Pennylane

Pennylane

Pennylane offers an all-in-one financial management and accounting platform designed for business leaders and their accountants, enabling them to efficiently manage their finances and accounting in one place while focusing on their core business activi...

Diversified Financial Services
251-1K
Founded 2020
$97M raised

Description

  • Ensure the security of Pennylane’s application, infrastructure, dependencies, code, and configuration.
  • Work with the Product team to integrate security from feature design through delivery.
  • Review code from a secure development perspective across a high release volume.
  • Detect vulnerabilities, propose patches, and help strengthen CI/CD security controls.
  • Secure AWS infrastructure, including the Kubernetes environment, with the DevOps team.
  • Perform regular security assessments such as code reviews, pentests, and bug bounty-related analysis.
  • Strengthen detection of malicious activity and respond to security incidents by investigating logs, blocking attacks, and recommending corrective actions.
  • Support ISO 27001 compliance for development-related controls through training, audits, and non-conformity management.
  • Build and improve secure development training materials and deliver regular training to developers.
  • Promote security awareness across the company and contribute technical input to tenders.

Requirements

  • Experience performing offensive security assessments on applications and infrastructure.
  • Ability to exploit and fix a wide range of web vulnerabilities beyond the OWASP Top 10.
  • Experience with at least one programming language such as Ruby, Python, or JavaScript.
  • Experience with cloud infrastructure security.
  • Ability to explain technical security topics to non-technical audiences.
  • Fluency in French and/or English, both spoken and written.
  • Humble, proactive, organized, and able to work well in a remote, collaborative environment.
  • Quick learner who is comfortable working across application security, cloud security, training, and ISO 27001 topics.
  • English level is assessed and appreciated according to the department.
  • Experience with Ruby on Rails, ReactJS, AWS, and Kubernetes is relevant to the role.

Benefits

  • 25 paid vacation days.
  • Competitive compensation package.
  • Company shares/equity.
  • Home office budget plus a monthly coworking allowance.
  • Access to Gymlib with 8,000 fitness spaces and 300+ wellness activities across Europe.
  • Access to Busuu for English or French language learning.
  • Latest Apple equipment.
  • Remote work from your country of residence in Europe, within a maximum two-hour time difference from CET.
  • For France-based employees: French contract, 6 to 12 RTT, 5 weeks of PTO, Swile lunch credits, and Alan Blue healthcare coverage.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Product Certification Manager

PQShield 11-50 Semiconductors & Semiconductor Equipment

PQShield is hiring an Experienced Security Certification Manager/Engineer to lead certification efforts for its RISC-V and post-quantum cryptography security IP platform.

CI/CD GitLab CI HubSpot
1 week ago

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
1 week, 5 days ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
2 weeks ago

Senior Application Security Engineer

Counterpart Health 51-200 hospital & health care

Counterpart Health is hiring a Senior Application Security Engineer to secure its AI-enabled primary care platform, Counterpart Assistant, by finding and fixing vulnerabilities that affect clinicians during live patient visits.

Penetration Testing
2 weeks ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers