Senior Application Security Manager

DaParrot Ltd

Deutschland

Hybrid

EUR 110.000 - 150.000

Vollzeit

Vor 3 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Pleo card
Lunch allowance
Private healthcare
Holiday allowance
Hybrid/Remote options
Extra holiday via salary sacrifice
Mental health support
Paid parental leave

Zusammenfassung

Pleo is seeking a Senior Application Security Manager to lead vulnerability management and define the long-term AppSec strategy within our Cybersecurity team. You will turn signals into a prioritized risk plan for engineering with a player-coach mindset.

You’ll mentor engineers, scale security through automation and AI, and collaborate with DevSecOps, SecOps, Risk & Compliance, Privacy and Legal to protect customers and comply with ISO27001, PCI-DSS and GDPR.

Qualifikationen

  • 10+ years of experience steering application security in a compliance-heavy environment.
  • Background as a senior security engineer who moved into management while remaining credible technically.
  • Track record mentoring engineers and driving accountability without micromanagement.
  • Experience turning signal into prioritised action through risk-based triage.
  • Experience using AI and automation to scale security coverage.
  • Ability to shape culture beyond your own team and influence engineering squads.

Aufgaben

  • Own vulnerability management end to end, including reporting, triage, mitigation and long-term strategy.
  • Build a structured, risk-ranked remediation approach to inform what to fix first.
  • Establish clear, company-wide reporting on our vulnerability posture for leadership visibility.
  • Set and deliver an AppSec roadmap with delivery expectations and accountability.
  • Partner with engineering squads as customers, embedding proactive security processes.
  • Multiply team impact through automation and AI to scale coverage.
  • Grow and mentor engineers toward staff-level capability.
  • Support Pleo's compliance obligations across ISO27001, PCI-DSS, GDPR.
  • Reduce attack surface through technical controls, policy and AI enablement.
  • Contribute to the broader Cybersecurity team and KPI planning for 2027.
  • Understand attack surface across payments and multi-region infra; form risk view.
  • Document a repeatable security program with proactive threat monitoring.

Kenntnisse

Security leadership
AppSec strategy
Mentor engineers
Risk-based triage
Automation & AI in security
Influence without authority

Jobbeschreibung

About Pleo

Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses 'go beyond'.

The word 'Pleo' actually means 'more than you'd expect', and living by that mantra has been the secret to our success over the last 10 years.

Now, we're at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can't say we've got this whole thing figured out. And frankly, that's half the fun! What we can say is that we're a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.

About the role

We're looking for a Senior Application Security Manager to join our Cybersecurity team at Pleo. In this role, you'll own vulnerability management and set the long-term application security strategy, turning a growing stream of signal into a risk-ranked plan the engineering organisation can actually act on. If you're a player-coach who wants high leverage with low bureaucracy, and you'd rather mature a program than maintain one, then this is the opportunity for you!

Who you'll be working with and reporting to

You'll report to our VP of Fraud & Security and lead a small AppSec team with dotted lines to other security members. Your primary customers are Pleo's engineering squads, and your closest partners are DevSecOps, who feed you signal and automation, alongside SecOps, Risk & Compliance, Privacy, and Legal. Our team is highly collaborative and dedicated to keeping Pleo and its customers safe. You'll also have the chance to shape how the wider organisation thinks about security, well beyond your own team.

What you'll be doing
  • Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.
  • Build a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.
  • Establish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.
  • Set and deliver an AppSec roadmap, bringing delivery expectations and accountability to a team that hasn't had them.
  • Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.
  • Multiply your team's impact through automation and AI, so coverage scales faster than headcount.
  • Grow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.
  • Support Pleo's compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.
  • Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.
  • Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.
What you bring
  • 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.
  • A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands-on.
  • A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.
  • Demonstrated experience turning signal into prioritised action through risk-based triage.
  • Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process.
  • The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.
  • Comfort in a fast-moving, complex, ever-evolving environment, where you're self-directed and proactive.
  • Exposure to fintech compliance requirements is a strong advantage. Backgrounds we also look at include DevSecOps and platform security leads with real AppSec depth.
Why is this role a good fit for you
  • You want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.
  • You treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.
  • You like being a player-coach, staying close to the technical work while growing the people around you.
  • You're motivated by high leverage and low bureaucracy, and you'd rather build the system than personally do every task.
This role is not a good fit for you
  • You're looking to step away from technical work entirely at this level.
  • You prefer to lead through mandate and process rather than partnership and example.
  • You're sceptical of automation, AI, or of leaning on signal from partner teams.
How you'll develop in this role
  • Get hands-on with Pleo's application security landscape, understanding our attack surface across payment systems and multi-region infrastructure, and forming your own view of where the real risk sits.
  • Stand up clear vulnerability reporting and a risk-ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.
  • Build trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.
  • Integrate into the Cybersecurity team, connecting with DevSecOps, SecOps, and Risk & Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.
  • By 12 months, the goal is a documented, repeatable security program with proactive threat monitoring in place, regulatory readiness for new markets, and a team that can scale.

We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into broader leadership, or acquiring new skills.

The location

Please note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.

Show me the benefits!
  • Your own Pleo card (no more out-of-pocket spending!)
  • Lunch is on us for your work days – enjoy catered meals or receive a lunch allowance based on your local office
  • Comprehensive private healthcare – depending on your location, coverage options include Vitality, Alan or Médis
  • We offer 25-28 days of holiday (depending on your location) + public holidays
  • For our Team, we offer both hybrid and fully remote working options
  • Option to purchase 5 additional days of holiday through a salary sacrifice
  • We use MyndUp to give our employees access to free mental health and well-being support with great success so far
  • Paid parental leave – we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Engineering Manager - Employee Spend
Engineering Manager - Employee Spend

Pleo • Deutschland

Hybrid
EUR 120.000 - 180.000
Pleo card
Lunch allowance
Private healthcare
+4
Senior Engineering Manager - Decision Intelligence
Senior Engineering Manager - Decision Intelligence

pleo • Deutschland

Hybrid
EUR 120.000 - 170.000
Pleo card
Lunch provided
Private healthcare
+4
Senior Applied AI Engineer
Senior Applied AI Engineer

ApplyMint • Deutschland

Hybrid
EUR 90.000 - 150.000
Your own Pleo card
Lunch provided or allowance
Private healthcare
+4
Account Executive II DACH
Account Executive II DACH

Meyandy LLC • Berlin

Hybrid
EUR 60.000 - 100.000
Your own Pleo card
Lunch allowance
Private health insurance
+2
Enterprise Account Executive - DACH
Enterprise Account Executive - DACH

Meyandy LLC • Berlin

Hybrid
EUR 70.000 - 120.000
Pleo card
Lunch allowance
Private health insurance
+4
Engineering Manager, Security *EU/UK remote*(m/f/d)
Engineering Manager, Security *EU/UK remote*(m/f/d)

Pliant • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-friendly work model
AI security tooling
Pliant Card with monthly credit
Security Engineer *EU/UK remote* (m/f/d)
Security Engineer *EU/UK remote* (m/f/d)

Pliant • Deutschland

Remote
EUR 70.000 - 90.000
Flexible work arrangements
Company card with monthly allowance for lunches
Attractive remuneration
Product & AI Security Engineer
Product & AI Security Engineer

Talon.One • Berlin

Hybrid
EUR 90.000 - 130.000
€1,000 annual learning budget
30 days annual leave
Home office setup budget
+1
Senior Manager - Infrastructure Security
Senior Manager - Infrastructure Security

Deliveryhero • Berlin

Hybrid
EUR 110.000 - 150.000
27 days holiday
Educational budget
Language courses
+8
Account Executive II DACH
Account Executive II DACH

Pleo • Berlin

Hybrid
EUR 50.000 - 70.000
Pleo card
Lunch allowance
Private health insurance
+2