Engineering Manager, Security
Startup
Full Time
Remote (within EU & UK)
ABOUT THE COMPANY
A fast-growing, VC-backed European fintech building B2B payment infrastructure — corporate cards, credit lines, and embedded finance tools — for companies with complex spend-management needs. The platform serves thousands of business customers and partner platforms across Europe, giving them API-first tooling and credit flexibility to run payments without friction. The team operates with a flat structure, ships fast, and is increasingly building its own AI-native tooling into day-to-day engineering work.
REQUIREMENTS
- Hands-on background in DevSecOps or cloud security, ideally having owned a cloud environment directly (identity and access management, key management, audit logging, service control policies)
- Strong Terraform skills, including writing secure, reusable modules from scratch
- Experience securing containerized workloads, including hardened base images and admission controls
- Scripting ability (Python, Bash, or TypeScript) to automate compliance and triage work rather than doing it by hand
- Working knowledge of PCI DSS, SOC 2, or similar frameworks, and experience running vulnerability management or incident response at a meaningful scale
- Experience managing engineers, or leading technical work people trusted before you had the title — including at least one hiring decision you learned from
- Ability to explain security risk clearly to a non-security audience
- A point of view on how AI is changing both the attacker's toolkit and how vulnerability response needs to adapt
- Comfort with AI-assisted development tools, and the same rigor reviewing AI-generated code as any other
ROLE & RESPONSIBILITIES
- Set the security foundations engineering builds on — secure-by-default infrastructure-as-code modules, hardened container images, and guardrails baked into the developer platform rather than bolted on later
- Keep day-to-day cloud security posture tight: closing out findings from cloud security tooling, tuning identity and access management, key management, and audit logging as the company scales, and making sure alerts are ones people actually need to act on
- Automate the evidence-gathering behind compliance audits (PCI DSS, SOC 2, and equivalent frameworks) so audit season stops being a fire drill
- Run vulnerability management and incident response end to end — triage, SLAs, remediation, and post-mortems
- Build out the application security practice: threat modeling, architecture reviews, and secure coding guidance product teams actually use
- Bring AI-native tooling into vulnerability operations, red-teaming, and incident response as the threat landscape shifts
- Grow a small security team and set the technical bar for whoever joins next
PERKS
- Choose your own equipment: Mac or Windows, whichever helps you do your best work
- A flat, low-bureaucracy culture with direct access to leadership
- Competitive compensation
- Fully remote, flexible working setup
- Room to shape a growing function and grow your own skills alongside it
- A monthly credit on the company's own card product, plus team meals with colleagues
HOW TO APPLY
Send your CV (and portfolio/GitHub if relevant), current salary, notice period, location, working visa status + a few lines about your motivation to join the company to mathieu@undiscovered-talent.com. No cover letter needed.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.