Security Engineer
Penneo A/S
Imagine being the person who keeps trust running underneath every signature, every submission, every compliant transaction across Europe. That's this job. You'll work hands-on with our application stack and infrastructure, help build the security foundation for our platform, and be the person engineering teams call when something breaks.
One day you're deep in a Terraform config chasing down a CVE. The next you're in a room with an external auditor, making sure our controls hold up. You'll fix vulnerabilities and shape the policies around them, in the same week. If that mix - real technical depth, real regulatory weight, real ownership - sounds like exactly the kind of problem you want to solve, keep reading.
About Penneo
At Penneo, we build technology that helps businesses operate with trust in an increasingly complex world. What started as a digital signing solution in Copenhagen has grown into secure, compliant workflows used across Europe. With new forms of tech- and AI-driven fraud emerging fast, our mission to protect the integrity of digital business is more important than ever.
Penneo is a Certified Trusted Service Provider - we were the very first private company in Denmark to achieve this certification. That means we're not just another SaaS company. We operate critical digital trust infrastructure under the eIDAS regulation, building products that more than 3,500 companies across Europe rely on for identity, signatures, secure data handling, and compliance.
Your role & impact
Every signature, every submission, every compliant transaction on our platform rests on the security work you do. As our Security Engineer, you'll scale that effort - hands-on, close to the code, close to the infrastructure. Operating as a Qualified Trust Service Provider means our software is regulated and our customers hold us to a high bar. You're part of the reason we clear it.
What you'll be doing:
- Own vulnerability management across our infrastructure: track CVEs, keep systems patched and current, and make sure nothing regulated slips through.
- Strengthen application security by working directly in the code and secure development practices, alongside the teams shipping it.
- Structure and automate our security work - from evidence collection to reporting - so it scales with us instead of slowing us down.
- Own and evolve our security guidelines using Visma tooling to stay ahead of risk across our infrastructure.
- Drive the response when vulnerabilities or incidents happen - from triage through to fix.
- Work closely with our principal engineers, tech leads, and platform team, and partner tightly with Compliance & Legal on what it takes to stay a regulated, certified provider.
- Document your work clearly. As a QTSP, our processes need to hold up to scrutiny - and so do yours.
You've spent 2-5 years doing this job for real, not designing it on a whiteboard. You know CVEs, application security, and denial-of-service attacks the way most people know their own street. You hold the certifications to prove it. And you're just as comfortable fixing a vulnerability at 9am as you are explaining it to a non-technical stakeholder at 3pm. You are deeply familiar with DevSecOps practices, possessing hands-on experience with SAST, DAST, and dependency management across diverse package managers.
You're not an architect and you're not here to hand the hard problems to someone else. You're here to do the work.
- Equally comfortable on the technical and process sides of security - from fixing a vulnerability to documenting a control.
- Strong stakeholder and communication skills. You'll work with engineers, leadership, and external parties alike.
- Able to work from our Copenhagen office around three days a week. Given the nature of the job, this isn't a fully remote role.
You'll build security infrastructure that 3,500+ companies across Europe depend on - not maintain legacy controls that nobody touches. You'll have real autonomy to shape how we approach vulnerability management, and automation. You'll work with principal engineers and technical leaders who actually ship things, not committees that oversee shipping.
Being a QTSP isn't compliance overhead - it means every control you build, every policy you write, actually has weight. You'll know your decisions matter, concretely. Thousands of businesses create signatures, identity data, and critical transactions through our platform. You'll be part of the reason they can trust it.
Don't wait to apply!
No application deadline - we hire, when we find the right match.
About Us
Penneo is founded and headquartered in Copenhagen. We offer a digital signing solution that helps businesses in Denmark, Norway, and Belgium get documents signed without the fuss - and with full legal compliance.
We are a team of 80+ passionate people, from 20+ countries, with a clear vision: to create a world where we can trust the way businesses do business.
Penneo is an equal-opportunity employer. All aspects of employment, hiring, and promotion are based on merit and business needs. We do not discriminate based on race, color, religion, marital status, age, national origin, physical or mental disability, medical condition, pregnancy, gender, sexual orientation, gender identity, or expression.
Please be aware that if hired, as part of our Background check, we require a copy of your criminal record. We do that to ensure that we remain a trusted service provider and partner as well as to comply with relevant compliance requirements such as ISO27001.