JobLarper
JobLarperCompaniesPliant › Information Security Manager (GRC Engineering) (m/f/d)

Information Security Manager (GRC Engineering) (m/f/d)

Pliant — Tracked from its ashby job board

Helsinki, Finland (Hybrid) Remote Manager Posted Jul 6, 2026
REST/APIsCloudAI/LLM

About the role

ABOUT US

Pliant is a European fintech specializing in B2B payment solutions. Our modular, API-first platform helps businesses streamline spending, improve cash flow, and integrate payments into their financial workflows. Designed for industries with complex payment needs, such as travel and fleet, Pliant enables greater efficiency, control, and profitability.

We serve two primary customer segments:

- Companies looking to optimize operational processes through intuitive apps and APIs, gaining control, automation, and financial flexibility through extended credit lines.

- Businesses such as financial software platforms, ERP providers, and banks that want to launch or enhance their credit card offerings using Pliant’s embedded finance and white-label solutions.

Founded in 2020 and headquartered in Berlin, Pliant supports over 4,000 businesses and more than 20 partners globally. As a licensed e-money institution (EMI), we issue credit cards in 11 currencies across more than 30 countries, helping companies streamline and simplify payments.

Learn more at www.getpliant.com http://www.getpliant.com

ABOUT THE ROLE

We are built AWS-native and audited against SOC 2, PCI DSS v4.0.1, HIPAA, and DORA. We run compliance like we run infrastructure: instrumented, automated, and owned by people who can read a log before they write a policy.

We're looking for an Information Security Manager (m/f/d) with a builder's mindset who happens to specialize in compliance, not a policy writer who happens to use a compliance tool. You'll own SOC 2, PCI DSS, HIPAA, and DORA end-to-end, and you'll do it by building automation, not by chasing screenshots.

They will report directly to the CISO in a growing team and be open to working with our team in our office in Helsinki (hybrid).

WHAT YOU`LL DO

- Build automated evidence pipelines against AWS, IAM, and our security stack (AWS, Wiz, Vanta, SentinelOne, Datadog), control monitoring that runs itself, maturing security and compliance status.

- Integrate compliance checks into CI/CD so drift gets caught before an auditor does.

- Extend our compliance automation platform (Vanta) with custom integrations where the defaults don't cover our control set.

- Own the security & compliance program (ISO 27001, SOC 2 Type 2, PCI DSS v4.0.1, HIPAA), audits, scoping, control testing, QSA/auditor relationships, risk register.

- Turn regulatory requirements into engineering-consumable specs and tickets, and track them to closure.

- Run vendor/third-party risk under DORA; support incident response from the compliance side.

WHAT YOU`LL BRING

- 3+ years in security compliance, with real ownership of at least one full SOC 2 or PCI DSS audit cycle.

- Experience of working with Tech and engineering teams

- Working knowledge of at least two of: SOC 2, PCI DSS, HIPAA, DORA, applied to a real environment, not textbook.

- Experience managing external auditors/QSAs through to a delivered report.

- Excellent written communication, you'll write for engineers, auditors, and executives in the same week.

- Comfortable owning ambiguity with a small team behind you, not a large one.

Nice to Have

- Experience at a regulated fintech, EMI, PSP, or bank.

- CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer.

- Experience with LLM-based tooling for security/compliance workflows.

Why This Role

The foundations are already built. The mandate now is to make the next stage, GRC Engineering and real control automation. Direct access to the CISO, real autonomy, and a genuine say in security strategy.

WHAT WE OFFER

- The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence

- Attractive remuneration

- Your choice of preferred OS, Windows or Mac

- Flat hierarchy and transparent communication in a relaxed, professional atmosphere

- Opportunity to develop your talent in a dynamic team with ambitious goals

- Flexibility and possibility to work remotely

- Company card with a monthly allowance for lunches, coffee, etc. with co-workers

Pliant is an equal opportunity employer. We welcome applications from people of all backgrounds, identities and abilities, and are committed to an inclusive hiring process. If you need any accommodations during the interview process, please let us know.

What the index says about this role

  • First seen by JobLarper — Aug 2, 2026, 6 days ago. Older postings collect hundreds of applicants — a tailored résumé matters more the longer a role has been live.
  • No pay range in our index for this listing. Across 20 indexed Software Engineer roles in EMEA that do publish one, the middle half sits between $175k and $330k, median $309k — JobLarper's read of the market, not a figure from Pliant.
  • What Software Engineer roles ask for — across 10,230 indexed openings: REST/APIs (46%), Backend (42%), Cloud (38%), Python (38%), Go (25%). This posting names REST/APIs, Cloud, AI/LLM.
  • Pliant is hiring actively — 16 open roles indexed.

Derived from the 27,000 roles JobLarper indexes daily from official company boards — not from the job description above.

⚡ JobLarper watched this role appear on Pliant's official board on Jul 6, 2026. Sign up free to get alerted minutes after roles like this go live, and tailor your real résumé to the exact description — nothing invented.

More open roles at Pliant

All 16 open roles at Pliant →

Similar Software Engineer roles at other companies