Senior Application Security Manager
RemoteUnited Kingdom or Spain
Job Summary
Own vulnerability management end to end, covering reporting, triage, mitigation, and long-term strategy for application security as a department. Build a structured, risk-ranked approach to remediation and establish clear, company-wide reporting on vulnerability posture. Set and deliver an AppSec roadmap while partnering with engineering squads to embed proactive security processes. Multiply team impact through automation and AI, and grow engineers by mentoring them toward staff-level capability. Support compliance obligations across ISO27001, PCI-DSS, and GDPR from a security vulnerability perspective. Reduce the attack surface through technical controls, policy, and AI enablement. Contribute to the broader Cybersecurity team to shape the 2027 KPIs.
Required Qualifications
- 10+ years of experience steering application security and wider information security strategy in a compliance-heavy environment
- A background as a senior security engineer who moved into management, with enough technical depth that you're still credible and still hands-on
- A track record of mentoring and growing engineers, and of keeping a team accountable without micromanaging it
- Demonstrated experience turning signal into prioritised action through risk-based triage
- Experience using AI and automation to scale security coverage, rather than solving everything through headcount or process
- The ability to shape culture outside your own team, influencing engineering squads without formal authority over them
- Comfort in a fast-moving, complex, ever-evolving environment, where you're self-directed and proactive
- Valid right to work in the country of choice
- English language proficiency
Desired Qualifications
- Exposure to fintech compliance requirements
- Backgrounds in DevSecOps and platform security leads with real AppSec depth
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.