964,952open jobs
58,250companies
159,771added this week
Browse all
Salary
$130k – $190k per year
Location
Remote (United States)
Seniority
Senior · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Jul 23, 2026.

Overview
Company
Impact
Profile match
Know your customers, verify transactions, and securely grow your business with identity verification and authentication in a single platform.

The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.

This is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.

The role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.

Why this role now

Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.

This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.

.

What You’ll Do (Essential Responsibilities)

    Hands-On Application Security Engineering

    • Perform hands-on security analysis of applications, services, APIs, and supporting components.
    • Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
    • Conduct manual secure code reviews of security-sensitive components and application changes.
    • Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
    • Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.
    • Vulnerability Validation & Remediation

      • Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
      • Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
      • Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
      • Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
      • Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
      • Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.
      • Secure Development Lifecycle

        • Help define and mature security gates and review checkpoints throughout the SDLC.
        • Embed security requirements into architecture, design, sprint, and release processes.
        • Integrate preventative security controls into developer workflows and CI/CD pipelines.
        • Partner with Engineering to make secure development practices practical and scalable.
        • SAST, DAST & Software Composition Analysis

          • Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
          • Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
          • Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
          • Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
          • Improve security automation and feedback within CI/CD workflows.
          • Threat Modeling & Secure Design

            • Threat-model new features and significant architectural changes before code is written.
            • Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
            • Use methodologies such as STRIDE, PASTA, or equivalent approaches.
            • Translate threat-model findings into practical engineering requirements and security controls.
            • API & Cloud-Native Security

              • Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
              • Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
              • Evaluate application security risks across distributed services and cloud-native architectures.
              • Developer Enablement

                • Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
                • Provide developers with clear, actionable remediation guidance.
                • Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
                • Help develop and mature a Security Champions program across development teams.
                • Create runbooks, standards, and secure-development patterns teams can use independently.
                • Application Security Testing

                  • Validate application and API vulnerabilities through hands-on testing when needed.
                  • Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
                  • Hands-on application or API penetration-testing experience is strongly preferred.

What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)

  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline.
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong hands-on coding and secure code review experience in Java, Python, and Go.
  • Ability to read, debug, and reason about production application code and communicate effectively with software engineers.
  • Ability to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
  • Hands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows.
  • Strong knowledge of software dependency and supply-chain security.
  • Experience prioritizing vulnerabilities using application and business context rather than scanner severity alone.
  • Strong understanding of OWASP Top 10 and OWASP API Security risks.
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Strong communication skills and the ability to influence developers, architects, and engineering leadership.

What Would be Nice (Preferred Skills & Experience)

  • Hands-on application and API penetration-testing experience.
  • Financial services, fintech, identity, fraud, or regulated SaaS experience.
  • Experience with PCI-DSS application security requirements.
  • Experience building or leading a Security Champions program.
  • Experience developing AppSec automation or internal security tooling.
  • OSCP, GWEB, CSSLP, or similar technical security certification.

Success Metrics -First Year

  • Establish trusted working relationships across Security and Engineering.
  • Improve the quality and actionability of SAST, DAST, and SCA findings.
  • Ensure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs.
  • Apply threat modeling consistently to major new features and architectural changes.
  • Reduce recurring vulnerability classes through upstream controls and secure development patterns.
  • Improve software dependency and supply-chain security practices.
  • Help launch and mature a Security Champions program across development teams.
  • Strengthen the overall technical credibility and effectiveness of Mitek’s Application Security function.

What we Offer

  • Ownership of the AppSec function with clear scope and executive visibility
  • A technically interesting attack surface - internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  • Direct collaboration with the VP of IT and Security and Engineering leadership
  • A development team that is receptive to security partnership rather than treating it as an external constraint
  • A security program investing proactively from a position of strength - not reactive, not in crisis
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
964,952 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
$91k per year • Remote (likely Germany) • Full-Time • 5+ years exp
Python
PowerShell
AI/ML
Prompt Engineering
LLM
EU AI Act
DevOps
GCP
Azure
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
NIST CSF
OWASP Top 10
Zero Trust
Microsoft Entra ID
Active Directory
PKI
SIEM
Apply
$130k – $152k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Atlanta
Cybersecurity
Crowdstrike
Qualys Cloud Platform
Microsoft Entra ID
SIEM
Apply
≈ $83k – $173k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Texarkana
DevOps
VMWare
Cybersecurity
Microsoft Entra ID
Management
ITIL
Apply
$160k – $180k per year • Remote (likely Sweden)
Python
PowerShell
DevOps
Azure
AWS
Cybersecurity
Qualys Cloud Platform
ISO 27001
Microsoft Defender
Zero Trust
PKI
SIEM
Apply
≈ $117k – $212k per year (Estimated) • Remote (United States) • Full-Time • 6+ years exp • Bachelor's Degree • United States
AI/ML
Copilot
Claude
DevOps
Terraform
Ansible
Azure
CI/CD
AWS
DNS
VPN
Cybersecurity
FortiGate
MITRE ATT&CK
SOC 2
HIPAA
NIST 800-53
Zero Trust
SIEM
Apply
≈ $16k – $36k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
Python
PowerShell
Databases
Azure SQL Database
DevOps
Terraform
Azure DevOps
Azure
CI/CD
Git
Docker
Kubernetes
Bicep
Azure AKS
FinOps
Cybersecurity
SonarQube
Apply
Sr. DevOps Engineer 7 hours ago
≈ $16k – $35k per year (Estimated) • In office • 4+ years exp • Mumbai
DevOps
Terraform
Kibana
CloudFormation
CI/CD
AWS
Kubernetes
Grafana
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Apply
SDET 7 hours ago
≈ $13k – $32k per year (Estimated) • In office • 6+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
AI/ML
Embeddings
Multimodal AI
AI Agents
DeepEval
LLM
RAG
Hallucination
Semantic Search
Human-in-the-Loop
Semantic Search
DevOps
Azure DevOps
GitHub Actions
Azure
CI/CD
Shift-Left
Cybersecurity
Shift-Left Security
QA
Selenium
Cypress
Playwright
Pytest
Apply
≈ $13k – $38k per year (Estimated) • In office • Full-Time • Hanoi
Python
SQL
Python
SQLAlchemy
pySpark
Databases
MySQL
PostgreSQL
Cassandra
Apache Kafka
AI/ML
Hadoop
Spark
Pandas
Apply
≈ $20k – $50k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Rostov-on-Don
Python
C++
DevOps
Linux
Windows
Apply
$65k – $80k per year • Remote (United States) • Full-Time • 1+ year exp
Marketing
Salesforce
LinkedIn
Apply
$130k – $150k per year • Remote (United States) • Full-Time • 4+ years exp
SQL
AI/ML
Copilot
Human-in-the-Loop
Structured Outputs
Analytics
ETL/ELT
Marketing
Salesforce
LinkedIn
Apply
GTM Engineer 1 day ago
$130k – $150k per year • Remote (United States) • Full-Time • 4+ years exp
SQL
AI/ML
Human-in-the-Loop
Structured Outputs
Analytics
ETL/ELT
Marketing
Salesforce
LinkedIn
Apply
$34k per year • Remote (Netherlands) • Contractor • Amsterdam
Cybersecurity
GDPR
Apply
$100k – $135k per year • Remote (United States) • Full-Time
Apply
See all jobs
This is one of many
964,952 more open roles from verified company boards, updated every day.