> Markdown version of [/jobs/ext/2394911-engineering-manager-security-eu-uk-remote](https://www.wearedevelopers.com/jobs/ext/2394911-engineering-manager-security-eu-uk-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineering Manager, Security *EU/UK remote* - **Company:** Pliant - **Location:** Germany (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Bash Shell, Cloud Computing Security, Identity and Access Management, Python (Programming Language), PCI Data Security Standards, Secure Coding, TypeScript, Software Vulnerability Management, Scripting, Software Security, Kubernetes, Terraform, Devsecops, Docker - **Published:** August 3, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=7233e7e4206a78ac ## About the Role * Hands-on background in DevSecOps or cloud security, ideally with real ownership of an AWS environment. IAM, KMS, CloudTrail, GuardDuty, and SCPs are things you have worked with directly. * Proficiency in Terraform, including the ability to write secure, reusable modules from scratch. * Experience securing containerized workloads (ECS, EKS, or Kubernetes), including hardened base images and admission controllers. * Scripting ability in Python, Bash, or TypeScript sufficient to automate compliance checks and triage workflows rather than doing them by hand each quarter. * Working knowledge of PCI DSS, SOC 2, and/or ISO 27001, plus experience running vulnerability management at scale or leading incident response for something that mattered. * Experience managing engineers or leading technical work where people trusted your calls before you had the title, including at least one hiring decision worth learning from. * Ability to explain a security risk clearly to non-security audiences without losing accuracy. * A point of view on AI as an attacker's tool and how vulnerability response needs to change as discovery-to-exploitation windows keep shrinking. * Comfort with AI-assisted development tools, and the same rigour reviewing AI-generated PRs as any other. ## Description Pliant builds corporate payment infrastructure, and the security team's job is to keep that infrastructure secure and compliant without slowing down the engineers building on it. This is the first Engineering Manager role for a team of two security engineers already covering DevSecOps, cloud security, and compliance today. You'll take over the people side while shaping where the function goes next, staying technical enough to drive lower-priority initiatives yourself, participate in reviews, and step in during incidents when the team needs you., * Own the security foundations the rest of engineering builds on: secure-by-default Terraform and Docker modules, hardened images for ECS and EKS workloads, and guardrails built into the developer platform rather than added afterwards. * Drive cloud security posture day to day: remediating findings from Wiz, keeping IAM, KMS, CloudTrail, and GuardDuty tuned as Pliant scales, and ensuring the alerts that fire are ones people should actually act on. * Automate compliance evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA so audits stop being a scramble. * Run vulnerability management and incident response end to end: triage, SLAs, remediation, and post-mortems. * Build the application security practice through threat modeling, architecture reviews, and secure coding guidance that product teams actually use. * Use and build AI-native security tooling for VulnOps, red-teaming, and incident response as the threat landscape evolves. * Grow the team: two engineers are in place today, and who you hire next sets the technical bar for security at Pliant for a long time. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)