> Markdown version of [/jobs/ext/2731070-security-engineer-eu-uk-remote](https://www.wearedevelopers.com/jobs/ext/2731070-security-engineer-eu-uk-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer EU/UK remote - **Company:** Pliant - **Location:** Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Amazon S3, Software System Penetration Testing, Bash Shell, Software as a Service, Cloud Computing Security, Cloud Engineering, Code Review, Continuous Integration, Cross-Site Request Forgery, Customer Data Management, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Open Source Technology, Open Web Application Security, PCI Data Security Standards, Program Analysis, Systems Development Life Cycle, Secure Coding, Security Information and Event Management, SQL Injection, Systems Integration, TypeScript, Software Vulnerability Management, Web Applications, Scripting, Software Security, Cross-Site Scripting (XSS), Containerization, Kubernetes, Patch Management, Terraform, Prisma Cloud Platform, Devsecops, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/security-engineer-eu-uk-remote-m-f-d-pliant-8347039 ## About the Role * 5+ years of experience in a technical security role, preferably in a cloud-native or fintech/SaaS environment. * Strong proficiency with AWS services and security (IAM, KMS, CloudTrail, S3, GuardDuty, SCPs, etc.). * Solid understanding of DevSecOps practices and integrating security into CI/CD workflows. * Proficient in Terraform and other IaC tooling, capable of writing secure, reusable modules and enforcing guardrails. * Proficient in Python, Bash, or TypeScript - capable of scripting and building automation tools. * Experience securing containers (Docker, ECS, EKS, or Kubernetes) and implementing hardened images. * Expert level understanding of OWASP Top 10, secure coding, and software supply chain risks. * Experience managing and integrating cloud security platforms (e.g., Wiz, Orca, Lacework, Prisma Cloud). * Understanding of vulnerability management and remediation workflows at scale. * Experience with application security practices, including code review, threat modeling, static and dynamic analysis (SAST, DAST), and attack surface analysis. * Experience performing Application Penetration Testing or Vulnerability Research / Bug Bounty Hunting. (Ability to discover and identify fixes for SQLi, XSS, CSRF, SSRF, authentication and authorization flaws, and other web-based security vulnerabilities) * Experience with threat modeling or security reviews. * Excellent communication skills and empathy, security is a complex topic that you have to be able to explain to audiences of various levels of previous exposure or learning. Bonus Skills * Exposure to compliance frameworks (PCI DSS, ISO 27001, SOC 2). * Familiarity with detection engineering or lightweight SIEM tooling. * Contributions to open-source security tools or internal security automation frameworks. What You'll Bring * A builder's mindset: you enjoy solving real-world security problems with automation. * A pragmatic approach to security: focused on reducing risk while enabling delivery. * Willingness to dive into unknowns, collaborate across teams, and take ownership. * Passion for clean, maintainable, and reusable code - even for security tools. ## Description We're looking for a hands-on Security Engineer EU/UK remote (m/f/d) with deep expertise in DevSecOps, cloud security (AWS), and automation to join our growing security team at Pliant. You'll play a critical role in designing and building secure foundations that scale. You will work closely with engineering, product, and infrastructure teams to embed security into our platform and developer workflows without slowing innovation. This role is ideal for someone who thrives in a fast-moving environment, owns problems end-to-end, and wants to build modern, automation-driven security at scale. What You'll Do * Integrate security best practices throughout the SDLC to protect products, infrastructure, and customer data. * Design, implement, and maintain security automation tooling to address problems at scale (e.g., patch management, vulnerability management, compliance evidence collection). * Embed security controls and guardrails into the developer platform to enable secure and efficient delivery. * Define and promote "Paved Roads" - reusable, secure development standards and Terraform/Docker modules. * Harden containerized workloads (ECS and EKS) - ensure clusters follow security best practices for isolation, networking, and access control; Maintain secure, up-to-date base images; enforce image signing and provenance; implement admission control, least-privilege IAM roles, and runtime anomaly detection. * Deploy and manage cloud security platforms (e.g., Wiz) and drive remediation workflows. * Automate collection of audit-ready evidence for frameworks like PCI DSS, ISO 27001, SOC 2, and DORA. * Support vulnerability management (triage, SLAs, RCA) and lead incident response and post-mortems. * Conduct threat modeling, architecture reviews, and provide guidance on secure design and cryptography. * Build and maintain security documentation, internal tooling, and feedback loops to strengthen security culture. * Act as a security SME across application, cloud, and compliance domains. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)