Sr. Application Security Engineer
See all open roles at mitek systems →
Likely real
- 11 open roles at this company in 30 days (mass-hiring blitz)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
What You’ll Do (Essential Responsibilities)
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Vulnerability Remediation
Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs
Work with development squads to explain findings, validate fixes, and confirm remediation
Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs
Secure Development Lifecycle
Define and own the SDLC — security gates and review checkpoints in sprint and release processes
Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output
Embed security requirements into product planning and architecture decisions
Threat Modeling & Secure Design
Threat-model new features and architectural changes before code is written
Review designs for authentication, authorization, data-flow, and cryptographic risk
Produce written threat models that serve as developer guidance and audit evidence
API Security & Secure Code Review
Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention
Conduct or coordinate manual secure code review of security-sensitive components
Lead application penetration-testing cycles — scoping, managing testers, validating findings
Developer Enablement
Build and run a Security Champions program across development squads
Deliver developer security training on OWASP Top 10 and secure-coding patterns
Create runbooks, coding standards, and pattern libraries developers can apply independently
This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.
Managerial Responsibilities
Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)
What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering
Application penetration testing including business-logic and API testing
Hands-on SAST, DAST, and SCA tuning and operationalization
Secure code review across at least two web-application languages
Threat modeling using STRIDE, PASTA, or equivalent
Depth in OWASP Top 10 and API security risks; ability to influence development teams
What Would be Nice (Preferred Skills & Experience)
Financial services, fintech, or SaaS for regulated industries
Financial-sector threat knowledge — fraud, account takeover, API abuse
Cloud-native application security including container security
PCI-DSS application security requirements
OSCP, GWEB, or CSSLP
Prior experience building a Security Champions program
Success Metrics -First Year
Remediation plan for all critical/high findings within 30 days
Critical/high remediation above 90% within SLA by month six
Threat modeling applied to all major new features within 90 days
Security Champions program launched (1+ per squad) within six months
SAST and DAST tuned and developer-actionable within 60 days
What we Offer
Ownership of the AppSec function with clear scope and executive visibility
A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
Direct collaboration with the VP of IT and Security and Engineering leadership
A development team that is receptive to security partnership rather than treating it as an external constraint
A security program investing proactively from a position of strength — not reactive, not in crisis
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot