M
USD 130000–190000/yr

Sr. Application Security Engineer

United StatesUnited StatesRemoteFull Timesenior
EngineeringSecurity Engineer
1 views0 saves0 applied

Quick Summary

Key Responsibilities

No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount) Knowledge,

Technical Tools
EngineeringSecurity Engineer

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.

What We Offer

~4 min read

The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly. 

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 

 Vulnerability Remediation 

Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs
Work with development squads to explain findings, validate fixes, and confirm remediation
Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs
Define and own the SDLC — security gates and review checkpoints in sprint and release processes
Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output
Embed security requirements into product planning and architecture decisions
Threat-model new features and architectural changes before code is written
Review designs for authentication, authorization, data-flow, and cryptographic risk
Produce written threat models that serve as developer guidance and audit evidence
Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention
Conduct or coordinate manual secure code review of security-sensitive components
Lead application penetration-testing cycles — scoping, managing testers, validating findings
Build and run a Security Champions program across development squads
Deliver developer security training on OWASP Top 10 and secure-coding patterns
Create runbooks, coding standards, and pattern libraries developers can apply independently
Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)
Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering
Application penetration testing including business-logic and API testing
Hands-on SAST, DAST, and SCA tuning and operationalization
Secure code review across at least two web-application languages
Threat modeling using STRIDE, PASTA, or equivalent
Depth in OWASP Top 10 and API security risks; ability to influence development teams
Financial services, fintech, or SaaS for regulated industries
Financial-sector threat knowledge — fraud, account takeover, API abuse
Cloud-native application security including container security
PCI-DSS application security requirements
OSCP, GWEB, or CSSLP
Prior experience building a Security Champions program
Remediation plan for all critical/high findings within 30 days
Critical/high remediation above 90% within SLA by month six
Threat modeling applied to all major new features within 90 days
Security Champions program launched (1+ per squad) within six months
SAST and DAST tuned and developer-actionable within 60 days
Ownership of the AppSec function with clear scope and executive visibility
A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
Direct collaboration with the VP of IT and Security and Engineering leadership
A development team that is receptive to security partnership rather than treating it as an external constraint
A security program investing proactively from a position of strength — not reactive, not in crisis

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
Open to applicants worldwide

Listing Details

Posted
July 23, 2026
First seen
July 23, 2026
Last seen
July 24, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
80%
Scored at
July 23, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

M
Sr. Application Security EngineerUSD 130000–190000