Engineering Manager, Security *EU/UK remote*(m/f/d)
Uses AI-native security tooling and expects familiarity with AI-assisted development and reviewing AI-generated PRs.
About the Role
Engineering Manager, Security to lead and grow a small security team for a European fintech platform, owning cloud and application security, vulnerability management, incident response, and compliance automation. Remote role for EU/UK candidates focused on hands-on technical leadership, hiring, and building security foundations across Terraform, container platforms, and AWS.
Job Description
Role
Pliant is hiring its first Engineering Manager for Security to take ownership of the people side and technical direction of a two-person security team. The manager will be hands-on enough to drive initiatives, participate in reviews, and lead incident response while hiring and scaling the security function.
Key Responsibilities
- Own security foundations used across engineering: secure-by-default Terraform and Docker modules, hardened images for ECS/EKS, and developer platform guardrails.
- Drive cloud security posture: remediate findings from Wiz and maintain IAM, KMS, CloudTrail, GuardDuty, and SCPs as the platform scales.
- Automate compliance evidence collection for standards like PCI DSS, SOC 2, ISO 27001, and DORA.
- Run vulnerability management and incident response end-to-end: triage, SLAs, remediation, and post-mortems.
- Build application security practice: threat modeling, architecture reviews, and secure coding guidance for product teams.
- Use and build AI-native security tooling for VulnOps, red-teaming, and incident response.
- Grow the team by hiring additional security engineers and setting the long-term technical bar.
Requirements
- Hands-on background in DevSecOps or cloud security with ownership of an AWS environment.
- Direct experience with IAM, KMS, CloudTrail, GuardDuty, and SCPs.
- Proficiency with Terraform and building secure, reusable modules.
- Experience securing containerized workloads (ECS, EKS, or Kubernetes), including hardened base images and admission controllers.
- Scripting ability in Python, Bash, or TypeScript to automate compliance checks and triage workflows.
- Working knowledge of PCI DSS, SOC 2, and/or ISO 27001, and experience running vulnerability management or incident response at scale.
- Experience managing engineers or leading technical work and making hiring decisions.
- Ability to explain security risks clearly to non-security audiences.
- A point of view on AI as an attacker tool and comfort with AI-assisted development tools and reviewing AI-generated PRs.
First Year Expectations
- Initial months: absorb current operations, meet stakeholders (Platform Core, SRE, product teams), and hire a third Security Engineer.
- By mid-year: deliver a security roadmap beyond audit-driven tasks and grow the team.
- By year one: report security posture with measurable metrics and automate compliance evidence collection.
Tech Stack
Terraform, Spacelift, AWS (including a PCI-scoped account), Datadog, Wiz, Docker, ECS, EKS, Kubernetes.
Benefits (selected)
- Flexible remote work (EU/UK remote)
- Attractive remuneration
- Choice of preferred OS (Windows or Mac)
- Monthly Pliant Card credit for product use and colleague meals
- Flat hierarchy, transparent communication, and professional development opportunities