SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Pliant is a European fintech specializing in B2B payment solutions, serving over 4,000 businesses globally as a licensed e-money institution. This is the first Engineering Manager role for a two-person security team, combining people leadership with hands-on technical contribution.
You will own security foundations across the engineering organization: designing secure-by-default Terraform and Docker modules, hardening container images for ECS and EKS workloads, and embedding guardrails into the developer platform. Day-to-day responsibilities include managing cloud security posture using tools like Wiz, tuning AWS services (IAM, KMS, CloudTrail, GuardDuty), and ensuring alert quality as the company scales.
Compliance automation is a key focus—you'll streamline evidence collection for PCI DSS, SOC 2, ISO 27001, and DORA to eliminate audit scrambles. You'll run vulnerability management and incident response end-to-end, including triage, SLAs, remediation, and post-mortems. Building an application security practice through threat modeling, architecture reviews, and secure coding guidance that product teams actually adopt is also critical.
The role includes exploring AI-native security tooling for vulnerability operations, red-teaming, and incident response. You'll grow the team by hiring a third security engineer, setting the technical bar for security at Pliant long-term.
Required background: hands-on DevSecOps or cloud security experience with real AWS ownership (IAM, KMS, CloudTrail, GuardDuty, SCPs). Proficiency in Terraform for writing secure, reusable modules. Experience securing containerized workloads (ECS, EKS, Kubernetes) with hardened images and admission controllers. Scripting ability in Python, Bash, or TypeScript for compliance automation. Working knowledge of PCI DSS, SOC 2, ISO 27001, plus vulnerability management or incident response leadership. Prior experience managing engineers or leading technical work where people trusted your judgment, including hiring decisions. Ability to communicate security risks clearly to non-technical audiences. Thoughtful perspective on AI as an attacker's tool and how vulnerability response must evolve. Comfort with AI-assisted development tools and rigorous code review practices.
First-year trajectory: months 1-3 focus on absorbing current operations and meeting stakeholders (Platform Core, SRE, product teams). Concurrent hiring for a third security engineer. By mid-year, a security roadmap beyond audit findings and team growth. By year-end, security posture measured in metrics with automated compliance evidence collection.