Security Engineer

Penneo A/S

København

Hybrid

DKK 700,000 - 900,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Penneo A/S in Copenhagen seeks a Security Engineer to own vulnerability management across our infrastructure and contribute to secure development practices. You'll work hands-on with code and infrastructure, chasing CVEs, and ensuring compliance as a QTSP in a regulated environment.

You'll collaborate with principal engineers, platform teams, Compliance & Legal, and external auditors to keep controls robust and auditable.

Qualifications

  • 2–5 years of hands-on security work in a relevant role.
  • Experience with CVEs, application security, and DoS awareness.
  • Certifications that prove security expertise are valued.
  • Ability to explain technical risks to non-technical stakeholders.
  • Hands-on with DevSecOps practices, SAST/DAST and dependency management.

Responsibilities

  • Own vulnerability management across our infrastructure and secure development practices.
  • Patch systems, chase CVEs, and ensure regulatory controls hold up.
  • Structure and automate security work from evidence collection to reporting.
  • Evolve security guidelines using internal tooling to stay ahead of risk.
  • Lead incident response from triage to fix and coordinate with Compliance & Legal.
  • Document work clearly to support QTSP certifications and audits.

Skills

CVEs
Application security
DAST
SAST
DevSecOps
Vulnerability mgmt
Stakeholder comms

Job description

Imagine being the person who keeps trust running underneath every signature, every submission, every compliant transaction across Europe. That's this job. You'll work hands-on with our application stack and infrastructure, help build the security foundation for our platform, and be the person engineering teams call when something breaks.

One day you're deep in a Terraform config chasing down a CVE. The next you're in a room with an external auditor, making sure our controls hold up. You'll fix vulnerabilities and shape the policies around them, in the same week. If that mix - real technical depth, real regulatory weight, real ownership - sounds like exactly the kind of problem you want to solve, keep reading.

About Penneo

At Penneo, we build technology that helps businesses operate with trust in an increasingly complex world. What started as a digital signing solution in Copenhagen has grown into secure, compliant workflows used across Europe. With new forms of tech- and AI-driven fraud emerging fast, our mission to protect the integrity of digital business is more important than ever.

Penneo is a Certified Trusted Service Provider - we were the very first private company in Denmark to achieve this certification. That means we're not just another SaaS company. We operate critical digital trust infrastructure under the eIDAS regulation, building products that more than 3,500 companies across Europe rely on for identity, signatures, secure data handling, and compliance.

Your role & impact

Every signature, every submission, every compliant transaction on our platform rests on the security work you do. As our Security Engineer, you'll scale that effort - hands-on, close to the code, close to the infrastructure. Operating as a Qualified Trust Service Provider means our software is regulated and our customers hold us to a high bar. You're part of the reason we clear it.

What you'll be doing
  • Own vulnerability management across our infrastructure: track CVEs, keep systems patched and current, and make sure nothing regulated slips through.
  • Strengthen application security by working directly in the code and secure development practices, alongside the teams shipping it.
  • Structure and automate our security work - from evidence collection to reporting - so it scales with us instead of slowing us down.
  • Own and evolve our security guidelines using Visma tooling to stay ahead of risk across our infrastructure.
  • Drive the response when vulnerabilities or incidents happen - from triage through to fix.
  • Work closely with our principal engineers, tech leads, and platform team, and partner tightly with Compliance & Legal on what it takes to stay a regulated, certified provider.
  • Document your work clearly. As a QTSP, our processes need to hold up to scrutiny - and so do yours.
What makes you a great match?

You've spent 2-5 years doing this job for real, not designing it on a whiteboard. You know CVEs, application security, and denial-of-service attacks the way most people know their own street. You hold the certifications to prove it. And you're just as comfortable fixing a vulnerability at 9am as you are explaining it to a non-technical stakeholder at 3pm. You are deeply familiar with DevSecOps practices, possessing hands-on experience with SAST, DAST, and dependency management across diverse package managers.

You're not an architect and you're not here to hand the hard problems to someone else. You're here to do the work.

  • Equally comfortable on the technical and process sides of security - from fixing a vulnerability to documenting a control.
  • Strong stakeholder and communication skills. You'll work with engineers, leadership, and external parties alike.
  • Able to work from our Copenhagen office around three days a week. Given the nature of the job, this isn't a fully remote role.
What's in it for you?

You'll build security infrastructure that 3,500+ companies across Europe depend on - not maintain legacy controls that nobody touches. You'll have real autonomy to shape how we approach vulnerability management, and automation. You'll work with principal engineers and technical leaders who actually ship things, not committees that oversee shipping.

Being a QTSP isn't compliance overhead - it means every control you build, every policy you write, actually has weight. You'll know your decisions matter, concretely. Thousands of businesses create signatures, identity data, and critical transactions through our platform. You'll be part of the reason they can trust it.

Practical info
  • Start date: 1 January 2027
  • No application deadline - we hire, when we find the right match.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Penneo Aps • København

On-site
DKK 550,000 - 850,000
Security Engineer - Vulnerability & Compliance
Security Engineer - Vulnerability & Compliance

Penneo Aps • København

On-site
DKK 550,000 - 850,000
Security Engineer — Hybrid, Build EU Trust Platform
Security Engineer — Hybrid, Build EU Trust Platform

Penneo A/S • København

Hybrid
DKK 700,000 - 900,000
Technical Security Consultant
Technical Security Consultant

Equa • København

Hybrid
DKK 750,000 - 1,100,000
Ownership of client engagements
Certification/conference budget
Lab for experimentation
+1
Information Security & Compliance Manager
Information Security & Compliance Manager

Teton • København

On-site
DKK 900,000 - 1,200,000
Information Security & Compliance Manager
Information Security & Compliance Manager

The Hub/Danske Bank • København

On-site
DKK 670,000 - 1,004,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Pleo • Denmark

On-site
DKK 900,000 - 1,300,000
Hybrid and remote options
Private healthcare
Generous holidays 25–28 days
+3
Information Security & Compliance Manager
Information Security & Compliance Manager

Teton.ai • København

On-site
DKK 900,000 - 1,100,000
Senior Product Security Engineer
Senior Product Security Engineer

Veo • Denmark

On-site
DKK 800,000 - 1,100,000
Indoor ball court
Rooftop terrace
Gym facility
Senior Product Security Enablement Engineer
Senior Product Security Enablement Engineer

Veo • Denmark

On-site
DKK 800,000 - 1,100,000