Security Engineer *EU/UK remote*; m/f/d
04103, Leipzig, Sachsen, Deutschland
Verfasst am 2026-10-07
-
IT/Informationstechnik
Cyber-Sicherheit, Informationssicherheit & Datenschutz
ABOUT US
Pliant is a European fintech specializing in B2B payment solutions. Our modular, API-first platform helps businesses streamline spending, improve cash flow, and integrate payments into their financial workflows. Designed for industries with complex payment needs, such as travel and fleet, Pliant enables greater efficiency, control, and profitability.
We serve two primary customer segments:
- Companies looking to optimize operational processes through intuitive apps and APIs, gaining control, automation, and financial flexibility through extended credit lines.
- Businesses such as financial software platforms, ERP providers, and banks that want to launch or enhance their credit card offerings using Pliant’s embedded finance and white-label solutions.
Founded in 2020 and headquartered in Berlin, Pliant supports over 4,000 businesses and more than 20 partners globally. As a licensed e-money institution (EMI), we issue credit cards in 11 currencies across more than 30 countries, helping companies streamline and simplify payments.
Learn more at
About the RoleWe’re looking for a hands-on Security Engineer EU/UK remote (m/f/d) with deep expertise in Dev Sec Ops , cloud security (AWS), and automation to join our growing security team 'll play a critical role in designing and building secure foundations that scale. You will work closely with engineering, product, and infrastructure teams to embed security into our platform and developer workflows without slowing innovation.
This role is ideal for someone who thrives in a fast-moving environment, owns problems end-to-end, and wants to build modern, automation-driven security at scale.
What You’ll Do- Integrate security best practices throughout the SDLC to protect products, infrastructure, and customer data.
- Design, implement, and maintain security automation tooling to address problems at scale (e.g., patch management, vulnerability management, compliance evidence collection).
- Embed security controls and guardrails into the developer platform to enable secure and efficient delivery.
- Define and promote "Paved Roads" - reusable, secure development standards and Terraform/Docker modules.
- Harden containerized workloads (ECS and EKS) - ensure clusters follow security best practices for isolation, networking, and access control;
Maintain secure, up-to-date base images; enforce image signing and provenance; implement admission control, least-privilege IAM roles, and runtime anomaly detection. - Deploy and manage cloud security platforms (e.g., Wiz) and drive remediation workflows.
- Automate collection of audit-ready evidence for frameworks like PCI DSS, ISO 27001, SOC 2, and DORA.
- Support vulnerability management (triage, SLAs, RCA) and lead incident response and post-mortems.
- Conduct threat modeling, architecture reviews, and provide guidance on secure design and cryptography.
- Build and maintain security documentation, internal tooling, and feedback loops to strengthen security culture.
- Act as a security SME across application, cloud, and compliance domains.
- 5+ years of experience in a technical security role, preferably in a cloud-native or fintech/SaaS environment.
- Strong proficiency with AWS services and security (IAM, KMS, Cloud Trail, S3, Guard Duty, SCPs, etc.).
- Solid understanding of Dev Sec Ops practices and integrating security into CI/CD workflows.
- Proficient in Terraform and other IaC tooling, capable of writing secure, reusable modules and enforcing guardrails.
- Proficient in Python, Bash, or Type Script – capable of scripting and building automation tools.
- Experience securing containers (Docker, ECS, EKS, or Kubernetes) and implementing hardened images.
- Expert level understanding of OWASP Top 10, secure coding, and software supply chain…
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).