Avatar for Mitek Systems
The global leader in mobile capture and digital identity verification software solutions
  • B2C
  • B2B
  • Public Stage
    Publicly traded company
  • +1

Sr. Application Security Engineer

Posted: 2 days ago• Recruiter recently active
Hires remotely in
Remote Work Policy

Remote only

Company Location
San Diego • 
London • 
Amsterdam • 
Paris • 
Barcelona • 
Saint Petersburg
Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
Java
Linux
Ubuntu
OAuth 2.0
AWS
Kubernetes
OWASP Top 10
mTLS
Go
OIDC
EKS
Stride
DAST
SAST
SCA
PASTA
OWASP API Security

About the job

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.

We are Virtual 1st! Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”

At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it. We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.

The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.

This is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.

The role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.

Why this role now

Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.

This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.

What You’ll Do (Essential Responsibilities)

Hands-On Application Security Engineering

  • Perform hands-on security analysis of applications, services, APIs, and supporting components
  • Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation
  • Conduct manual secure code reviews of security-sensitive components and application changes
  • Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions
  • Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes

Vulnerability Validation & Remediation

  • Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure
  • Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports
  • Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls
  • Work with development teams to explain findings, identify root cause, and determine the appropriate remediation
  • Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability
  • Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate

Secure Development Lifecycle

  • Help define and mature security gates and review checkpoints throughout the SDLC
  • Embed security requirements into architecture, design, sprint, and release processes
  • Integrate preventative security controls into developer workflows and CI/CD pipelines
  • Partner with Engineering to make secure development practices practical and scalable

SAST, DAST & Software Composition Analysis

  • Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings
  • Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings
  • Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options
  • Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls
  • Improve security automation and feedback within CI/CD workflows

Threat Modeling & Secure Design

  • Threat-model new features and significant architectural changes before code is written
  • Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios
  • Use methodologies such as STRIDE, PASTA, or equivalent approaches
  • Translate threat-model findings into practical engineering requirements and security controls

API & Cloud-Native Security

  • Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention
  • Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments
  • Evaluate application security risks across distributed services and cloud-native architectures

Developer Enablement

  • Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper
  • Provide developers with clear, actionable remediation guidance
  • Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns
  • Help develop and mature a Security Champions program across development teams
  • Create runbooks, standards, and secure-development patterns teams can use independently

Application Security Testing

  • Validate application and API vulnerabilities through hands-on testing when needed
  • Coordinate external penetration-testing engagements, validate reported findings, and drive remediation
  • Hands-on application or API penetration-testing experience is strongly preferred

What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)

  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation
  • Strong hands-on coding and secure code review experience in Java, Python, and Go
  • Ability to read, debug, and reason about production application code and communicate effectively with software engineers
  • Ability to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation
  • Hands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows
  • Strong knowledge of software dependency and supply-chain security
  • Experience prioritizing vulnerabilities using application and business context rather than scanner severity alone
  • Strong understanding of OWASP Top 10 and OWASP API Security risks
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments
  • Strong communication skills and the ability to influence developers, architects, and engineering leadership

What Would Be Nice (Preferred Skills & Experience)

  • Hands-on application and API penetration-testing experience
  • Financial services, fintech, identity, fraud, or regulated SaaS experience
  • Experience with PCI-DSS application security requirements
  • Experience building or leading a Security Champions program
  • Experience developing AppSec automation or internal security tooling
  • OSCP, GWEB, CSSLP, or similar technical security certification

Success Metrics -First Year

  • Establish trusted working relationships across Security and Engineering
  • Improve the quality and actionability of SAST, DAST, and SCA findings
  • Ensure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs
  • Apply threat modeling consistently to major new features and architectural changes
  • Reduce recurring vulnerability classes through upstream controls and secure development patterns
  • Improve software dependency and supply-chain security practices
  • Help launch and mature a Security Champions program across development teams
  • Strengthen the overall technical credibility and effectiveness of Mitek’s Application Security function

What We Offer

  • Ownership of the AppSec function with clear scope and executive visibility
  • A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  • Direct collaboration with the VP of IT and Security and Engineering leadership
  • A development team that is receptive to security partnership rather than treating it as an external constraint
  • A security program investing proactively from a position of strength — not reactive, not in crisis

We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters. Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities.

Benefit offerings – may vary based on geographic location

Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics

Financial future: retirement/pension plan contributions, MTK stock plan participation

Income protection: life event & disability coverage

Paid time off: generous annual leave, company holidays, volunteer time off

Learning: e-learning license, tuition reimbursement, hackathons

Home office setup allowance

Additional/optional benefits: pet insurance, identity theft protection, legal assistance

We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

About the company

Mitek Systems company logo
The global leader in mobile capture and digital identity verification software solutions501-1000 Employees
Company Size
501-1000
Company Type
SaaS
Company Type
Enterprise Software Company
Company Industries
B2B · SaaS · Mobile · Artificial Intelligence / Machine Learning
  • B2C
  • B2B
  • Public Stage
    Publicly traded company
  • 4.1
    Highly rated
    Mitek Systems is highly rated on Glassdoor, with 4.1 out of 5 stars
Learn more about Mitek Systems image

Funding

AMOUNT RAISED
$54K
FUNDED OVER
1 round
Round
S
$54113
Seed - Nov 2018

Perks

Medical, Dental, and Vision Insurance (United States)
401k with Employer Matching (US)
Maternity/Paternity Leave
Employee Stock Purchase Plan
Paid Time Off and Company Holidays

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives
Archesys company logo
Archesys
Improving the government services that impact everyday lives
Archesys company logo
Archesys
Improving the government services that impact everyday lives