← All verified jobs

Sr. Application Security Engineer

mitek systems United StatesRemote

See all open roles at mitek systems

Ghost-risk verdict

Likely real

  • 11 open roles at this company in 30 days (mass-hiring blitz)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

What You’ll Do (Essential Responsibilities)

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Vulnerability Remediation

Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs

Work with development squads to explain findings, validate fixes, and confirm remediation

Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs

Secure Development Lifecycle

Define and own the SDLC — security gates and review checkpoints in sprint and release processes

Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output

Embed security requirements into product planning and architecture decisions

Threat Modeling & Secure Design

Threat-model new features and architectural changes before code is written

Review designs for authentication, authorization, data-flow, and cryptographic risk

Produce written threat models that serve as developer guidance and audit evidence

API Security & Secure Code Review

Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention

Conduct or coordinate manual secure code review of security-sensitive components

Lead application penetration-testing cycles — scoping, managing testers, validating findings

Developer Enablement

Build and run a Security Champions program across development squads

Deliver developer security training on OWASP Top 10 and secure-coding patterns

Create runbooks, coding standards, and pattern libraries developers can apply independently

This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.

Managerial Responsibilities

Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)

What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)

Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering

Application penetration testing including business-logic and API testing

Hands-on SAST, DAST, and SCA tuning and operationalization

Secure code review across at least two web-application languages

Threat modeling using STRIDE, PASTA, or equivalent

Depth in OWASP Top 10 and API security risks; ability to influence development teams

What Would be Nice (Preferred Skills & Experience)

Financial services, fintech, or SaaS for regulated industries

Financial-sector threat knowledge — fraud, account takeover, API abuse

Cloud-native application security including container security

PCI-DSS application security requirements

OSCP, GWEB, or CSSLP

Prior experience building a Security Champions program

Success Metrics -First Year

Remediation plan for all critical/high findings within 30 days

Critical/high remediation above 90% within SLA by month six

Threat modeling applied to all major new features within 90 days

Security Champions program launched (1+ per squad) within six months

SAST and DAST tuned and developer-actionable within 60 days

What we Offer

Ownership of the AppSec function with clear scope and executive visibility

A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context

Direct collaboration with the VP of IT and Security and Engineering leadership

A development team that is receptive to security partnership rather than treating it as an external constraint

A security program investing proactively from a position of strength — not reactive, not in crisis

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.