Application Security & Observability Engineer

Job Level:  Professional
Location: 

Sofia- Srebarna 16, BG

Area of Expertise:  IT & Tech Engineering
Unit:  Allianz Bulgaria
Employing Entity:  POD Allianz Bulgaria AD
Job Type:  Full-Time
Remote Job:  Hybrid working
Employment Type:  Permanent
ID:  104969
Position Cluster:  Non-Executive

What you do

Application Security

  • Configure, maintain and monitor our code & application security tools: Static Application Security Testing (SAST), Software Composition Analysis (SCA), Web Application Firewall (WAF), and similar technologies, and adapt AI workflows and tools to ensure multiple layers of security scanning
  • Identify vulnerabilities in code, applications and infrastructure, and report findings to all relevant stakeholders
  • Act as the bridge between security findings and development teams – translating technical findings into clear, actionable guidance
  • Track and manage remediation from start to finish: follow up with developers, involve the right teams, coordinate fixes, and validate that issues are actually resolved
  • Coordinate the IT side of engagements with external penetration testers – scoping support, access, and follow-up on findings
  • Prepare security reports for internal stakeholders and external parties (audits, regulators, partners)

Observability & Monitoring

  • Configure and maintain end-to-end observability using a best-in-class observability platform
  • Advise development teams on best practices and assist for onboarding their applications to the monitoring platform
  • Regularly review application logs to spot vulnerabilities, security issues, performance problems, and opportunities for optimization
  • Support root cause analysis of production incidents
  • Collaborate with application teams to improve reliability and performance
  • Identify trends through telemetry data and recommend improvements

Continuous Improvement

  • Effectively use AI tools (e.g., Microsoft Copilot, ChatGPT, Azure AI, or similar) for requirements analysis, code scanning, documentation preparation, and data analysis while ensuring the accuracy and quality of deliverables
  • Keep our internal application security and monitoring standards up to date with new technologies, industry standards, regulatory requirements (e.g. DORA, GDPR), and architectural changes across the organization
  • Apply and help evolve internal rules, procedures and best practices in the security & observability domain
  • Integrate application security scanning into key development pipelines on a continuous basis
  • Ensure remediation and closure of vulnerabilities within agreed SLAs
  • Improve visibility and monitoring coverage across Allianz’s application portfolio

 

What you bring

Technical background

  • 3+ years of experience in application security, DevSecOps, site reliability or a closely related IT field
  • Practical experience with at least one category of code security tooling (SAST, SCA, WAF, or relevant) – for example: Checkmarx, Veracode, SonarQube, OWASP ZAP, Snyk, Fortify, or similar
  • Familiarity with an enterprise-grade observability/APM platform (e.g. Datadog, New Relic, AppDynamics)
  • Solid understanding of common application vulnerabilities (e.g. OWASP Top 10, CWE) and secure development practices
  • Comfortable reading application logs to diagnose security, performance, and reliability issues
  • Understanding of software development lifecycle and CI/CD pipelines
  • Experience with cloud-native applications and environments, including security and observability of SaaS, PaaS & IaaS solutions in Microsoft Azure and Amazon Web Services

What makes you successful

  • You're a strong communicator who can explain technical security findings to both technical and non-technical audiences
  • You have a proactive mindset – you look for issues and improvements rather than waiting for tickets to arrive
  • You're comfortable coordinating between developers, security teams, external testers, and management
  • You have an organized approach to tracking multiple open issues and fixes simultaneously to closure

Nice to have

  • Security certifications (e.g. CISSP, CEH, OSCP, Security+, or vendor-specific tool certifications)
  • Experience working in a regulated industry (finance, insurance) and familiarity with regulations such as GDPR, DORA or the EU AI Act
  • Experience automating security monitoring, reporting, vulnerability management or incident response workflows using Python, PowerShell, Bash or similar technologies.

 

What we offer 

Money 

  • Annual performance-based bonuses 
  • Free employee share + stock purchase plan 
  • Preferential pricing on Allianz products 
  • Additional pension 
  • A discount network with 50+ sites 

Time 

  • Hybrid work model 
  • Extra day off every 5 years of service 
  • Additional day off - Allianz Family Day 

Health 

  • Free medical insurance  
  • Special price for Multisport Card 
  • 24/7 mental health support 

Career 

  • Career development, digital learning & international mobility. 
  • Opportunities across insurance, asset management & banking within Allianz Group. 
  • Great Place to Work & EDGE certified environment. 
  • Fresh fruit and free coffee in the office 
  • Off-site location in the mountains 
  • Corporate teambuildings 

104969 | IT & Tech Engineering | Professional | Non-Executive | Allianz Bulgaria | Full-Time | Permanent

Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us. 

 

At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. And the foundation for this is our inclusive workplace, where people and performance both matter, and nurtures a culture grounded in integrity, fairness, inclusion and trust. 

 

We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations. 

 

Join us. Let's care for tomorrow.