Security Engineer *EU/UK remote* (m/f/d)

Other Jobs To Apply

<p style="min-height:1.5em"><strong>ABOUT US</strong></p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Pliant is a European fintech specializing in B2B payment solutions. Our modular, API-first platform helps businesses streamline spending, improve cash flow, and integrate payments into their financial workflows. Designed for industries with complex payment needs, such as travel and fleet, Pliant enables greater efficiency, control, and profitability.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">We serve two primary customer segments:</p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Companies looking to optimize operational processes through intuitive apps and APIs, gaining control, automation, and financial flexibility through extended credit lines.</p></li><li><p style="min-height:1.5em">Businesses such as financial software platforms, ERP providers, and banks that want to launch or enhance their credit card offerings using Pliant’s embedded finance and white-label solutions.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em">Founded in 2020 and headquartered in Berlin, Pliant supports over 4,000 businesses and more than 20 partners globally. As a licensed e-money institution (EMI), we issue credit cards in 11 currencies across more than 30 countries, helping companies streamline and simplify payments.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Learn more at<a target="_blank" rel="noopener noreferrer" href="http://www.getpliant.com/"><strong><br></strong></a><a target="_blank" rel="noopener noreferrer nofollow" href="http://www.getpliant.com"><strong>www.getpliant.com</strong></a></p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>About the Role</strong></p><p style="min-height:1.5em"></p><p style="min-height:1.5em">We’re looking for a hands-on <strong>Security Engineer </strong><em><strong>EU/UK remote</strong></em><strong> (m/f/d) </strong>with deep expertise in <strong>DevSecOps, cloud security (AWS), and automation</strong> to join our growing security team at Pliant. You'll play a critical role in designing and building secure foundations that scale. You will work closely with engineering, product, and infrastructure teams to embed security into our platform and developer workflows without slowing innovation.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">This role is ideal for someone who thrives in a fast-moving environment, owns problems end-to-end, and wants to build modern, automation-driven security at scale.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What You’ll Do</strong></p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Integrate security best practices throughout the SDLC to protect products, infrastructure, and customer data.</p></li><li><p style="min-height:1.5em">Design, implement, and maintain security automation tooling to address problems at scale (e.g., patch management, vulnerability management, compliance evidence collection).</p></li><li><p style="min-height:1.5em">Embed security controls and guardrails into the developer platform to enable secure and efficient delivery.</p></li><li><p style="min-height:1.5em">Define and promote “Paved Roads” - reusable, secure development standards and Terraform/Docker modules.</p></li><li><p style="min-height:1.5em">Harden containerized workloads (ECS and EKS) - ensure clusters follow security best practices for isolation, networking, and access control; Maintain secure, up-to-date base images; enforce image signing and provenance; implement admission control, least-privilege IAM roles, and runtime anomaly detection.</p></li><li><p style="min-height:1.5em">Deploy and manage cloud security platforms (e.g., Wiz) and drive remediation workflows.</p></li><li><p style="min-height:1.5em">Automate collection of audit-ready evidence for frameworks like PCI DSS, ISO 27001, SOC 2, and DORA.</p></li><li><p style="min-height:1.5em">Support vulnerability management (triage, SLAs, RCA) and lead incident response and post-mortems.</p></li><li><p style="min-height:1.5em">Conduct threat modeling, architecture reviews, and provide guidance on secure design and cryptography.</p></li><li><p style="min-height:1.5em">Build and maintain security documentation, internal tooling, and feedback loops to strengthen security culture.</p></li><li><p style="min-height:1.5em">Act as a security SME across application, cloud, and compliance domains.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What We’re Looking For</strong></p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">5+ years of experience in a technical security role, preferably in a cloud-native or fintech/SaaS environment.</p></li><li><p style="min-height:1.5em">Strong proficiency with AWS services and security (IAM, KMS, CloudTrail, S3, GuardDuty, SCPs, etc.).</p></li><li><p style="min-height:1.5em">Solid understanding of DevSecOps practices and integrating security into CI/CD workflows.</p></li><li><p style="min-height:1.5em">Proficient in Terraform and other IaC tooling, capable of writing secure, reusable modules and enforcing guardrails.</p></li><li><p style="min-height:1.5em">Proficient in Python, Bash, or TypeScript – capable of scripting and building automation tools.</p></li><li><p style="min-height:1.5em">Experience securing containers (Docker, ECS, EKS, or Kubernetes) and implementing hardened images.</p></li><li><p style="min-height:1.5em">Expert level understanding of OWASP Top 10, secure coding, and software supply chain risks.</p></li><li><p style="min-height:1.5em">Experience managing and integrating cloud security platforms (e.g., Wiz, Orca, Lacework, Prisma Cloud).</p></li><li><p style="min-height:1.5em">Understanding of vulnerability management and remediation workflows at scale.</p></li><li><p style="min-height:1.5em">Experience with application security practices, including code review, threat modeling, static and dynamic analysis (SAST, DAST), and attack surface analysis.</p></li><li><p style="min-height:1.5em">Experience performing Application Penetration Testing or Vulnerability Research / Bug Bounty Hunting. (Ability to discover and identify fixes for SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities)</p></li><li><p style="min-height:1.5em">Experience with threat modeling or security reviews.</p></li><li><p style="min-height:1.5em">Excellent communication skills and empathy, security is a complex topic that you have to be able to explain to audiences of various levels of previous exposure or learning.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Bonus Skills</strong></p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Exposure to compliance frameworks (PCI DSS, ISO 27001, SOC 2).</p></li><li><p style="min-height:1.5em">Familiarity with detection engineering or lightweight SIEM tooling.</p></li><li><p style="min-height:1.5em">Contributions to open-source security tools or internal security automation frameworks.<br></p></li></ul><p style="min-height:1.5em"><strong>What You’ll Bring</strong></p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">A builder’s mindset: you enjoy solving real-world security problems with automation.</p></li><li><p style="min-height:1.5em">A pragmatic approach to security: focused on reducing risk while enabling delivery.</p></li><li><p style="min-height:1.5em">Willingness to dive into unknowns, collaborate across teams, and take ownership.</p></li><li><p style="min-height:1.5em">Passion for clean, maintainable, and reusable code - even for security tools.<br></p></li></ul><p style="min-height:1.5em"><strong>WHAT WE OFFER</strong></p><p style="min-height:1.5em"></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence</p></li><li><p style="min-height:1.5em">Attractive remuneration</p></li><li><p style="min-height:1.5em">Your choice of preferred OS, Windows or Mac</p></li><li><p style="min-height:1.5em">Flat hierarchy and transparent communication in a relaxed, professional atmosphere</p></li><li><p style="min-height:1.5em">Opportunity to develop your talent in a dynamic team with ambitious goals</p></li><li><p style="min-height:1.5em">Flexibility and possibility to work remotely</p></li><li><p style="min-height:1.5em">Company card with a monthly allowance for lunches, coffee, etc. with co-workers</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em">At Pliant, we believe diversity and inclusion are essential to building not only an innovative product but also an exceptional experience for both our customers and our team. This commitment begins with our hiring process—we welcome individuals of all racial and ethnic backgrounds, religions, national origins, gender identities or expressions, sexual orientations, ages, marital statuses, and abilities. If you require accommodations or accessibility support during the interview process, please let us know in your application so we can make sure your experience is seamless.</p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...