Sr. Application Security Engineer
Quick Summary
Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions.
Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.
What We Offer
~1 min readMitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.
This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.
.
Additional/optional benefits: pet insurance, identity theft protection, legal assistance
We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!
- Perform hands-on security analysis of applications, services, APIs, and supporting components.
- Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
- Conduct manual secure code reviews of security-sensitive components and application changes.
- Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
- Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.
- Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
- Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
- Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
- Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
- Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
- Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.
- Help define and mature security gates and review checkpoints throughout the SDLC.
- Embed security requirements into architecture, design, sprint, and release processes.
- Integrate preventative security controls into developer workflows and CI/CD pipelines.
- Partner with Engineering to make secure development practices practical and scalable.
- Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
- Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
- Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
- Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
- Improve security automation and feedback within CI/CD workflows.
- Threat-model new features and significant architectural changes before code is written.
- Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
- Use methodologies such as STRIDE, PASTA, or equivalent approaches.
- Translate threat-model findings into practical engineering requirements and security controls.
- Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
- Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
- Evaluate application security risks across distributed services and cloud-native architectures.
- Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
- Provide developers with clear, actionable remediation guidance.
- Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
- Help develop and mature a Security Champions program across development teams.
- Create runbooks, standards, and secure-development patterns teams can use independently.
- Validate application and API vulnerabilities through hands-on testing when needed.
- Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
- Hands-on application or API penetration-testing experience is strongly preferred.
Location & Eligibility
Listing Details
- Posted
- July 23, 2026
- First seen
- July 23, 2026
- Last seen
- September 17, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 80%
- Scored at
- July 23, 2026
Signal breakdown
Please let Miteksystems 2 know you found this job on Jobera.
4 other jobs at Miteksystems 2
View all →Explore open roles at Miteksystems 2.
Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.