Pennylane

Pennylane

Pennylane offers an all-in-one financial management and accounting platform designed for business leaders and their accountants, enabling them to efficiently manage their finances and accounting in one place while focusing on their core business activi...

Diversified Financial Services
251-1K
Founded 2020
$97M raised

Description

  • Ensure the security of Pennylane’s application, infrastructure, dependencies, code, and configuration.
  • Work with the Product team to integrate security from feature design through delivery.
  • Review code from a secure development perspective across a high release volume.
  • Detect vulnerabilities, propose patches, and help strengthen CI/CD security controls.
  • Secure AWS infrastructure, including the Kubernetes environment, with the DevOps team.
  • Perform regular security assessments such as code reviews, pentests, and bug bounty-related analysis.
  • Strengthen detection of malicious activity and respond to security incidents by investigating logs, blocking attacks, and recommending corrective actions.
  • Support ISO 27001 compliance for development-related controls through training, audits, and non-conformity management.
  • Build and improve secure development training materials and deliver regular training to developers.
  • Promote security awareness across the company and contribute technical input to tenders.

Requirements

  • Experience performing offensive security assessments on applications and infrastructure.
  • Ability to exploit and fix a wide range of web vulnerabilities beyond the OWASP Top 10.
  • Experience with at least one programming language such as Ruby, Python, or JavaScript.
  • Experience with cloud infrastructure security.
  • Ability to explain technical security topics to non-technical audiences.
  • Fluency in French and/or English, both spoken and written.
  • Humble, proactive, organized, and able to work well in a remote, collaborative environment.
  • Quick learner who is comfortable working across application security, cloud security, training, and ISO 27001 topics.
  • English level is assessed and appreciated according to the department.
  • Experience with Ruby on Rails, ReactJS, AWS, and Kubernetes is relevant to the role.

Benefits

  • 25 paid vacation days.
  • Competitive compensation package.
  • Company shares/equity.
  • Home office budget plus a monthly coworking allowance.
  • Access to Gymlib with 8,000 fitness spaces and 300+ wellness activities across Europe.
  • Access to Busuu for English or French language learning.
  • Latest Apple equipment.
  • Remote work from your country of residence in Europe, within a maximum two-hour time difference from CET.
  • For France-based employees: French contract, 6 to 12 RTT, 5 weeks of PTO, Swile lunch credits, and Alan Blue healthcare coverage.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Modern Health 251-1K Health Care Providers & Services

Modern Health is hiring a remote Product Security Engineer to strengthen security and compliance across its mental health platform, applications, cloud infrastructure, and software development lifecycle.

Agile AWS Bash CI/CD Cybersecurity Datadog Django Flask GitLab HashiCorp Vault Packer Penetration Testing PostgreSQL Python Redis Terraform
1 day, 21 hours ago

Application Security Engineer - Senior

Banco Plata, S.A., Institución de Banca Múltiple. 1001-5000 Banking / financial services

Plata is seeking an Application Security Engineer to join its Information Security team and embed security controls, testing, and practices throughout the software development lifecycle.

Burp Suite CI/CD Kubernetes Microservices OWASP Penetration Testing
3 days, 21 hours ago

Senior Product Security Engineer

payabl. 51-250 Diversified Financial Services

Payabl is seeking a Senior Product Security Engineer to establish and embed product security across its payments engineering organization, integrating secure practices throughout the software development lifecycle.

AWS CI/CD Penetration Testing
3 days, 21 hours ago

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
5 days, 20 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers