Skip to main content
Cision

Senior Security Engineer

RemoteBulgaria only
Published
Role
Security
Experience
Senior
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to BG only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer with 3–5 years in security operations, incident response, systems administration, or cloud operations. Must be Bulgaria-based/eligible for Remote - Bulgaria, hands-on with AWS, scripting, SIEM, Linux/Windows, Active Directory, and after-hours incident response. GCP security, Kubernetes, containers, and cloud-native workloads are preferred.

Core skills

AWSSIEMLinux

Required skills

Python/Bash/PowerShellSplunk/Chronicle/SentinelWindowsActive Directory

Optional skills

GCPIAMCloud LoggingCompute EngineCloud StorageVPCsKubernetesContainers

What you'll do

  • Monitor and investigate security alerts across cloud, identity, endpoint, and network environments.
  • Review logs and activity from AWS, GCP, Active Directory, Linux systems, Windows systems, and security tools.
  • Support incident response by gathering evidence, validating suspicious activity, and documenting findings.
  • Write scripts to automate repetitive security tasks, log analysis, reporting, or enrichment.
  • Assist with security reviews, including IAM, storage exposure, compute workloads, and network configurations.
  • Investigate authentication activity, user behavior, privilege changes, and potential account compromise.
  • Work with internal teams to understand systems, identify risks, and support remediation, compliance and audit activities.
  • Be available for after-hours incident response when urgent security events require investigation or support.

What they require

  • Experience with cloud security concepts, services, logs, and IAM.
  • Strong scripting ability, preferably with Python, Bash, or PowerShell.
  • Experience with SIEM platforms such as Splunk, Chronicle, Sentinel, or similar tools.
  • Working knowledge of Linux and Windows systems, command line usage, permissions, processes, and logs.
  • Basic to intermediate understanding of Active Directory, including users, groups, authentication, and privilege changes.
  • Ability to read and interpret logs from cloud platforms, operating systems, and security tools.
  • Understanding of common security concepts such as phishing, credential compromise, privilege escalation, lateral movement, and exposed services.
  • Strong analytical, documentation, and communication skills.
  • Preferred: Experience with Google Cloud Platform security, including IAM, Cloud Logging, Compute Engine, Cloud Storage, VPCs, and service accounts.
  • Preferred: Exposure to Kubernetes, containers, or cloud-native workloads.
  • Preferred: Experience creating automation for security monitoring or response.
  • 3-5 years of experience in security operations, incident response, systems administration, cloud operations, or a similar technical role.
  • Hands-on experience using scripts to solve operational or security problems.
  • Comfortable working in both cloud and Linux command-line environments.
  • Candidates must be available for after-hours incident response when urgent security events require investigation or support.
  • The interview process will include a hands-on practical exercise conducted through screen sharing, where candidates will be asked to demonstrate relevant technical skills.

Benefits

  • Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success.
  • As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation.
  • Your growth is our success.

Cision is the global leader in consumer and media intelligence, engagement, and communication solutions. We equip PR and corporate communications, marketing, and social media professionals with the tools they need to excel in today's data driven world.

Media IntelligenceEnterprisecision.com

Details

Apply routeGreenhouse
Salary not disclosed