Skip to content

Open nowPosted 145 days ago

Security Engineer *EU/UK remote* (m/f/d)

Pliant38 open roles

Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer *EU/UK remote* (m/f/d)Pliant · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Pliant's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Pliant postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 145 days ago

Pliant median: 7 days open

The posting

ABOUT US

Pliant is a modular B2B payments platform that combines commercial card issuing, payment accounts, FX, and spend management in one system — adapting to existing setups rather than requiring customers to replace them.

Businesses across industries such as travel, e-commerce, and insurance use Pliant to manage complex payment workflows with cards, backed by credit lines Pliant underwrites itself.

Fintechs and software platforms embed Pliant's payment infrastructure into their own products, from API-based Cards-as-a-Service to fully white-label solutions. Banks use Pliant's Card & Spend OS, the customer-facing interface, on their own infrastructure to run card programs

Founded in 2020 and headquartered in Berlin, Pliant serves 5,000+ businesses and 40+ partners across Europe and the United States. A principal member of Visa and Mastercard, Pliant issues commercial cards in 13 currencies across 32 countries — under its own European e-money license and with licensed partners in the UK and US.

Learn more at http://www.getpliant.com/www.getpliant.com http://www.getpliant.com

About the Role

We’re looking for a hands-on Security Engineer (m/f/d) with deep expertise in DevSecOps, cloud security (AWS), and automation to join our growing security team at Pliant. You'll play a critical role in designing and building secure foundations that scale. You will work closely with engineering, product, and infrastructure teams to embed security into our platform and developer workflows without slowing innovation.

This role is ideal for someone who thrives in a fast-moving environment, owns problems end-to-end, and wants to build modern, automation-driven security at scale.

What You’ll Do

- Integrate security best practices throughout the SDLC to protect products, infrastructure, and customer data.

- Design, implement, and maintain security automation tooling to address problems at scale (e.g., patch management, vulnerability management, compliance evidence collection).

- Embed security controls and guardrails into the developer platform to enable secure and efficient delivery.

- Define and promote “Paved Roads” - reusable, secure development standards and Terraform/Docker modules.

- Harden containerized workloads (ECS and EKS) - ensure clusters follow security best practices for isolation, networking, and access control; Maintain secure, up-to-date base images; enforce image signing and provenance; implement admission control, least-privilege IAM roles, and runtime anomaly detection.

- Deploy and manage cloud security platforms (e.g., Wiz) and drive remediation workflows.

- Automate collection of audit-ready evidence for frameworks like PCI DSS, ISO 27001, SOC 2, and DORA.

- Support vulnerability management (triage, SLAs, RCA) and lead incident response and post-mortems.

- Conduct threat modeling, architecture reviews, and provide guidance on secure design and cryptography.

- Build and maintain security documentation, internal tooling, and feedback loops to strengthen security culture.

- Act as a security SME across application, cloud, and compliance domains.

What We’re Looking For

- 5+ years of experience in a technical security role, preferably in a cloud-native or fintech/SaaS environment.

- Strong proficiency with AWS services and security (IAM, KMS, CloudTrail, S3, GuardDuty, SCPs, etc.).

- Solid understanding of DevSecOps practices and integrating security into CI/CD workflows.

- Proficient in Terraform and other IaC tooling, capable of writing secure, reusable modules and enforcing guardrails.

- Proficient in Python, Bash, or TypeScript – capable of scripting and building automation tools.

- Experience securing containers (Docker, ECS, EKS, or Kubernetes) and implementing hardened images.

- Expert level understanding of OWASP Top 10, secure coding, and software supply chain risks.

- Experience managing and integrating cloud security platforms (e.g., Wiz, Orca, Lacework, Prisma Cloud).

- Understanding of vulnerability management and remediation workflows at scale.

- Experience with application security practices, including code review, threat modeling, static and dynamic analysis (SAST, DAST), and attack surface analysis.

- Experience performing Application Penetration Testing or Vulnerability Research / Bug Bounty Hunting. (Ability to discover and identify fixes for SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities)

- Experience with threat modeling or security reviews.

- Excellent communication skills and empathy, security is a complex topic that you have to be able to explain to audiences of various levels of previous exposure or learning.

Bonus Skills

- Exposure to compliance frameworks (PCI DSS, ISO 27001, SOC 2).

- Familiarity with detection engineering or lightweight SIEM tooling.

- Contributions to open-source security tools or internal security automation frameworks.

What You’ll Bring

- A builder’s mindset: you enjoy solving real-world security problems with automation.

- A pragmatic approach to security: focused on reducing risk while enabling delivery.

- Willingness to dive into unknowns, collaborate across teams, and take ownership.

- Passion for clean, maintainable, and reusable code - even for security tools.

WHAT WE OFFER

- The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence

- Attractive remuneration

- Your choice of preferred OS, Windows or Mac

- Flat hierarchy and transparent communication in a relaxed, professional atmosphere

- Opportunity to develop your talent in a dynamic team with ambitious goals

- Flexibility and possibility to work remotely

- Company card with a monthly allowance for lunches, coffee, etc. with co-workers

Pliant is an equal opportunity employer. We welcome applications from people of all backgrounds, identities and abilities, and are committed to an inclusive hiring process. If you need any accommodations during the interview process, please let us know.

At Pliant we use the Ashby AI Criteria to assist with looking over resumes against our job qualifications for this role. All final decisions are made by our Talent Team and Hiring Team.

A human is behind these processes. Ashby does not automatically reject candidates or make final hiring decisions. Our teams review all results and make the final hiring decision with every candidate that applies.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Pliant's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Pliant's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Pliant's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.