Information Security Specialist @Muse Group
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago

[Hiring] Information Security Specialist @Muse Group

1mth ago - Muse Group is hiring a remote Information Security Specialist. 💸 Salary: unspecified 📍Location: Bulgaria

Role Description

We are looking for an Information Security Specialist to strengthen our approach to cyber and business security. We need an expert who can embed security by default into our IT services, working closely with our IT Operations and Application Management teams. We are actively integrating AI and automation into all areas of the business and expect candidates with a mindset focused on improving efficiency and delivering a better user experience.

  • Secure Software Development Lifecycle (S-SDLC): Build S-SDLC mostly from scratch. Own and continuously improve the company's secure SDLC framework: requirements, design and architecture review gates, secure coding standards, and the role of SAST/DAST and dependency scanning within the pipeline. Work with product and engineering teams on adoption, and track compliance against the framework.
  • SIEM implementation and management: Define the SIEM architecture, log source inventory, retention requirements, correlation rules and alerting logic, building on the company's existing log-management approach. Partner with IT Operations and Enterprise IT, who own the underlying platform build and day-to-day maintenance.
  • Monitoring of information security systems: Regularly review output from the company's security monitoring stack (endpoint detection and response, vulnerability scanning, SIEM, threat intelligence, etc.) and translate findings into prioritized, risk-based recommendations and escalations.
  • Information security audits: Plan and run internal audits against ISO 27001 and the CIS Critical Security Controls (CIS18) or similar frameworks, maintain the related compliance trackers, and coordinate external audits, penetration tests, and remediation follow-up.
  • Security architecture, configuration and “secure by default” analysis: Prepare and analyze proposals for security architecture and secure configuration of infrastructure and products. Review new initiatives against “secure by default” and “secure by design” principles, and provide written recommendations to the owning teams.
  • Information security incident handling: Participate in incident response as a governance and coordination function: support the incident team, review evidence and logs, coordinate the data-protection breach assessment, and own post-incident root-cause and lessons-learned documentation.
  • Zero Trust concept: Design the company's Zero Trust roadmap — identity-centric access, least privilege, network micro-segmentation, Zero Trust network access — and drive its adoption across corporate and product infrastructure, in partnership with the teams that implement it.

Important, what this role is and is not:

  • Is: governance, architecture and configuration review, audit planning and execution, monitoring oversight, and coordination during incident response.
  • Is not: hands-on implementation of infrastructure changes, production system administration, or a place on an on-call / out-of-hours rotation.

Hands-on access is expected for read purposes only — reviewing configurations, logs, dashboards and alerts to produce well-founded recommendations.

Qualifications

  • More than 6 years of hands-on experience in information security or IT infrastructure, with a strong technical background.
  • Solid understanding of web and mobile application vulnerabilities and secure coding practices (e.g., OWASP Top 10).
  • Ability to identify, explain, and mitigate risks based on the OWASP framework, familiarity with OWASP ASVS (Application Security Verification Standard) for security requirements and testing.
  • Practical knowledge of ISO 27001 and the CIS Critical Security Controls (CIS18) or similar frameworks; experience running or supporting internal or external security audits.
  • Working knowledge of SIEM concepts and tools (e.g., Graylog, Splunk, Elastic, Microsoft Sentinel), secure SDLC / DevSecOps practices, vulnerability management, EDR, and identity and access management.
  • Understanding of Zero Trust architecture principles and how to sequence their adoption.
  • Strong written English and the ability to produce clear, business-facing documentation and recommendations.

Requirements

  • Experience in a remote-first, multi-product SaaS or consumer software company is beneficial.
  • Prior exposure to GDPR or data-privacy work is an advantage.
  • Familiarity with CrowdStrike Falcon, Invicti, or comparable EDR / vulnerability-scanning tools.
  • Relevant certifications (e.g., CompTIA Security+, CSSLP, CISM, ISO 27001 Lead Auditor/Implementer, CISA or analogs).

Benefits

  • Creativity every day: Make inspiring products for musicians, artists and creators – no day is the same.
  • Impactful work: Influence the future of the music industry and change the lives of millions worldwide.
  • Work set up: We’ll make sure you’re set up for success with the right work equipment, whether that’s company-provided hardware or an equipment allowance.
  • Growth and development: Receive specialized training, language lessons, conferences and learning materials.
  • Team well-being: Support for your mental health and wellbeing, including confidential help during life’s tougher moments.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Bulgaria
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Information Security Specialist @Muse Group
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Bulgaria
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,072+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later