Application Security & Observability Engineer
Sofia- Srebarna 16, BG
What you do
Application Security
- Configure, maintain and monitor our code & application security tools: Static Application Security Testing (SAST), Software Composition Analysis (SCA), Web Application Firewall (WAF), and similar technologies, and adapt AI workflows and tools to ensure multiple layers of security scanning
- Identify vulnerabilities in code, applications and infrastructure, and report findings to all relevant stakeholders
- Act as the bridge between security findings and development teams – translating technical findings into clear, actionable guidance
- Track and manage remediation from start to finish: follow up with developers, involve the right teams, coordinate fixes, and validate that issues are actually resolved
- Coordinate the IT side of engagements with external penetration testers – scoping support, access, and follow-up on findings
- Prepare security reports for internal stakeholders and external parties (audits, regulators, partners)
Observability & Monitoring
- Configure and maintain end-to-end observability using a best-in-class observability platform
- Advise development teams on best practices and assist for onboarding their applications to the monitoring platform
- Regularly review application logs to spot vulnerabilities, security issues, performance problems, and opportunities for optimization
- Support root cause analysis of production incidents
- Collaborate with application teams to improve reliability and performance
- Identify trends through telemetry data and recommend improvements
Continuous Improvement
- Effectively use AI tools (e.g., Microsoft Copilot, ChatGPT, Azure AI, or similar) for requirements analysis, code scanning, documentation preparation, and data analysis while ensuring the accuracy and quality of deliverables
- Keep our internal application security and monitoring standards up to date with new technologies, industry standards, regulatory requirements (e.g. DORA, GDPR), and architectural changes across the organization
- Apply and help evolve internal rules, procedures and best practices in the security & observability domain
- Integrate application security scanning into key development pipelines on a continuous basis
- Ensure remediation and closure of vulnerabilities within agreed SLAs
- Improve visibility and monitoring coverage across Allianz’s application portfolio
What you bring
Technical background
- 3+ years of experience in application security, DevSecOps, site reliability or a closely related IT field
- Practical experience with at least one category of code security tooling (SAST, SCA, WAF, or relevant) – for example: Checkmarx, Veracode, SonarQube, OWASP ZAP, Snyk, Fortify, or similar
- Familiarity with an enterprise-grade observability/APM platform (e.g. Datadog, New Relic, AppDynamics)
- Solid understanding of common application vulnerabilities (e.g. OWASP Top 10, CWE) and secure development practices
- Comfortable reading application logs to diagnose security, performance, and reliability issues
- Understanding of software development lifecycle and CI/CD pipelines
- Experience with cloud-native applications and environments, including security and observability of SaaS, PaaS & IaaS solutions in Microsoft Azure and Amazon Web Services
What makes you successful
- You're a strong communicator who can explain technical security findings to both technical and non-technical audiences
- You have a proactive mindset – you look for issues and improvements rather than waiting for tickets to arrive
- You're comfortable coordinating between developers, security teams, external testers, and management
- You have an organized approach to tracking multiple open issues and fixes simultaneously to closure
Nice to have
- Security certifications (e.g. CISSP, CEH, OSCP, Security+, or vendor-specific tool certifications)
- Experience working in a regulated industry (finance, insurance) and familiarity with regulations such as GDPR, DORA or the EU AI Act
- Experience automating security monitoring, reporting, vulnerability management or incident response workflows using Python, PowerShell, Bash or similar technologies.
What we offer
Money
- Annual performance-based bonuses
- Free employee share + stock purchase plan
- Preferential pricing on Allianz products
- Additional pension
- A discount network with 50+ sites
Time
- Hybrid work model
- Extra day off every 5 years of service
- Additional day off - Allianz Family Day
Health
- Free medical insurance
- Special price for Multisport Card
- 24/7 mental health support
Career
- Career development, digital learning & international mobility.
- Opportunities across insurance, asset management & banking within Allianz Group.
- Great Place to Work & EDGE certified environment.
- Fresh fruit and free coffee in the office
- Off-site location in the mountains
- Corporate teambuildings
104969 | IT & Tech Engineering | Professional | Non-Executive | Allianz Bulgaria | Full-Time | Permanent
Allianz Group is one of the most trusted insurance and asset management companies in the world. Caring for our employees, their ambitions, dreams and challenges, is what makes us a unique employer. Together we can build an environment where everyone feels empowered and has the confidence to explore, to grow and to shape a better future for our customers and the world around us.
At Allianz, we stand for unity: we believe that a united world is a more prosperous world, and we are dedicated to consistently advocating for equal opportunities for all. And the foundation for this is our inclusive workplace, where people and performance both matter, and nurtures a culture grounded in integrity, fairness, inclusion and trust.
We therefore welcome applications regardless of ethnicity or cultural background, age, gender, nationality, religion, social class, disability or sexual orientation, or any other characteristics protected under applicable local laws and regulations.
Join us. Let's care for tomorrow.