Security Engineer – Detection & Identity
tbi bank · Sofia, Bulgaria, BG
Checked against recruitee — still accepting applications.
- Location
- Sofia, Bulgaria, BG
- Type
- Full-time
- Posted
Join the best bank to work for in Bulgaria*
Who we are:
Do you want to join a well-established bank with a start-up culture? No, we’re not joking!
We, at tbi , have been one the most profitable banks for years and we are growing at a fast pace. We’re a bank with a long history of success that operates as a start-up and we’re always on the lookout for new opportunities to grow our business. How do we do that?
It's all about our people. Our team is made up of brave, passionate and caring people who don’t just want to follow the same path – we want to transform into mobile-first, state-of-the-art lifestyle ecosystem. Our colleagues love working here – 70% of them would recommend tbi as an employer to their friends and family. Our people are engaged in challenging and meaningful work, inspired to grow their potential and career, encouraged to learn and empowered to take decisions. That’s not corporate babble, it’s what our people say.
Do you want to play a key role in our unique success story?
We are looking for a strong, hands-on Security Engineer to build and operate our detection and identity capabilities. You will implement and run our SIEM, identity and access management (IAM) and user behaviour analytics (UEBA), and lead security incident detection and response, working across security, infrastructure and fraud teams. This is a senior individual-contributor role focused on deep technical implementation rather than people management - we are looking for a builder, not only an operator.
What You’ll do:
- Implement, configure and operate the Bank’s SIEM - log onboarding, correlation rules, detection use cases and alerting.
- Design and build detection content for threats including account abuse, enumeration, anomalous access and insider risk.
- Implement and improve identity and access management (IAM) controls - access governance, privileged access, joiner-mover-leaver and access reviews.
- Implement user and entity behaviour analytics (UEBA) and correlate activity to identities for risk-based detection.
- Configure monitoring for anomaly detection and automated response across cloud and hybrid environments.
- Coordinate and investigate information security incidents and lead technical incident response.
- Analyse large datasets and security logs from network, infrastructure and application sources.
- Develop scripts and automation for detection, enrichment and response (SOAR).
- Support the definition and control of access rights to information and critical systems.
- Evaluate and help implement new detection, identity and monitoring technologies.
Stop retyping the same form
Upload a CV once. Otto fills in this application and the next forty.
Try Free Now →