Auf einen Blick
- Aufgaben: Leite das Vulnerabilitätsmanagement und entwickle die langfristige Strategie für Anwendungssicherheit.
- Unternehmen: Pleo, ein innovatives Unternehmen im Bereich Ausgabenmanagement mit einer vielfältigen Kultur.
- Vorteile: Wettbewerbsfähiges Gehalt, umfassende Gesundheitsversorgung, flexible Arbeitsmodelle und berufliche Entwicklung.
- Weitere Informationen: Wachstumsorientiertes Team mit großartigen Karrierechancen und Unterstützung für persönliche Entwicklung.
- Warum dieser Job: Gestalte die Sicherheitskultur und arbeite an spannenden Herausforderungen in einem dynamischen Umfeld.
- Qualifikationen: Mindestens 10 Jahre Erfahrung in der Anwendungssicherheit und Führungskompetenz.
Das prognostizierte Gehalt liegt zwischen 58500 - 71500 € pro Jahr.
About Pleo
Messy spend management is tricky business.
And tedious processes are a lose-lose situation for all involved, not just finance.
At Pleo, we're changing that.
We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses 'go beyond'.
The word 'Pleo' actually means 'more than you'd expect', and living by that mantra has been the secret to our success over the last 10 years.
Now, we're at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success.
We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high.
With great ambitions driving us forward, we can't say we've got this whole thing figured out.
And frankly, that's half the fun!
What we can say is that we're a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.
About the role
We're looking for a Senior Application Security Manager to join our Cybersecurity team at Pleo.
In this role, you'll own vulnerability management and set the long-term application security strategy, turning a growing stream of signal into a risk-ranked plan the engineering organisation can actually act on.
If you're a player-coach who wants high leverage with low bureaucracy, and you'd rather mature a program than maintain one, then this is the opportunity for you!
Who you'll be working with and reporting to
You'll report to our VP of Fraud & Security and lead a small App Sec team with dotted lines to other security members.
Your primary customers are Pleo's engineering squads, and your closest partners are Dev Sec Ops, who feed you signal and automation, alongside Sec Ops, Risk & Compliance, Privacy, and Legal.
Our team is highly collaborative and dedicated to keeping Pleo and its customers safe.
You'll also have the chance to shape how the wider organisation thinks about security, well beyond your own team.
- What you'll be doing
- Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.
- Build a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.
- Establish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.
- Set and deliver an App Sec roadmap, bringing delivery expectations and accountability to a team that hasn't had them.
- Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.
- Multiply your team's impact through automation and AI, so coverage scales faster than headcount.
- Grow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.
- Support Pleo's compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.
- Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.
- Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.
What you bring
- 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.
- A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands-on.
- A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.
- Demonstrated experience turning signal into prioritised action through risk-based triage.
- Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process.
- The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.
- Comfort in a fast-moving, complex, ever-evolving environment, where you're self-directed and proactive.
- Exposure to fintech compliance requirements is a strong advantage. Backgrounds we also look at include Dev Sec Ops and platform security leads with real App Sec depth.
- Why is this role a good fit for you
- You want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.
- You treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.
- You like being a player-coach, staying close to the technical work while growing the people around you.
- You're motivated by high leverage and low bureaucracy, and you'd rather build the system than personally do every task.
- This role is not a good fit for you
- You're looking to step away from technical work entirely at this level.
- You prefer to lead through mandate and process rather than partnership and example.
- You're sceptical of automation, AI, or of leaning on signal from partner teams.
- How you'll develop in this role
- Get hands-on with Pleo's application security landscape, understanding our attack surface across payment systems and multi-region infrastructure, and forming your own view of where the real risk sits.
- Stand up clear vulnerability reporting and a risk-ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.
- Build trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.
- Integrate into the Cybersecurity team, connecting with Dev Sec Ops, Sec Ops, and Risk & Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.
- By 12 months, the goal is a documented, repeatable security program with proactive threat monitoring in place, regulatory readiness for new markets, and a team that can scale.
We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into broader leadership, or acquiring new skills.
The location
Please note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work.
We are unable to offer visa sponsorship for this role in any of the listed locations.
Show me the benefits!
- Your own Pleo card (no more out-of-pocket spending!)
- Lunch is on us for your work days – enjoy catered meals or receive a lunch allowance based on your local office
- Comprehensive private healthcare – depending on your location, coverage options include Vitality, Alan or Médis
- We offer 25-28 days of holiday (depending on your location) + public holidays
- For our Team, we offer both hybrid and fully remote working options
- Option to purchase 5 additional days of holiday through a salary sacrifice
- We use Mynd Up to give our employees access to free mental health and well-being support with great success so far
- Paid parental leave – we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
- #J-18808-Ljbffr
Senior Application Security Manager Arbeitgeber: DaParrot Ltd
Pleo ist ein hervorragender Arbeitgeber, der eine dynamische und unterstützende Arbeitsumgebung bietet, in der Innovation und Zusammenarbeit im Mittelpunkt stehen. Mit einem engagierten Team von über 850 Mitarbeitern aus mehr als 100 Nationalitäten fördern wir die persönliche und berufliche Weiterentwicklung und bieten flexible Arbeitsmodelle, um die Work-Life-Balance zu unterstützen. Unsere umfassenden Benefits, einschließlich privater Gesundheitsversorgung und großzügiger Urlaubsregelungen, machen Pleo zu einem attraktiven Arbeitsplatz für alle, die in der Fintech-Branche einen bedeutenden Beitrag leisten möchten.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Senior Application Security Manager erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie DaParrot Ltd kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von DaParrot Ltd zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei DaParrot Ltd.
Wir glauben, dass du diese Fähigkeiten brauchst, um Senior Application Security Manager mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei DaParrot Ltd vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei DaParrot Ltd könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. DaParrot Ltd sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird DaParrot Ltd auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!