M
New
USD 130000–190000/yr

Sr. Application Security Engineer

United StatesUnited StatesRemoteFull Timesenior
EngineeringSecurity Engineer
4 views0 saves0 applied

Quick Summary

Overview

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions.

Technical Tools
EngineeringSecurity Engineer

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.

What We Offer

~1 min read

Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.

This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.

. 

Additional/optional benefits: pet insurance, identity theft protection, legal assistance 

We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further! 

  • Perform hands-on security analysis of applications, services, APIs, and supporting components.
  • Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
  • Conduct manual secure code reviews of security-sensitive components and application changes.
  • Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
  • Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.
  • Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
  • Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
  • Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
  • Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
  • Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
  • Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.
  • Help define and mature security gates and review checkpoints throughout the SDLC.
  • Embed security requirements into architecture, design, sprint, and release processes.
  • Integrate preventative security controls into developer workflows and CI/CD pipelines.
  • Partner with Engineering to make secure development practices practical and scalable.
  • Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
  • Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
  • Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
  • Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
  • Improve security automation and feedback within CI/CD workflows.
  • Threat-model new features and significant architectural changes before code is written.
  • Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
  • Use methodologies such as STRIDE, PASTA, or equivalent approaches.
  • Translate threat-model findings into practical engineering requirements and security controls.
  • Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
  • Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
  • Evaluate application security risks across distributed services and cloud-native architectures.
  • Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
  • Provide developers with clear, actionable remediation guidance.
  • Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
  • Help develop and mature a Security Champions program across development teams.
  • Create runbooks, standards, and secure-development patterns teams can use independently.
  • Validate application and API vulnerabilities through hands-on testing when needed.
  • Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
  • Hands-on application or API penetration-testing experience is strongly preferred.
  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline.
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong hands-on coding and secure code review experience in Java, Python, and Go.
  • Ability to read, debug, and reason about production application code and communicate effectively with software engineers.
  • Ability to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
  • Hands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows.
  • Strong knowledge of software dependency and supply-chain security.
  • Experience prioritizing vulnerabilities using application and business context rather than scanner severity alone.
  • Strong understanding of OWASP Top 10 and OWASP API Security risks.
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Strong communication skills and the ability to influence developers, architects, and engineering leadership.
  • Hands-on application and API penetration-testing experience.
  • Financial services, fintech, identity, fraud, or regulated SaaS experience.
  • Experience with PCI-DSS application security requirements.
  • Experience building or leading a Security Champions program.
  • Experience developing AppSec automation or internal security tooling.
  • OSCP, GWEB, CSSLP, or similar technical security certification.
  • Establish trusted working relationships across Security and Engineering.
  • Improve the quality and actionability of SAST, DAST, and SCA findings.
  • Ensure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs.
  • Apply threat modeling consistently to major new features and architectural changes.
  • Reduce recurring vulnerability classes through upstream controls and secure development patterns.
  • Improve software dependency and supply-chain security practices.
  • Help launch and mature a Security Champions program across development teams.
  • Strengthen the overall technical credibility and effectiveness of Mitek’s Application Security function.
  •  

  • Ownership of the AppSec function with clear scope and executive visibility
  • A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  • Direct collaboration with the VP of IT and Security and Engineering leadership
  • A development team that is receptive to security partnership rather than treating it as an external constraint
  • A security program investing proactively from a position of strength — not reactive, not in crisis 
  • Location & Eligibility

    Where is the job
    United States
    Remote within one country
    Who can apply
    Open to applicants worldwide

    Listing Details

    Posted
    July 23, 2026
    First seen
    July 23, 2026
    Last seen
    September 17, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    80%
    Scored at
    July 23, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    M
    Sr. Application Security EngineerUSD 130000–190000