# Senior Application Security Manager

[Pleo](https://gurify.com/jobs?q=Pleo) · London · Posted today

Senior

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/pleo/9c3d090f-9f03-4e8e-8e5a-c5369d9f5dce)

## Job description

### ABOUT PLEO

Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.

The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.

Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.

### ABOUT THE ROLE

We're looking for a Senior Application Security Manager to join our Cybersecurity team at Pleo. In this role, you'll own vulnerability management and set the long-term application security strategy, turning a growing stream of signal into a risk-ranked plan the engineering organisation can actually act on. If you're a player-coach who wants high leverage with low bureaucracy, and you'd rather mature a program than maintain one, then this is the opportunity for you!

### WHO YOU'LL BE WORKING WITH AND REPORTING TO

You'll report to our VP of Fraud & Security and lead a small AppSec team with dotted lines to other security members. Your primary customers are Pleo's engineering squads, and your closest partners are DevSecOps, who feed you signal and automation, alongside SecOps, Risk & Compliance, Privacy, and Legal. Our team is highly collaborative and dedicated to keeping Pleo and its customers safe. You'll also have the chance to shape how the wider organisation thinks about security, well beyond your own team.

### WHAT YOU'LL BE DOING

### As a Senior Application Security Manager, you will:

- Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.

- Build a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.

- Establish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.

- Set and deliver an AppSec roadmap, bringing delivery expectations and accountability to a team that hasn't had them.

- Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.

- Multiply your team's impact through automation and AI, so coverage scales faster than headcount.

- Grow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.

- Support Pleo's compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.

- Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.

- Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.

### WHAT YOU BRING

### You'll thrive in this role if you have:

- 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.

- A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands-on.

- A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.

- Demonstrated experience turning signal into prioritised action through risk-based triage.

- Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process.

- The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.

- Comfort in a fast-moving, complex, ever-evolving environment, where you're self-directed and proactive.

- Exposure to fintech compliance requirements is a strong advantage. Backgrounds we also look at include DevSecOps and platform security leads with real AppSec depth.

### WHY IS THIS ROLE A GOOD FIT FOR YOU

### This role is a good fit for you if:

- You want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.

- You treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.

- You like being a player-coach, staying close to the technical work while growing the people around you.

- You're motivated by high leverage and low bureaucracy, and you'd rather build the system than personally do every task.

This role is not a good fit for you if:

- You're looking to step away from technical work entirely at this level.

- You prefer to lead through mandate and process rather than partnership and example.

- You're sceptical of automation, AI, or of leaning on signal from partner teams.

### HOW YOU'LL DEVELOP IN THIS ROLE

### In your first 6 months at Pleo, you'll:

- Get hands-on with Pleo's application security landscape, understanding our attack surface across payment systems and multi-region infrastructure, and forming your own view of where the real risk sits.

- Stand up clear vulnerability reporting and a risk-ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.

- Build trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.

- Integrate into the Cybersecurity team, connecting with DevSecOps, SecOps, and Risk & Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.

By 12 months, the goal is a documented, repeatable security program with proactive threat monitoring in place, regulatory readiness for new markets, and a team that can scale.

We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into broader leadership, or acquiring new skills.

### THE LOCATION

Please note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.

SHOW ME THE BENEFITS!

- Your own Pleo card (no more out-of-pocket spending!)

- Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office

- Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis

- We offer 25-28 days of holiday (depending on your location) + public holidays

- For our Team, we offer both hybrid and fully remote working options

- Option to purchase 5 additional days of holiday through a salary sacrifice

- We use MyndUp to give our employees access to free mental health and well-being support with great success so far

- Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work

### THE INTERVIEW PROCESS

We want to ensure you are set-up for success and understand what will be expected of you. If your application is successful, our interview process is as follows:

1. Intro call: A 30-minute chat with our Talent Partner to discuss the role, your background, and how you feel about the player-coach shape of the job.

2. Hiring Manager interview: a 60-minute conversation with our security management team, covering your AppSec depth, your evidence of maturing an existing program, and your partnership mindset.

3. Technical interview: a 60-minute deep dive with our AppSec team on your hands-on application security expertise.

4. Cross-functional interview: a 30-45 minute conversation with Privacy, Legal, and Risk & Compliance on how you work across those boundaries.

5. Leadership interview: a 45-minute conversation on mentoring and growing engineers, and influencing without authority.

### ABOUT YOUR APPLICATION

- English first. Since it's our company language, please submit your application in English. You’ll be using it a lot if you join us.

- A fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly, we only accept applications through our system—our support team can’t pass on calls or emails.

- Diversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply, even if you don't tick every single box. We encourage people from all backgrounds and experiences to join us.

- Interview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format, email belonging@pleo.io. We’ll design a process that works for you.

- Your data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy here https://www.pleo.io/en/legal.

- Applying for multiple roles? Nothing is stopping you, and we assess every role independently. However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.

- Reapplying. If you’re applying for the same role again, please wait six months from your last decision before hitting submit.

**Live in Pleo’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- CA [Lead Application Security Engineer](https://gurify.com/job/lead-application-security-engineer-at-cais-2e04484adf2f) Cais · London, United Kingdom · 3 weeks ago
- IS [Security Engineer (Corporate ...](https://gurify.com/job/security-engineer-corporate-at-isomorphiclabs-17e7d61d3f92) Isomorphiclabs · London · last week
- AN [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-andurilindustries-c2faf3dcb01a) Andurilindustries · London, United Kingdom · last week
- ZE [AI Agent Security | Head of EMEA](https://gurify.com/job/ai-agent-security-head-of-emea-at-zenity-b87651053db9) Zenity · London, United Kingdom · last week
- SN [Senior Network Security Engineer (Palo Alto SASE) - Natilik](https://gurify.com/job/senior-network-security-engineer-palo-alto-sase-natilik-56f1fadf72a1) London, United Kingdom · last week
- AN [Senior Product Security Engineer](https://gurify.com/job/senior-product-security-engineer-at-andurilindustries-74aa38d8eb35) Andurilindustries · London, United Kingdom · last week

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Application Security Manager","description":"\u003Ch3\u003EABOUT PLEO\u003C/h3\u003E\u003Cp\u003EMessy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we\u0026#39;re changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses \u2018go beyond\u2019.\u003C/p\u003E\u003Cp\u003EThe word \u2018Pleo\u2019 actually means \u2018more than you\u2019d expect\u2019, and living by that mantra has been the secret to our success over the last 10 years.\u003C/p\u003E\u003Cp\u003ENow, we\u2019re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000\u002B customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can\u2019t say we\u2019ve got this whole thing figured out. And frankly, that\u2019s half the fun! What we can say is that we\u2019re a driven, progressive, and, importantly, a kind bunch of 850\u002B people from over 100 nationalities, all committed to delivering the future of business spending, together.\u003C/p\u003E\u003Ch3\u003EABOUT THE ROLE\u003C/h3\u003E\u003Cp\u003EWe\u0026#39;re looking for a Senior Application Security Manager to join our Cybersecurity team at Pleo. In this role, you\u0026#39;ll own vulnerability management and set the long-term application security strategy, turning a growing stream of signal into a risk-ranked plan the engineering organisation can actually act on. If you\u0026#39;re a player-coach who wants high leverage with low bureaucracy, and you\u0026#39;d rather mature a program than maintain one, then this is the opportunity for you!\u003C/p\u003E\u003Ch3\u003EWHO YOU\u0026#39;LL BE WORKING WITH AND REPORTING TO\u003C/h3\u003E\u003Cp\u003EYou\u0026#39;ll report to our VP of Fraud \u0026amp; Security and lead a small AppSec team with dotted lines to other security members. Your primary customers are Pleo\u0026#39;s engineering squads, and your closest partners are DevSecOps, who feed you signal and automation, alongside SecOps, Risk \u0026amp; Compliance, Privacy, and Legal. Our team is highly collaborative and dedicated to keeping Pleo and its customers safe. You\u0026#39;ll also have the chance to shape how the wider organisation thinks about security, well beyond your own team.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u0026#39;LL BE DOING\u003C/h3\u003E\u003Ch3\u003EAs a Senior Application Security Manager, you will:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EOwn vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEstablish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESet and deliver an AppSec roadmap, bringing delivery expectations and accountability to a team that hasn\u0026#39;t had them.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPartner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMultiply your team\u0026#39;s impact through automation and AI, so coverage scales faster than headcount.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGrow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESupport Pleo\u0026#39;s compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHAT YOU BRING\u003C/h3\u003E\u003Ch3\u003EYou\u0026#39;ll thrive in this role if you have:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003E10\u002B years of experience steering application security and wider information security strategy in a compliance-heavy environment.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA background as a senior security engineer who moved into management, with enough technical depth that you\u0026#39;re still credible and still hands-on.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDemonstrated experience turning signal into prioritised action through risk-based triage.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience using AI and automation to scale security coverage, rather than solving everything through headcount or process.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThe ability to shape culture outside your own team, influencing engineering squads without formal authority over them.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComfort in a fast-moving, complex, ever-evolving environment, where you\u0026#39;re self-directed and proactive.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExposure to fintech compliance requirements is a strong advantage. Backgrounds we also look at include DevSecOps and platform security leads with real AppSec depth.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EWHY IS THIS ROLE A GOOD FIT FOR YOU\u003C/h3\u003E\u003Ch3\u003EThis role is a good fit for you if:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EYou want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou like being a player-coach, staying close to the technical work while growing the people around you.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;re motivated by high leverage and low bureaucracy, and you\u0026#39;d rather build the system than personally do every task.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EThis role is not a good fit for you if:\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;re looking to step away from technical work entirely at this level.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou prefer to lead through mandate and process rather than partnership and example.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;re sceptical of automation, AI, or of leaning on signal from partner teams.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EHOW YOU\u0026#39;LL DEVELOP IN THIS ROLE\u003C/h3\u003E\u003Ch3\u003EIn your first 6 months at Pleo, you\u0026#39;ll:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EGet hands-on with Pleo\u0026#39;s application security landscape, understanding our attack surface across payment systems and multi-region infrastructure, and forming your own view of where the real risk sits.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStand up clear vulnerability reporting and a risk-ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIntegrate into the Cybersecurity team, connecting with DevSecOps, SecOps, and Risk \u0026amp; Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EBy 12 months, the goal is a documented, repeatable security program with proactive threat monitoring in place, regulatory readiness for new markets, and a team that can scale.\u003C/p\u003E\u003Cp\u003EWe\u0026#39;re committed to helping you develop your career, whether that means taking on bigger projects, stepping into broader leadership, or acquiring new skills.\u003C/p\u003E\u003Ch3\u003ETHE LOCATION\u003C/h3\u003E\u003Cp\u003EPlease note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.\u003C/p\u003E\u003Cp\u003ESHOW ME THE BENEFITS!\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EYour own Pleo card (no more out-of-pocket spending!)\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ELunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EComprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or M\u0026#233;dis\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe offer 25-28 days of holiday (depending on your location) \u002B public holidays\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFor our Team, we offer both hybrid and fully remote working options\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOption to purchase 5 additional days of holiday through a salary sacrifice\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWe use MyndUp to give our employees access to free mental health and well-being support with great success so far\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPaid parental leave - we want to make sure that we\u0026#39;re supportive of families and help you feel that you don\u0026#39;t have to compromise your family due to work\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ETHE INTERVIEW PROCESS\u003C/h3\u003E\u003Cp\u003EWe want to ensure you are set-up for success and understand what will be expected of you. If your application is successful, our interview process is as follows:\u003C/p\u003E\u003Cp\u003E1. Intro call: A 30-minute chat with our Talent Partner to discuss the role, your background, and how you feel about the player-coach shape of the job.\u003C/p\u003E\u003Cp\u003E2. Hiring Manager interview: a 60-minute conversation with our security management team, covering your AppSec depth, your evidence of maturing an existing program, and your partnership mindset.\u003C/p\u003E\u003Cp\u003E3. Technical interview: a 60-minute deep dive with our AppSec team on your hands-on application security expertise.\u003C/p\u003E\u003Cp\u003E4. Cross-functional interview: a 30-45 minute conversation with Privacy, Legal, and Risk \u0026amp; Compliance on how you work across those boundaries.\u003C/p\u003E\u003Cp\u003E5. Leadership interview: a 45-minute conversation on mentoring and growing engineers, and influencing without authority.\u003C/p\u003E\u003Ch3\u003EABOUT YOUR APPLICATION\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EEnglish first. Since it\u0026#39;s our company language, please submit your application in English. You\u2019ll be using it a lot if you join us.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly, we only accept applications through our system\u2014our support team can\u2019t pass on calls or emails.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDiversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply, even if you don\u0026#39;t tick every single box. We encourage people from all backgrounds and experiences to join us.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EInterview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format, email belonging@pleo.io. We\u2019ll design a process that works for you.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYour data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy here https://www.pleo.io/en/legal.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EApplying for multiple roles? Nothing is stopping you, and we assess every role independently. However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EReapplying. If you\u2019re applying for the same role again, please wait six months from your last decision before hitting submit.\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"senior-application-security-manager-at-pleo-a802ea6ca707"},"url":"https://gurify.com/job/senior-application-security-manager-at-pleo-a802ea6ca707","datePosted":"2026-08-13","validThrough":"2026-09-27T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Pleo","sameAs":"https://jobs.ashbyhq.com/pleo"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Senior Application Security Manager","item":"https://gurify.com/job/senior-application-security-manager-at-pleo-a802ea6ca707"}]}
```
