Back to Jobs
Pliant
Development Just now

Engineering Manager - Security

Pliant
United StatesUnited States
Full-time
Not Disclosed
Lead/Manager

Job Description

Key Skills Required

Master these to land this role

BackendBestseller 🔥
Learn in 18 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
PythonBestseller 🔥
Learn in 56 Hours
AWSCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

Pliant builds corporate payment infrastructure, and the security team's job is to keep that infrastructure secure and compliant without slowing down the engineers building on it. This is the first Engineering Manager role for a team of two security engineers already covering DevSecOps, cloud security, and compliance today. You'll take over the people side while shaping where the function goes next, staying technical enough to drive lower-priority initiatives yourself, participate in reviews, and step in during incidents when the team needs you.

What You'll Do

  • Own the security foundations the rest of engineering builds on: secure-by-default Terraform and Docker modules, hardened images for ECS and EKS workloads, and guardrails built into the developer platform rather than added afterwards.

  • Drive cloud security posture day to day: remediating findings from Wiz, keeping IAM, KMS, CloudTrail, and GuardDuty tuned as Pliant scales, and ensuring the alerts that fire are ones people should actually act on.

  • Automate compliance evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA so audits stop being a scramble.

  • Run vulnerability management and incident response end to end: triage, SLAs, remediation, and post-mortems.

  • Build the application security practice through threat modeling, architecture reviews, and secure coding guidance that product teams actually use.

  • Use and build AI-native security tooling for VulnOps, red-teaming, and incident response as the threat landscape evolves.

  • Grow the team: two engineers are in place today, and who you hire next sets the technical bar for security at Pliant for a long time.

What You'll Bring

  • Hands-on background in DevSecOps or cloud security, ideally with real ownership of an AWS environment. IAM, KMS, CloudTrail, GuardDuty, and SCPs are things you have worked with directly.

  • Proficiency in Terraform, including the ability to write secure, reusable modules from scratch.

  • Experience securing containerized workloads (ECS, EKS, or Kubernetes), including hardened base images and admission controllers.

  • Scripting ability in Python, Bash, or TypeScript sufficient to automate compliance checks and triage workflows rather than doing them by hand each quarter.

  • Working knowledge of PCI DSS, SOC 2, and/or ISO 27001, plus experience running vulnerability management at scale or leading incident response for something that mattered.

  • Experience managing engineers or leading technical work where people trusted your calls before you had the title, including at least one hiring decision worth learning from.

  • Ability to explain a security risk clearly to non-security audiences without losing accuracy.

  • A point of view on AI as an attacker's tool and how vulnerability response needs to change as discovery-to-exploitation windows keep shrinking.

  • Comfort with AI-assisted development tools, and the same rigour reviewing AI-generated PRs as any other.

The First Year

The first few months are mostly absorbing what is already running and meeting the people who depend on it: Platform Core, SRE, and the product teams who will come to you when something looks like a security question. You will also be hiring, as Pliant is looking for a third Security Engineer to onboard on the team. By mid-year, you have a security roadmap that is not just a backlog of audit findings, and the team has grown past its current two engineers. By year one, the security posture is something you can describe in metrics rather than vibes, and compliance evidence for the next audit is being collected automatically rather than assembled by hand the week before.

Stack

Terraform, Spacelift, AWS (including a dedicated PCI-scoped account), Datadog, Wiz. We're mid-migration from ECS to Kubernetes, so container security work spans both.

How would you rate this job post?

See what other professionals think about this role.

banner

Pliant is a high-growth fintech platform and corporate card management infrastructure provider engineered to streamline enterprise payment workflows, B2B procurement, and expense automation across global markets. Founded in Berlin in 2020, the company eliminates the rigid credit caps, sluggish approval cycles, and fragmented receipt reconciliation of legacy commercial banking by offering bank-independent Visa corporate credit cards with high spending limits, automated receipt collection, and real-time spend analytics. Moving beyond simple virtual card generators, Pliant equips mid-market enterprises and scale-ups with a modular financial operating system that includes white-label Card-as-a-Service (CaaS) capabilities, Pro APIs, and multi-currency business accounts. Under the hood, its enterprise architecture—bolstered by native ERP and accounting integrations (DATEV, NetSuite, Dynamics 365, Lexware), 3D Secure verification, and automated PSD2/PCI-DSS compliance pipelines—natively handles high-volume transaction processing, custom card issuance flows, and dynamic spend control rules. What sets Pliant apart is its dual delivery model; by offering both turnkey mobile spend apps for end-users and embedded API rails for developers, the platform enables organizations to optimize cash flow, unlock substantial transaction cashback, and automate back-office bookkeeping with elite precision.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Engineering Manager - Security at Pliant