At a Glance
- Tasks: Lead a global team to embed security in Miro’s software development lifecycle.
- Company: Join Miro, a dynamic company at the forefront of innovative software solutions.
- Benefits: Competitive salary, remote work options, and opportunities for professional growth.
- Other info: Collaborative culture focused on continuous learning and improvement.
- Why this job: Make a real impact by enhancing security in cutting-edge AI-driven software development.
- Qualifications: 10+ years in application security and strong leadership skills required.
The predicted salary is between 80000 - 100000 € per year.
Requirements
- 10+ years of experience in software, application, or product security, including significant experience in secure software development
- 3+ years of technical leadership or management experience in a security-focused role
- Extensive experience with threat modeling methodologies (e.g., STRIDE, PASTA) and risk assessment, particularly within a SaaS or product-centric organization
- Deep expertise in Secure Software Development Lifecycles (SSDLC), including integrating security into agile and custom development frameworks
- Demonstrated experience running Security Champions programs and scaling developer engagement
- Experience leading offensive security programs (penetration testing, red teaming, bug bounty)
- Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM
- Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations
- Experience working with AWS and securing API-driven, microservice-based architectures
- Ability to manage distributed teams and communicate effectively across technical and business stakeholders
- Developer-Aligned: You understand the pace and pressure of modern software development and are committed to reducing friction while improving security posture
- An Exceptional Communicator: You can articulate complex technical risks to non-technical stakeholders and translate business goals into security strategy for your team
- A Natural Collaborator: You excel at building strong relationships and influencing cross-functional teams without direct authority
- A Pragmatic Problem-Solver: You are skilled at identifying scalable, risk-based solutions and are comfortable navigating ambiguity in a fast-paced environment
- Data-Driven: You use metrics and KPIs to measure the effectiveness of your programs and drive continuous improvement
- A Passionate Mentor: You are dedicated to developing talent and empowering engineers and product managers to be security champions
What the job involves
The Senior Manager of Application Security leads a global team responsible for embedding security into Miro’s Software Development Lifecycle (SDLC)—from concept to code to customer impact. This team partners closely with product and engineering to proactively mitigate risk while accelerating developer velocity and innovation. The role focuses on enabling secure-by-default development through secure design support, automated tooling, vulnerability management, offensive testing, and developer engagement. It also plays a critical role in integrating security into Miro’s Discover, Define, Deliver product lifecycle and aligning with our AMPED Ways of Working (Analytics, Marketing, Product, Engineering, Design) and AMPED Operating Model.
As Miro embraces AI-supported software development and explores Agentic AI workflows that empower engineers, product teams, and security teams alike, this role will contribute to adapting and securing those evolving working methods—ensuring that innovation and trust go hand in hand.
As Senior Manager of Application Security, you will define and operationalize Miro’s application security strategy in alignment with our industry-leading software development lifecycle and AMPED framework. You will lead a multidisciplinary team of application security engineers and offensive security specialists who work directly with developers, product teams, and platform engineering across multiple regions. You will embed security into all phases of the product lifecycle—from early discovery and architecture threat modeling, to design reviews and secure delivery pipelines, and ongoing monitoring and testing post-release. Your team will also support Miro’s AI-driven development tooling and guide secure adoption of Agentic AI workflows, which enable both developers and security teams to collaborate more efficiently and proactively.
The role requires a pragmatic, hands-on leader who thrives in fast-moving environments and has a deep understanding of both software engineering and security, as well as a passion for empowering teams to build securely and autonomously.
Lead and mentor a globally distributed team of security engineers focused on application security, offensive testing, secure architecture, and vulnerability remediation. Lead and coordinate the team’s initiatives and help provide project management leadership to the team members. Coordinate cross-function and cross-stream initiatives and projects. Drive integration of security into Miro’s Discover, Define, Deliver lifecycle through the lens of the AMPED Ways of Working and Operating Model. Collaborate with Product, Engineering, and Design to ensure security is considered at the earliest stages of ideation—via threat modeling, risk reviews, and abuse-case analysis. Shape and evolve Miro’s Secure SDLC practices, integrating security seamlessly into CI/CD pipelines, infrastructure-as-code, and developer tooling. Oversee execution of bug bounty and third-party testing programs, ensuring vulnerabilities are triaged, communicated, and remediated effectively. Build and scale Miro’s Security Champions program to embed security ownership within each engineering team. Guide secure adoption of AI-augmented software development tools, including LLMs used for code generation, reviews, or architectural assistance. Help envision and safely operationalize Agentic AI-driven developer and security workflows, including policy-driven autonomous agents supporting security automation and decision-making. Provide structured guidance, patterns, and reference architectures that support developers in implementing secure, scalable, and privacy-respecting features. Define and report on KPIs and success metrics for secure development adoption, vulnerability resolution, and developer engagement. Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations). Foster a strong team culture based on collaboration, learning, and continuous improvement.
Senior Manager of Application Security in London employer: Deepstreamtech
Miro is an exceptional employer that prioritises a collaborative and innovative work culture, making it an ideal place for professionals in application security. With a strong focus on employee growth, Miro offers opportunities to lead a global team while embedding security into cutting-edge software development practices, all within a dynamic environment that embraces AI-driven workflows. Employees benefit from a supportive atmosphere that encourages mentorship, continuous learning, and the chance to make a meaningful impact on product security and developer engagement.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Manager of Application Security in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or conferences related to application security. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio that highlights your experience with secure software development, threat modelling, and any offensive security programs you've led. This will give potential employers a clear picture of what you bring to the table.
✨Tip Number 3
Don’t just apply—engage! When you find a role that excites you, reach out to current employees on LinkedIn. Ask them about their experiences and the company culture. This not only shows your interest but can also give you valuable insights.
✨Tip Number 4
Apply through our website! We love seeing candidates who take the initiative. Plus, it’s a great way to ensure your application gets into the right hands. Make sure to tailor your application to highlight your leadership and collaboration skills in security.
We think you need these skills to ace Senior Manager of Application Security in London
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in application security, especially your leadership roles and any relevant methodologies you've used. We want to see how your background aligns with our needs!
Showcase Your Technical Skills:Don’t hold back on detailing your technical expertise! Mention your familiarity with SSDLC, threat modelling, and any tools you’ve used like AWS or AI/LLM tooling. This is your chance to shine and show us what you bring to the table.
Communicate Clearly:Remember, we value clear communication! When describing your past experiences, make sure to articulate complex concepts in a way that’s easy to understand. This will demonstrate your ability to bridge the gap between technical and non-technical stakeholders.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Deepstreamtech
✨Know Your Stuff
Make sure you brush up on your knowledge of secure software development and threat modelling methodologies like STRIDE and PASTA. Be ready to discuss how you've applied these in past roles, especially in a SaaS environment.
✨Show Your Leadership Skills
Since this role involves managing a global team, be prepared to share examples of your technical leadership experience. Talk about how you've successfully led teams, run Security Champions programs, or scaled developer engagement in previous positions.
✨Communicate Clearly
You’ll need to articulate complex security concepts to non-technical stakeholders. Practice explaining technical risks in simple terms and how they align with business goals. This will show that you can bridge the gap between tech and business.
✨Be a Problem Solver
Demonstrate your ability to navigate ambiguity and find scalable, risk-based solutions. Share specific examples of challenges you've faced in fast-paced environments and how you tackled them, particularly in relation to integrating security into development processes.