← Sottava, jobs the hour they open
2 mo agofound 2 h ago
Engineering Manager - Security *EU/UK remote*(m/f/d)
Posted by Pliant on 3 August 2026, 65 days ago. Still on their Ashby board when we checked 31 min ago.
What the posting is about
Manage security team, secure infrastructure, automate compliance, and grow team. Background in DevSecOps, cloud security, and AWS. Proficiency in Terraform, scripting, and understanding of PCI DSS, SOC 2, ISO 27001. Experience managing engineers and hiring.
Read out of the posting
LevelNot stated
Experience askedNot stated
EmploymentFull time
LocationRemote
RemoteYes
Visa sponsorshipNot stated
SalaryNot published, and most postings do not
Posted2026-08-03
Found viaashby, direct from their system
We saw it 2 months after it went up.
The posting, as the company wrote it
ABOUT US
Pliant is a modular B2B payments platform that combines commercial card issuing, payment accounts, FX, and spend management in one system — adapting to existing setups rather than requiring customers to replace them.
Businesses across industries such as travel, e-commerce, and insurance use Pliant to manage complex payment workflows with cards, backed by credit lines Pliant underwrites itself.
Fintechs and software platforms embed Pliant's payment infrastructure into their own products, from API-based Cards-as-a-Service to fully white-label solutions. Banks use Pliant's Card & Spend OS, the customer-facing interface, on their own infrastructure to run card programs.
Founded in 2020 and headquartered in Berlin, Pliant serves 5,000+ businesses and 40+ partners across Europe and the United States. A principal member of Visa and Mastercard, Pliant issues commercial cards in 13 currencies across 32 countries — under its own European e-money license and with licensed partners in the UK and US.
Learn more at http://www.getpliant.com/www.getpliant.com http://www.getpliant.com
ABOUT THE ROLE
Pliant builds corporate payment infrastructure, and the security team's job is to keep that infrastructure secure and compliant without slowing down the engineers building on it. This is the first Engineering Manager role for a team of two security engineers already covering DevSecOps, cloud security, and compliance today. You'll take over the people side while shaping where the function goes next, staying technical enough to drive lower-priority initiatives yourself, participate in reviews, and step in during incidents when the team needs you.
WHAT YOU'LL DO
- Own the security foundations the rest of engineering builds on: secure-by-default Terraform and Docker modules, hardened images for ECS and EKS workloads, and guardrails built into the developer platform rather than added afterwards.
- Drive cloud security posture day to day: remediating findings from Wiz, keeping IAM, KMS, CloudTrail, and GuardDuty tuned as Pliant scales, and ensuring the alerts that fire are ones people should actually act on.
- Automate compliance evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA so audits stop being a scramble.
- Run vulnerability management and incident response end to end: triage, SLAs, remediation, and post-mortems.
- Build the application security practice through threat modeling, architecture reviews, and secure coding guidance that product teams actually use.
- Use and build AI-native security tooling for VulnOps, red-teaming, and incident response as the threat landscape evolves.
- Grow the team: two engineers are in place today, and who you hire next sets the technical bar for security at Pliant for a long time.
WHAT YOU'LL BRING
- Hands-on background in DevSecOps or cloud security, ideally with real ownership of an AWS environment. IAM, KMS, CloudTrail, GuardDuty, and SCPs are things you have worked with directly.
- Proficiency in Terraform, including the ability to write secure, reusable modules from scratch.
- Experience securing containerized workloads (ECS, EKS, or Kubernetes), including hardened base images and admission controllers.
- Scripting ability in Python, Bash, or TypeScript sufficient to automate compliance checks and triage workflows rather than doing them by hand each quarter.
- Working knowledge of PCI DSS, SOC 2, and/or ISO 27001, plus experience running vulnerability management at scale or leading incident response for something that mattered.
- Experience managing engineers or leading technical work where people trusted your calls before you had the title, including at least one hiring decision worth learning from.
- Ability to explain a security risk clearly to non-security audiences without losing accuracy.
- A point of view on AI as an attacker's tool and how vulnerability response needs to change as discovery-to-exploitation windows keep shrinking.
- Comfort with AI-assisted development tools, and the same rigour reviewing AI-generated PRs as any other.
THE FIRST YEAR
The first few months are mostly absorbing what is already running and meeting the people who depend on it: Platform Core, SRE, and the product teams who will come to you when something looks like a security question. You will also be hiring, as Pliant is looking for a third Security Engineer to onboard on the team. By mid-year, you have a security roadmap that is not just a backlog of audit findings, and the team has grown past its current two engineers. By year one, the security posture is something you can describe in metrics rather than vibes, and compliance evidence for the next audit is being collected automatically rather than assembled by hand the week before.
STACK
Terraform, Spacelift, AWS (including a dedicated PCI-scoped account), Datadog, Wiz. We're mid-migration from ECS to Kubernetes, so container security work spans both.
WHAT WE OFFER
- The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence
- Attractive remuneration
- Your choice of preferred OS, Windows or Mac
- Flat hierarchy and transparent communication in a relaxed, professional atmosphere
- Opportunity to develop your talent in a dynamic team with ambitious goals
- Flexibility and possibility to work remotely
- Pliant Card with monthly credit to explore the product and enjoy food with colleagues
Pliant is an equal opportunity employer. We welcome applications from people of all backgrounds, identities and abilities, and are committed to an inclusive hiring process. If you need any accommodations during the interview process, please let us know.
At Pliant we use the Ashby AI Criteria to assist with looking over resumes against our job qualifications for this role. All final decisions are made by our Talent Team and Hiring Team.
A human is behind these processes. Ashby does not automatically reject candidates or make final hiring decisions. Our teams review all results and make the final hiring decision with every candidate that applies.
Also open at Pliant
Why this page exists
We read companies’ own hiring systems every hour, 1,287 of them, and show a job the hour it opens instead of when a job board gets around to indexing it. We saw it 2 months after it went up.
The feed is free. No card, no trial to expire.
Apply at PliantA free account first, no card