Job Type: Full-Time / Hybrid
About Borek Solutions
Borek Solutions Group operates internationally in technology and business services, with a presence in Germany, India, and Kosovo. The company assists global clients with software development, AI and automation, digital products, and managed services. Its teams bring together technical know-how, innovation, and cross-border cooperation to create solutions that can scale for clients.
About the Role
Borek Solutions is seeking a Mid-Level Application & Cloud Security Engineer (Azure) to embed security across the build and operational lifecycle of a new digital platform based on Azure.
This practical technical security position brings together Application Security, Azure Cloud Security, Penetration Testing, and DevSecOps. You will partner closely with developers and technical teams to uncover vulnerabilities, reinforce application and cloud protections, and support secure development from initial design to final delivery.
Key Responsibilities
- Conduct practical penetration testing of web applications and APIs, producing clear security reports.
- Oversee Azure security, covering Key Vault, managed HSM, customer-managed keys, and key custody.
- Integrate OWASP ASVS Level 2 into development and release workflows.
- Develop and keep threat models current using STRIDE or equivalent methodologies.
- Administer Microsoft Entra ID, managed identities, and Microsoft Graph permissions.
- Examine CI/CD pipelines and Infrastructure-as-Code to identify security weaknesses.
- Evaluate application-security findings in .NET and Python environments.
- Implement GDPR, privacy-by-design, and secure-development principles.
- Collaborate directly with developers to identify, prioritize, and remediate security matters.
- Keep security documentation clear and ready for audits.
Requirements
- Several years of practical background in Application and Cloud Security, ideally in Microsoft Azure environments.
- Strong hands-on capability in web application and API penetration testing.
- Practical experience using Azure Key Vault, managed HSM, and key management.
- Familiarity with OWASP ASVS, web/API security, and threat modelling.
- Experience with Microsoft Entra ID, managed identities, and Graph permissions.
- Experience assessing secure CI/CD pipelines and Infrastructure-as-Code.
- Working knowledge of .NET and Python for conducting security assessments.
- Understanding of GDPR and security requirements for sensitive data.
- Excellent documentation, communication, and problem-solving abilities.
- Fluent English; German is an advantage.
Preferred Qualifications
- Experience in LLM and AI agent security, including risks related to prompt injection and data exfiltration.
- Knowledge of the EU AI Act and its associated technical requirements.
- Certifications including OSCP, CISSP, AZ-500, or similar.
- Experience with platforms that process sensitive or protected personal data.
What We Offer
- A permanent contract under a hybrid work arrangement, with up to 2 WFH days after 3 months.
- A welcoming and energetic work environment.
- A welcome package and health insurance paid by the employer.
- Professional growth opportunities and close cooperation with international teams in Germany & India.
Become part of Borek Solutions Group and contribute to secure, high-quality digital solutions with international reach.
Job Type: Full-Time / Hybrid
About Borek Solutions
Borek Solutions Group operates internationally in technology and business services, with a presence in Germany, India, and Kosovo. The company assists global clients with software development, AI and automation, digital products, and managed services. Its teams bring together technical know-how, innovation, and cross-border cooperation to create solutions that can scale for clients.
About the Role
Borek Solutions is seeking a Mid-Level Application & Cloud Security Engineer (Azure) to embed security across the build and operational lifecycle of a new digital platform based on Azure.
This practical technical security position brings together Application Security, Azure Cloud Security, Penetration Testing, and DevSecOps. You will partner closely with developers and technical teams to uncover vulnerabilities, reinforce application and cloud protections, and support secure development from initial design to final delivery.
Key Responsibilities
- Conduct practical penetration testing of web applications and APIs, producing clear security reports.
- Oversee Azure security, covering Key Vault, managed HSM, customer-managed keys, and key custody.
- Integrate OWASP ASVS Level 2 into development and release workflows.
- Develop and keep threat models current using STRIDE or equivalent methodologies.
- Administer Microsoft Entra ID, managed identities, and Microsoft Graph permissions.
- Examine CI/CD pipelines and Infrastructure-as-Code to identify security weaknesses.
- Evaluate application-security findings in .NET and Python environments.
- Implement GDPR, privacy-by-design, and secure-development principles.
- Collaborate directly with developers to identify, prioritize, and remediate security matters.
- Keep security documentation clear and ready for audits.
Requirements
- Several years of practical background in Application and Cloud Security, ideally in Microsoft Azure environments.
- Strong hands-on capability in web application and API penetration testing.
- Practical experience using Azure Key Vault, managed HSM, and key management.
- Familiarity with OWASP ASVS, web/API security, and threat modelling.
- Experience with Microsoft Entra ID, managed identities, and Graph permissions.
- Experience assessing secure CI/CD pipelines and Infrastructure-as-Code.
- Working knowledge of .NET and Python for conducting security assessments.
- Understanding of GDPR and security requirements for sensitive data.
- Excellent documentation, communication, and problem-solving abilities.
- Fluent English; German is an advantage.
Preferred Qualifications
- Experience in LLM and AI agent security, including risks related to prompt injection and data exfiltration.
- Knowledge of the EU AI Act and its associated technical requirements.
- Certifications including OSCP, CISSP, AZ-500, or similar.
- Experience with platforms that process sensitive or protected personal data.
What We Offer
- A permanent contract under a hybrid work arrangement, with up to 2 WFH days after 3 months.
- A welcoming and energetic work environment.
- A welcome package and health insurance paid by the employer.
- Professional growth opportunities and close cooperation with international teams in Germany & India.
Become part of Borek Solutions Group and contribute to secure, high-quality digital solutions with international reach.