1
Kategoria
Skadon
Orari
Lokacioni
	 	 

Job Type: Full-Time / Hybrid

About Borek Solutions

Borek Solutions Group is an international technology and business services company with operations in Germany, India, and Kosovo. We support international clients through software development, AI and automation, digital solutions, and managed services. Our teams combine technical expertise, innovation, and international collaboration to build scalable solutions for our clients.

About the Role

We are looking for a Mid-Level Application & Cloud Security Engineer (Azure) to ensure security is embedded throughout the development and operation of a new Azure-based digital platform.

This is a hands-on technical security role combining Application Security, Azure Cloud Security, Penetration Testing, and DevSecOps. You will work closely with developers and technical teams to identify vulnerabilities, strengthen cloud and application security, and ensure secure development from design through delivery.

Your Responsibilities

  • Perform hands-on penetration testing of web applications and APIs and provide clear security reports.
  • Manage Azure security, including Key Vault, managed HSM, customer-managed keys, and key custody.
  • Apply OWASP ASVS Level 2 as part of the development and release process.
  • Create and maintain threat models using STRIDE or equivalent methodologies.
  • Manage Microsoft Entra ID, managed identities, and Microsoft Graph permissions.
  • Review CI/CD pipelines and Infrastructure-as-Code for security vulnerabilities.
  • Assess application security findings across .NET and Python environments.
  • Apply GDPR, privacy-by-design, and secure development principles.
  • Work directly with developers to identify, prioritize, and resolve security issues.
  • Maintain clear, audit-ready security documentation.

What We Require From You

  • A few years of hands-on experience in Application and Cloud Security, preferably within Microsoft Azure.
  • Strong practical experience with web application and API penetration testing.
  • Hands-on experience with Azure Key Vault, managed HSM, and key management.
  • Knowledge of OWASP ASVS, web/API security, and threat modelling.
  • Experience with Microsoft Entra ID, managed identities, and Graph permissions.
  • Experience reviewing secure CI/CD pipelines and Infrastructure-as-Code.
  • Working knowledge of .NET and Python for security assessment.
  • Understanding of GDPR and security requirements for sensitive data.
  • Strong documentation, communication, and problem-solving skills.
  • Fluent English German is considered an advantage.

Nice to Have

  • Experience with LLM and AI agent security, including prompt injection and data-exfiltration risks.
  • Knowledge of the EU AI Act and related technical requirements.
  • Certifications such as OSCP, CISSP, AZ-500, or similar.
  • Experience working with platforms handling sensitive or protected personal data.

How to apply?

Interested? Please apply directly here

What We Offer

 

  • Permanent contract with a hybrid work model (up to 2 days WFH after 3 months).
  • Friendly, vibrant working environment.
  • Welcome package and employer-covered health insurance.
  • Opportunity for growth and close collaboration with international teams (Germany & India).

 

 

 

Join Borek Solutions Group and help us build secure, high-quality digital solutions with international impact.

 

KosovaJob është rrjeti më i madh i punësimit në Kosovë i çertifikuar nga Bureau Veritas me ISO 9001:2015 Standardet për kualitet