Skip to content

Open nowPosted 19 days ago

Security Engineer

penneo1 open role

Where
Copenhagen
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineerpenneo · Copenhagen
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on penneo's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 19 days ago

The posting

Is this you?

Imagine being the person who keeps trust running underneath every signature, every submission, every compliant transaction across Europe. That's this job. You'll work hands-on with our application stack and infrastructure, help build the security foundation for our platform, and be the person engineering teams call when something breaks.

One day you're deep in a Terraform config chasing down a CVE. The next you're in a room with an external auditor, making sure our controls hold up. You'll fix vulnerabilities and shape the policies around them, in the same week. If that mix - real technical depth, real regulatory weight, real ownership - sounds like exactly the kind of problem you want to solve, keep reading.

About Penneo

At Penneo, we build technology that helps businesses operate with trust in an increasingly complex world. What started as a digital signing solution in Copenhagen has grown into secure, compliant workflows used across Europe. With new forms of tech- and AI-driven fraud emerging fast, our mission to protect the integrity of digital business is more important than ever.

Penneo is a Certified Trusted Service Provider - we were the very first private company in Denmark to achieve this certification. That means we're not just another SaaS company. We operate critical digital trust infrastructure under the eIDAS regulation, building products that more than 3,500 companies across Europe rely on for identity, signatures, secure data handling, and compliance.

Your role & impact

Every signature, every submission, every compliant transaction on our platform rests on the security work you do. As our Security Engineer, you'll scale that effort - hands-on, close to the code, close to the infrastructure. Operating as a Qualified Trust Service Provider means our software is regulated and our customers hold us to a high bar. You're part of the reason we clear it.

What you'll be doing:

  • Own vulnerability management across our infrastructure: track CVEs, keep systems patched and current, and make sure nothing regulated slips through.
  • Strengthen application security by working directly in the code and secure development practices, alongside the teams shipping it.
  • Structure and automate our security work - from evidence collection to reporting - so it scales with us instead of slowing us down.
  • Own and evolve our security guidelines using Visma tooling to stay ahead of risk across our infrastructure.
  • Drive the response when vulnerabilities or incidents happen - from triage through to fix.
  • Work closely with our principal engineers, tech leads, and platform team, and partner tightly with Compliance & Legal on what it takes to stay a regulated, certified provider.
  • Document your work clearly. As a QTSP, our processes need to hold up to scrutiny - and so do yours.

What makes you a great match?

You've spent 2-5 years doing this job for real, not designing it on a whiteboard. You know CVEs, application security, and denial-of-service attacks the way most people know their own street. You hold the certifications to prove it. And you're just as comfortable fixing a vulnerability at 9am as you are explaining it to a non-technical stakeholder at 3pm. You are deeply familiar with DevSecOps practices, possessing hands-on experience with SAST, DAST, and dependency management across diverse package managers.

You're not an architect and you're not here to hand the hard problems to someone else. You're here to do the work.

  • Equally comfortable on the technical and process sides of security - from fixing a vulnerability to documenting a control.
  • Strong stakeholder and communication skills. You'll work with engineers, leadership, and external parties alike.
  • Able to work from our Copenhagen office around three days a week. Given the nature of the job, this isn't a fully remote role.

What's in it for you?

You'll build security infrastructure that 3,500+ companies across Europe depend on - not maintain legacy controls that nobody touches. You'll have real autonomy to shape how we approach vulnerability management, and automation. You'll work with principal engineers and technical leaders who actually ship things, not committees that oversee shipping.

Being a QTSP isn't compliance overhead - it means every control you build, every policy you write, actually has weight. You'll know your decisions matter, concretely. Thousands of businesses create signatures, identity data, and critical transactions through our platform. You'll be part of the reason they can trust it.

Don't wait to apply!

No application deadline - we hire, when we find the right match.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against penneo's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on penneo's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    penneo's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.