Information Security Manager (GRC Engineering) (m/f/d)

Pliant
Pliant

IT · Full-time

Helsinki, Finland

Posted on Jul 6, 2026

ABOUT US

Pliant is a modular B2B payments platform that combines commercial card issuing, payment accounts, FX, and spend management in one system — adapting to existing setups rather than requiring customers to replace them.

Businesses across industries such as travel, e-commerce, and insurance use Pliant to manage complex payment workflows with cards, backed by credit lines Pliant underwrites itself.

Fintechs and software platforms embed Pliant's payment infrastructure into their own products, from API-based Cards-as-a-Service to fully white-label solutions. Banks use Pliant's Card & Spend OS, the customer-facing interface, on their own infrastructure to run card programs.

Founded in 2020 and headquartered in Berlin, Pliant serves 5,000+ businesses and 40+ partners across Europe and the United States. A principal member of Visa and Mastercard, Pliant issues commercial cards in 13 currencies across 32 countries — under its own European e-money license and with licensed partners in the UK and US.

Learn more at www.getpliant.com

Learn more at www.getpliant.com

ABOUT THE ROLE

We are built AWS-native and audited against SOC 2, PCI DSS v4.0.1, HIPAA, and DORA. We run compliance like we run infrastructure: instrumented, automated, and owned by people who can read a log before they write a policy.

We're looking for an Information Security Manager (m/f/d) with a builder's mindset who happens to specialize in compliance, not a policy writer who happens to use a compliance tool. You'll own SOC 2, PCI DSS, HIPAA, and DORA end-to-end, and you'll do it by building automation, not by chasing screenshots.

They will report directly to the CISO in a growing team and be open to working with our team in our office in Helsinki (hybrid).


WHAT YOU`LL DO

  • Build automated evidence pipelines against AWS, IAM, and our security stack (AWS, Wiz, Vanta, SentinelOne, Datadog), control monitoring that runs itself, maturing security and compliance status.

  • Integrate compliance checks into CI/CD so drift gets caught before an auditor does.

  • Extend our compliance automation platform (Vanta) with custom integrations where the defaults don't cover our control set.

  • Own the security & compliance program (ISO 27001, SOC 2 Type 2, PCI DSS v4.0.1, HIPAA), audits, scoping, control testing, QSA/auditor relationships, risk register.

  • Turn regulatory requirements into engineering-consumable specs and tickets, and track them to closure.

  • Run vendor/third-party risk under DORA; support incident response from the compliance side.

WHAT YOU`LL BRING

  • 3+ years in security compliance, with real ownership of at least one full SOC 2 or PCI DSS audit cycle.

  • Experience of working with Tech and engineering teams

  • Working knowledge of at least two of: SOC 2, PCI DSS, HIPAA, DORA, applied to a real environment, not textbook.

  • Experience managing external auditors/QSAs through to a delivered report.

  • Excellent written communication, you'll write for engineers, auditors, and executives in the same week.

  • Comfortable owning ambiguity with a small team behind you, not a large one.

Nice to Have

  • Experience at a regulated fintech, EMI, PSP, or bank.

  • CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer.

  • Experience with LLM-based tooling for security/compliance workflows.

Why This Role

The foundations are already built. The mandate now is to make the next stage, GRC Engineering and real control automation. Direct access to the CISO, real autonomy, and a genuine say in security strategy.


WHAT WE OFFER

  • The opportunity to work in a growing team with big responsibilities that thrives on a strong exchange of knowledge and excellence

  • Attractive remuneration

  • Your choice of preferred OS, Windows or Mac

  • Flat hierarchy and transparent communication in a relaxed, professional atmosphere

  • Opportunity to develop your talent in a dynamic team with ambitious goals

  • Flexibility and possibility to work remotely

  • Company card with a monthly allowance for lunches, coffee, etc. with co-workers


Pliant is an equal opportunity employer. We welcome applications from people of all backgrounds, identities and abilities, and are committed to an inclusive hiring process. If you need any accommodations during the interview process, please let us know.

At Pliant we use the Ashby AI Criteria to assist with looking over resumes against our job qualifications for this role. All final decisions are made by our Talent Team and Hiring Team.

A human is behind these processes. Ashby does not automatically reject candidates or make final hiring decisions. Our teams review all results and make the final hiring decision with every candidate that applies.