
Posted 2 months ago
Sr. Application Security Engineer
AI Summary
Senior Application Security Engineer at Mitek Systems serves as the technical authority on application security, owning vulnerability remediation, secure SDLC, threat modeling, API security, and developer enablement for a ~50-person team building internet-hosted banking and financial software.
About this role
Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.
We are Virtual 1st! Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”
At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it. We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.
Why this role now
The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly.
What You’ll Do (Essential Responsibilities)
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Vulnerability Remediation
-
Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs
-
Work with development squads to explain findings, validate fixes, and confirm remediation
-
Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs
Secure Development Lifecycle
-
Define and own the SDLC — security gates and review checkpoints in sprint and release processes
-
Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output
-
Embed security requirements into product planning and architecture decisions
Threat Modeling & Secure Design
-
Threat-model new features and architectural changes before code is written
-
Review designs for authentication, authorization, data-flow, and cryptographic risk
-
Produce written threat models that serve as developer guidance and audit evidence
API Security & Secure Code Review
-
Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention
-
Conduct or coordinate manual secure code review of security-sensitive components
-
Lead application penetration-testing cycles — scoping, managing testers, validating findings
Developer Enablement
-
Build and run a Security Champions program across development squads
-
Deliver developer security training on OWASP Top 10 and secure-coding patterns
-
Create runbooks, coding standards, and pattern libraries developers can apply independently
This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.
Managerial Responsibilities
-
Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)
What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
What Would be Nice (Preferred Skills & Experience)
Success Metrics -First Year
What we Offer
Skills
Explore related jobs
More jobs at Mitek Systems
Similar Threat Modeling jobs
Browse these categories
Market data for security engineer roles
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.