisted penetration testing within our team and translate it into practical, scalable processes.
AI-Assisted Engineering: Use tools such as Claude Code to build and maintain internal security tools and automations. Help identify AI-specific risks early—from the secure use of AI coding assistants to prompt injection.
📌 Required Qualifications
Azure Security & Certifications: At least five years of experience in security engineering and several years of hands-on experience implementing Azure security. Hold an AZ-500 certification or have equivalent practical expertise.
Infrastructure & Automation: Confidently read, write, and further develop security-related Terraform code.
Identity & Detection: Practical experience with Entra ID, RBAC, and PIM, as well as solid knowledge of network security, SIEM, and detection engineering.
Offensive Security & Vulnerability Management: Experience with traditional or AI-assisted penetration testing and with tools such as Tenable or Microsoft Defender Vulnerability Management.
Hands-On Mindset: Design security controls and implement and operate them in practice. Take ownership and develop solutions when problems are identified.
Collaboration & Communication: Share knowledge and responsibility and work closely with the team on areas of joint ownership. Communicate confidently and professionally in English.
⭐ Desirable Experience
Experience with an ongoing cloud migration and AI/LLM security.
SC-100, CISSP, CCSP, or Security+ certifications.
Experience with Python, Django, PowerShell, or AI-assisted development.
🎁 Benefits
Your Benefits: 25 days of annual leave, food vouchers, a subsidized MultiSport Card, medical and dental coverage, as well as fantastic team and company events.
Your Workplace: Flexible, hybrid model and two weeks of “workation” within the EU each year (applies only to employees holding an EU passport).
Your Footprint: Join a profitable company that gives you the freedom and trust to actively shape its future and work with us on the future of work.
Our Values: Open and authentic culture and a high-performing team with a great sense of humor. Responsibility is genuinely shared here.
Your Opportunity: Opportunity to shape our security architecture, guardrails, and processes from the ground up.
🛂 Visa & Eligibility
No specific visa or work-authorization information was mentioned in the job description.
Please let Yoummday Gmbh know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.