Now hiring

Security Engineer @ Penneo

CopenhagenOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Is this you? <p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Imagine being the person who keeps trust running underneath every signature, every submission, every compliant transaction across Europe. That's this job. You'll work hands-on with our application stack and infrastructure, help build the security foundation for our platform, and be the person engineering teams call when something breaks.</span></p><br><p style="line-height:1.2;margin-top:0pt;margin-bottom:11.25pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">One day you're deep in a Terraform config chasing down a CVE. The next you're in a room with an external auditor, making sure our controls hold up. You'll fix vulnerabilities and shape the policies around them, in the same week. If that mix - real technical depth, real regulatory weight, real ownership - sounds like exactly the kind of problem you want to solve, keep reading.</span></p> About Penneo <p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">At Penneo, we build technology that helps businesses operate with trust in an increasingly complex world. What started as a digital signing solution in Copenhagen has grown into secure, compliant workflows used across Europe. With new forms of tech- and AI-driven fraud emerging fast, our mission to protect the integrity of digital business is more important than ever.</span></p><br><p style="line-height:1.2;margin-top:0pt;margin-bottom:11.25pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Penneo is a Certified Trusted Service Provider - we were the very first private company in Denmark to achieve this certification. That means we're not just another SaaS company. We operate critical digital trust infrastructure under the eIDAS regulation, building products that more than 3,500 companies across Europe rely on for identity, signatures, secure data handling, and compliance.</span></p> Your role & impact <span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Every signature, every submission, every compliant transaction on our platform rests on the security work you do. As our Security Engineer, you'll scale that effort - hands-on, close to the code, close to the infrastructure. Operating as a Qualified Trust Service Provider means our software is regulated and our customers hold us to a high bar. You're part of the reason we clear it.</span> What you'll be doing: <ul style="margin-top:0px;margin-bottom:0px;"><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Own vulnerability management across our infrastructure: track CVEs, keep systems patched and current, and make sure nothing regulated slips through.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Strengthen application security by working directly in the code and secure development practices, alongside the teams shipping it.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Structure and automate our security work - from evidence collection to reporting - so it scales with us instead of slowing us down.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Own and evolve our security guidelines using Visma tooling to stay ahead of risk across our infrastructure.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Drive the response when vulnerabilities or incidents happen - from triage through to fix.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Work closely with our principal engineers, tech leads, and platform team, and partner tightly with Compliance &amp; Legal on what it takes to stay a regulated, certified provider.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Document your work clearly. As a QTSP, our processes need to hold up to scrutiny - and so do yours.</span></p></li></ul> What makes you a great match? <p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">You've spent 2-5 years doing this job for real, not designing it on a whiteboard. You know CVEs, application security, and denial-of-service attacks the way most people know their own street. You hold the certifications to prove it. And you're just as comfortable fixing a vulnerability at 9am as you are explaining it to a non-technical stakeholder at 3pm. You are deeply familiar with DevSecOps practices, possessing hands-on experience with SAST, DAST, and dependency management across diverse package managers.</span></p><br><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">You're not an architect and you're not here to hand the hard problems to someone else. You're here to do the work.</span></p><ul style="margin-top:0px;margin-bottom:0px;"><li style="list-style-type:disc;font-size:11pt;font-family:Arial, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Equally comfortable on the technical and process sides of security - from fixing a vulnerability to documenting a control.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Arial, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Strong stakeholder and communication skills. You'll work with engineers, leadership, and external parties alike.</span></p></li><li style="list-style-type:disc;font-size:11pt;font-family:Arial, sans-serif;color:rgb(0,0,0);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;margin-left:-6pt;"><p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Able to work from our Copenhagen office around three days a week. Given the nature of the job, this isn't a fully remote role.</span></p></li></ul> What's in it for you? <p style="line-height:1.2;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">You'll build security infrastructure that 3,500+ companies across Europe depend on - not maintain legacy controls that nobody touches. You'll have real autonomy to shape how we approach vulnerability management, and automation. You'll work with principal engineers and technical leaders who actually ship things, not committees that oversee shipping.</span></p><p style="line-height:1.2;margin-top:12pt;margin-bottom:12pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Being a QTSP isn't compliance overhead - it means every control you build, every policy you write, actually has weight. You'll know your decisions matter, concretely. Thousands of businesses create signatures, identity data, and critical transactions through our platform. You'll be part of the reason they can trust it.</span></p> Don't wait to apply! <p style="line-height:1.2;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:11pt;font-family:Montserrat, sans-serif;color:rgb(4,34,76);background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">No application deadline - we hire, when we find the right match. </span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores