At a Glance
- Tasks: Lead application security strategy and manage vulnerabilities to protect our customers.
- Company: Join a dynamic fintech company transforming spend management for over 40,000 customers.
- Benefits: Enjoy competitive pay, comprehensive healthcare, and flexible working options.
- Other info: Collaborative culture with opportunities for personal and professional growth.
- Why this job: Make a real impact in a fast-paced environment while mentoring future security leaders.
- Qualifications: 10+ years in application security with a hands-on management approach.
The predicted salary is between 63000 - 77000 £ per year.
About Pleo Messy spend management is tricky business.
And tedious processes are a lose-lose situation for all involved, not just finance.
At the company, we're changing that.
We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’.
The word ‘the company’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.
Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success.
We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high.
With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out.
And frankly, that’s half the fun!
What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.
About the role
We're looking for a Senior Application Security Manager to join our Cybersecurity team at the company.
In this role, you'll own vulnerability management and set the long-term application security strategy, turning a growing stream of signal into a risk-ranked plan the engineering organisation can actually act on.
If you're a player-coach who wants high leverage with low bureaucracy, and you'd rather mature a program than maintain one, then this is the opportunity for you!
Who you'll be working with and reporting to
You’ll report to our VP of Fraud & Security and lead a small App Sec team with dotted lines to other security members.
Your primary customers are the company's engineering squads, and your closest partners are Dev Sec Ops, who feed you signal and automation, alongside Sec Ops, Risk & Compliance, Privacy, and Legal.
Our team is highly collaborative and dedicated to keeping the company and its customers safe.
You'll also have the chance to shape how the wider organisation thinks about security, well beyond your own team.
What you'll be doing
As a Senior Application Security Manager, you will
- Own vulnerability management end to end, covering reporting, triage, mitigation, and the long-term strategy for application security as a department.
- Build a structured, risk-ranked approach to remediation, so the organisation knows what to fix first and why.
- Establish clear, company-wide reporting on our vulnerability posture, giving leadership the data-driven visibility they need.
- Set and deliver an App Sec roadmap, bringing delivery expectations and accountability to a team that hasn't had them.
- Partner with engineering squads as customers rather than gatekeeping them, embedding proactive security processes into how they already work.
- Multiply your team's impact through automation and AI, so coverage scales faster than headcount.
- Grow and mentor engineers, coaching them toward staff-level capability and building their confidence along the way.
- Support the company's compliance obligations across ISO27001, PCI-DSS, GDPR, and the regulatory expectations of each market we operate in, from a security vulnerability perspective.
- Reduce our attack surface through technical controls, policy, and AI enablement, addressing both external threats and internal risk.
- Contribute to the broader Cybersecurity team, staying connected with ongoing initiatives and helping shape our 2027 KPIs.
What you bring
You thrive in this role if you have
- 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment.
- A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands‑on.
- A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it.
- Demonstrated experience turning signal into prioritised action through risk-based triage.
- Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process.
- The ability to shape culture outside your own team, influencing engineering squads without formal authority over them.
- Comfort in a fast-moving, complex, ever‑evolving environment, where you're self‑directed and proactive.
- Exposure to fintech compliance requirements is a strong advantage. Backgrounds we also look at include Dev Sec Ops and platform security leads with real App Sec depth.
- Why is this role a good fit for you
- You want a fast, visible impact on a program with real room to improve, without having to fight for basic tooling and process first.
- You treat developers as customers and get satisfaction from security becoming an enabler rather than a blocker.
- You like being a player‑coach, staying close to the technical work while growing the people around you.
- You're motivated by high leverage and low bureaucracy, and you'd rather build the system than personally do every task.
- This role is not a good fit for you
- You're looking to step away from technical work entirely at this level.
- You prefer to lead through mandate and process rather than partnership and example.
- You're sceptical of automation, AI, or of leaning on signal from partner teams.
- How you'll develop in this role
- Get hands‑on with the company's application security landscape, understanding our attack surface across payment systems and multi‑region infrastructure, and forming your own view of where the real risk sits.
- Stand up clear vulnerability reporting and a risk‑ranked remediation approach, and get key vulnerabilities patched proactively ahead of our next compliance audit.
- Build trust with engineering squads and start shifting the security culture, so teams come to you early rather than late.
- Integrate into the Cybersecurity team, connecting with Dev Sec Ops, Sec Ops, and Risk & Compliance, and begin shaping the roadmap and KPIs that carry the program into 2027.
Show me the benefits!
- Your own the company card (no more out‑of‑pocket spending!)
- Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office
- Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis
- We offer 25-28 days of holiday (depending on your location) + public holidays
- For our Team, we offer both hybrid and fully remote working options
- Option to purchase 5 additional days of holiday through a salary sacrifice
- We use Mynd Up to give our employees access to free mental health and well‑being support with great success so far
- Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
- The interview process
We want to ensure you are set-up for success and understand what will be expected of you. If your application is successful, our interview process is as follows:
- Intro call: A 30‑minute chat with our Talent Partner to discuss the role, your background, and how you feel about the player‑coach shape of the job.
- Hiring Manager interview: a 60‑minute conversation with our security management team, covering your App Sec depth, your evidence of maturing an existing program, and your partnership mindset.
- Technical interview: a 60‑minute deep dive with our App Sec team on your hands‑on application security expertise.
- Cross‑functional interview: a 30‑45 minute conversation with Privacy, Legal, and Risk & Compliance on how you work across those boundaries.
- Leadership interview: a 45‑minute conversation on mentoring and growing engineers, and influencing without authority.
About your application
English first. Since it's our company language, please submit your application in English. You’ll be using it a lot if you join us.
- A fair look for everyone.
Our talent team reads every single application to ensure the process is fair.
To keep things running smoothly, we only accept applications through our system—our support team can’t pass on calls or emails.
- Diversity drives us.
We can only reach our goals if our team reflects the world around us.
That starts with you hitting apply, even if you don't tick every single box.
We encourage people from all backgrounds and experiences to join us.
- Interview at your best.
We want you to feel comfortable throughout the process.
If you have any accessibility requirements or need a specific format, email ----- We’ll design a process that works for you.
- Your data is safe.
When you apply, we process your personal data as a data processor.
For more information on how the company processes personal data, read our Privacy Policy here.
• Applying for multiple roles?
Nothing is stopping you, and we assess every role independently.
However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.
- Reapplying. If you’re applying for the same role again, please wait six months from your last decision before hitting submit.
- The location
Please note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work.
We are unable to offer visa sponsorship for this role in any of the listed locations.
- Find Jobs in United Kingdom on Arbeitnow
- #J-18808-Ljbffr
Senior Application Security Manager in London employer: United States Digital Space LLC
United States Digital Space LLC is an exceptional employer, offering a dynamic work culture that prioritises innovation and collaboration in the heart of Greater London. With a strong focus on employee well-being and flexible work options, we provide ample opportunities for professional growth and development, making it an ideal environment for those looking to make a meaningful impact in the field of AI-enabled SaaS engineering.
Contact Details:
United States Digital Space LLC Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Senior Application Security Manager in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including United States Digital Space LLC, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through United States Digital Space LLC
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at United States Digital Space LLC. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Application Security Manager in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at United States Digital Space LLC insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to United States Digital Space LLC that you’re committed to staying ahead in the game.
How to prepare for a job interview at United States Digital Space LLC
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at United States Digital Space LLC to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at United States Digital Space LLC.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.