Senior Application Security Manager
Key details
- Compensation
- $70,000 - $105,000
Job Description
Salary: £70,000 - 105,000 per year
Requirements
- 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.
- A background as a senior security engineer who moved into management, with enough technical depth to remain credible and hands-on.
- A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.
- Demonstrated experience turning signal into prioritised action through risk-based triage.
- Experience using AI and automation to scale security coverage rather than relying only on headcount or process.
- The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.
- Comfort in a fast-moving, complex, ever-evolving environment, with a self-directed and proactive approach.
- Exposure to fintech compliance requirements is a strong advantage.
- Backgrounds we also look at include DevSecOps and platform security leads with real AppSec depth.
Responsibilities
- Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.
- Build a structured, risk-ranked approach to remediation so the organisation knows what to fix first and why.
- Establish clear, company-wide reporting on our vulnerability posture, giving leadership data-driven visibility.
- Set and deliver an AppSec roadmap, bringing delivery expectations and accountability to the team.
- Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.
- Multiply the teams impact through automation and AI so coverage scales faster than headcount.
- Grow and mentor engineers, coaching them toward staff-level capability and building their confidence.
- Support our compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.
- Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.
- Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.
- In your first 6 months, get hands-on with our application security landscape, stand up vulnerability reporting, build trust with engineering squads, and integrate into the Cybersecurity team.
- By 12 months, help establish a documented, repeatable security program with proactive threat monitoring, regulatory readiness for new markets, and a team that can scale.
Technologies
- AI
- DevSecOps
- Support
- Security
More
We at Pleo build spend solutions that make managing money seamless, empowering, and effective for finance teams and employees, with a vision to help businesses go beyond. We are a driven, progressive, and kind team of 850+ people from over 100 nationalities, supporting more than 40,000 customers. This Senior Application Security Manager role sits within our Cybersecurity team and reports to our VP of Fraud & Security, with close collaboration across DevSecOps, SecOps, Risk & Compliance, Privacy, and Legal. We offer remote, hybrid, or in-person working options in the listed locations, provided you are physically based in the country of your choice with a valid right to work, and we are unable to offer visa sponsorship for this role. Benefits include a Pleo card, lunch on work days, comprehensive private healthcare depending on location, 25-28 days of holiday plus public holidays, hybrid and fully remote options for our team, the option to purchase 5 additional days of holiday, free mental health and well-being support through MyndUp, and paid parental leave.
last updated 35 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 7 indexed roles at this employer: $70,000 - $105,000(mid ~87500)
Context reflects data collected at crawl time.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs, or every remote job category.
Senior Application Security Manager
Analytics Engineer
Analytics Engineer
Source: DevITJobs • Last updated 1w ago