Engineering Manager, Security *EU/UK remote*(m/f/d)

Pliant

United States

Remote

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-friendly policy
Attractive remuneration
Pliant Card monthly credit
Choose Windows or Mac OS
Flat hierarchy

Job summary

Pliant is expanding its security team and seeks an Engineering Manager for Security to guide DevSecOps, cloud security, and compliance initiatives. You’ll own security foundations, drive posture, and automate audits while maintaining fast-moving engineering timelines.

You will mentor engineers, hire when needed, and help shape the team’s long-term strategy as Pliant scales globally, with a focus on secure-by-default platforms.

Qualifications

  • Hands-on background in DevSecOps or cloud security with AWS ownership.
  • Proficiency writing secure, reusable Terraform modules.
  • Experience securing containerized workloads (ECS/EKS/Kubernetes).
  • Scripting ability in Python, Bash, or TS to automate checks.
  • Familiarity with PCI DSS, SOC 2, ISO 27001 and vulnerability management at scale.
  • Experience leading engineers and hiring decisions.
  • Ability to explain security risks to non-security audiences.

Responsibilities

  • Own security foundations: Terraform modules, hardened ECS/EKS images, secure platform guardrails.
  • Drive cloud security posture: IAM, KMS, CloudTrail, GuardDuty tuning and alert relevance.
  • Automate evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA.
  • Lead end-to-end vulnerability management and incident response.
  • Build security practice via threat modeling, architecture reviews, secure coding guidance.
  • Leverage AI-native security tooling for VulnOps and incident response.
  • Grow the team from two engineers to set the security bar long-term.

Skills

DevSecOps
Cloud security
Terraform
AWS security
Vulnerability management
Incident response
Leadership / Hiring
Python / Bash / TS

Tools

Terraform
Spacelift
AWS
Datadog
Wiz

Job description

ABOUT US

Pliant is a European fintech specializing in B2B payment solutions. Our modular, API-first platform helps businesses streamline spending, improve cash flow, and integrate payments into their financial workflows. Designed for industries with complex payment needs, such as travel and fleet, Pliant enables greater efficiency, control, and profitability.

We serve two primary customer segments:

  • Companies looking to optimize operational processes through intuitive apps and APIs, gaining control, automation, and financial flexibility through extended credit lines.

  • Businesses such as financial software platforms, ERP providers, and banks that want to launch or enhance their credit card offerings using Pliant's embedded finance and white-label solutions.

Founded in 2020 and headquartered in Berlin, Pliant supports over 4,000 businesses and more than 20 partners globally. As a licensed e-money institution (EMI), we issue credit cards in 11 currencies across more than 30 countries, helping companies streamline and simplify payments.

Learn more at www.getpliant.com

ABOUT THE ROLE

Pliant builds corporate payment infrastructure, and the security team's job is to keep that infrastructure secure and compliant without slowing down the engineers building on it. This is the first Engineering Manager role for a team of two security engineers already covering DevSecOps, cloud security, and compliance today. You'll take over the people side while shaping where the function goes next, staying technical enough to drive lower-priority initiatives yourself, participate in reviews, and step in during incidents when the team needs you.

WHAT YOU'LL DO
  • Own the security foundations the rest of engineering builds on: secure-by-default Terraform and Docker modules, hardened images for ECS and EKS workloads, and guardrails built into the developer platform rather than added afterwards.

  • Drive cloud security posture day to day: remediating findings from Wiz, keeping IAM, KMS, CloudTrail, and GuardDuty tuned as Pliant scales, and ensuring the alerts that fire are ones people should actually act on.

  • Automate compliance evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA so audits stop being a scramble.

  • Run vulnerability management and incident response end to end: triage, SLAs, remediation, and post-mortems.

  • Build the application security practice through threat modeling, architecture reviews, and secure coding guidance that product teams actually use.

  • Use and build AI-native security tooling for VulnOps, red-teaming, and incident response as the threat landscape evolves.

  • Grow the team: two engineers are in place today, and who you hire next sets the technical bar for security at Pliant for a long time.

WHAT YOU'LL BRING
  • Hands-on background in DevSecOps or cloud security, ideally with real ownership of an AWS environment. IAM, KMS, CloudTrail, GuardDuty, and SCPs are things you have worked with directly.

  • Proficiency in Terraform, including the ability to write secure, reusable modules from scratch.

  • Experience securing containerized workloads (ECS, EKS, or Kubernetes), including hardened base images and admission controllers.

  • Scripting ability in Python, Bash, or TypeScript sufficient to automate compliance checks and triage workflows rather than doing them by hand each quarter.

  • Working knowledge of PCI DSS, SOC 2, and/or ISO 27001, plus experience running vulnerability management at scale or leading incident response for something that mattered.

  • Experience managing engineers or leading technical work where people trusted your calls before you had the title, including at least one hiring decision worth learning from.

  • Ability to explain a security risk clearly to non-security audiences without losing accuracy.

  • A point of view on AI as an attacker's tool and how vulnerability response needs to change as discovery-to-exploitation windows keep shrinking.

  • Comfort with AI-assisted development tools, and the same rigour reviewing AI-generated PRs as any other.

THE FIRST YEAR

The first few months are mostly absorbing what is already running and meeting the people who depend on it: Platform Core, SRE, and the product teams who will come to you when something looks like a security question. You will also be hiring, as Pliant is looking for a third Security Engineer to onboard on the team. By mid-year, you have a security roadmap that is not just a backlog of audit findings, and the team has grown past its current two engineers. By year one, the security posture is something you can describe in metrics rather than vibes, and compliance evidence for the next audit is being collected automatically rather than assembled by hand the week before.

STACK

Terraform, Spacelift, AWS (including a dedicated PCI-scoped account), Datadog, Wiz. We\'re mid-migration from ECS to Kubernetes, so container security work spans both.

WHAT WE OFFER
  • The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence

  • Attractive remuneration

  • Your choice of preferred OS, Windows or Mac

  • Flat hierarchy and transparent communication in a relaxed, professional atmosphere

  • Opportunity to develop your talent in a dynamic team with ambitious goals

  • Flexibility and possibility to work remotely

  • Pliant Card with monthly credit to explore the product and enjoy food with colleagues

Pliant is an equal opportunity employer. We welcome applications from people of all backgrounds, identities and abilities, and are committed to an inclusive hiring process. If you need any accommodations during the interview process, please let us know.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

GoMining • United States

Hybrid
USD 120,000 - 190,000
Courses & conferences support (up to )
Remote or hybrid format with flexible,
Paid time off and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Head of Security
Head of Security

Plenful • San Francisco (CA)

Hybrid
USD 180,000 - 240,000
Healthcare Coverage
401(k) with Company Match
Equity
+5
Staff Software Engineer - Security Engineering
Staff Software Engineer - Security Engineering

MoneyLion • San Francisco (CA)

On-site
USD 180,000 - 250,000
Software Engineer, Security
Software Engineer, Security

Raydar • San Francisco (CA)

On-site
USD 250,000 - 350,000
Staff Software Engineer - Security Engineering
Staff Software Engineer - Security Engineering

Plaid • Seattle (WA)

On-site
USD 222,000 - 329,000
Staff Software Engineer (Security Engineering)
Staff Software Engineer (Security Engineering)

Plaid • United States

On-site
USD 180,000 - 240,000
Equity
401(k)
Health insurance
Head of Security
Head of Security

RXinsider LTD. • San Francisco (CA), Northern (KY)

Hybrid
USD 260,000 - 380,000
Healthcare Coverage
401(k) with Company Match
Equity
+5