{"id":955289,"url":"https://alion.io/job/mitek-systems-sr-application-security-engineer","title":"Sr. Application Security Engineer","company":{"id":680208,"name":"Mitek Systems","domain":"miteksystems.com","url":"https://alion.io/company/miteksystems","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Lever","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":{"min":130000,"max":190000,"currency":"USD","period":"year","gross":null,"usd_annual":190000},"salary_estimate":null,"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Amazon EKS","optional":false},{"name":"AWS","optional":false},{"name":"CI/CD","optional":false},{"name":"Go","optional":false},{"name":"Java","optional":false},{"name":"Kubernetes","optional":false},{"name":"Linux","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"STRIDE","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Ubuntu","optional":false},{"name":"PCI DSS","optional":true}],"status":"live","first_seen_at":"2026-07-23T00:30:26Z","employer_posted_date":"2026-07-23","last_verified_at":"2026-10-04T02:19:38Z","board_verified":true,"closed_at":null,"days_open":73,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":73},"description":"The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.\nThis is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.\nThe role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.\nWhy this role now\nMitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.\nThis person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.\n.\nWhat You’ll Do (Essential Responsibilities)\nHands-On Application Security Engineering\nPerform hands-on security analysis of applications, services, APIs, and supporting components.\nWork directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.\nConduct manual secure code reviews of security-sensitive components and application changes.\nPartner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.\nDevelop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.\nVulnerability Validation & Remediation\nOwn application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.\nPersonally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.\nAssess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.\nWork with development teams to explain findings, identify root cause, and determine the appropriate remediation.\nDrive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.\nMaintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.\nSecure Development Lifecycle\nHelp define and mature security gates and review checkpoints throughout the SDLC.\nEmbed security requirements into architecture, design, sprint, and release processes.\nIntegrate preventative security controls into developer workflows and CI/CD pipelines.\nPartner with Engineering to make secure development practices practical and scalable.\nSAST, DAST & Software Composition Analysis\nOperate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.\nInvestigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.\nEvaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.\nPartner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.\nImprove security automation and feedback within CI/CD workflows.\nThreat Modeling & Secure Design\nThreat-model new features and significant architectural changes before code is written.\nReview designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.\nUse methodologies such as STRIDE, PASTA, or equivalent approaches.\nTranslate threat-model findings into practical engineering requirements and security controls.\nAPI & Cloud-Native Security\nReview application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.\nPartner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.\nEvaluate application security risks across distributed services and cloud-native architectures.\nDeveloper Enablement\nBuild strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.\nProvide developers with clear, actionable remediation guidance.\nDeliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.\nHelp develop and mature a Security Champions program across development teams.\nCreate runbooks, standards, and secure-development patterns teams can use independently.\nApplication Security Testing\nValidate application and API vulnerabilities through hands-on testing when needed.\nCoordinate external penetration-testing engagements, validate reported findings, and drive remediation.\nHands-on application or API penetration-testing experience is strongly preferred.\nWhat You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)\n7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline.\nDemonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.\nStrong hands-on coding and secure code review experience in Java, Python, and Go.\nAbility to read, debug, and reason about production application code and communicate effectively with software engineers.\nAbility to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.\nHands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows.\nStrong knowledge of software dependency and supply-chain security.\nExperience prioritizing vulnerabilities using application and business context rather than scanner severity alone.\nStrong understanding of OWASP Top 10 and OWASP API Security risks.\nExperience with threat modeling using STRIDE, PASTA, or similar methodologies.\nExperience securing cloud-native applications running in AWS and Kubernetes/EKS environments.\nStrong communication skills and the ability to influence developers, architects, and engineering leadership.\nWhat Would be Nice (Preferred Skills & Experience)\nHands-on application and API penetration-testing experience.\nFinancial services, fintech, identity, fraud, or regulated SaaS experience.\nExperience with PCI-DSS application security requirements.\nExperience building or leading a Security Champions program.\nExperience developing AppSec automation or internal security tooling.\nOSCP, GWEB, CSSLP, or similar technical security certification.\nSuccess Metrics -First Year\nEstablish trusted working relationships across Security and Engineering.\nImprove the quality and actionability of SAST, DAST, and SCA findings.\nEnsure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs.\nApply threat modeling consistently to major new features and architectural changes.\nReduce recurring vulnerability classes through upstream controls and secure development patterns.\nImprove software dependency and supply-chain security practices.\nHelp launch and mature a Security Champions program across development teams.\nStrengthen the overall technical credibility and effectiveness of Mitek’s Application Security function.\nWhat we Offer\nOwnership of the AppSec function with clear scope and executive visibility\nA technically interesting attack surface - internet-facing financial software, complex API integrations, and a dual US/EU regulatory context\nDirect collaboration with the VP of IT and Security and Engineering leadership\nA development team that is receptive to security partnership rather than treating it as an external constraint\nA security program investing proactively from a position of strength - not reactive, not in crisis","description_format":"text","description_chars":8541,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Artificial Intelligence","Cybersecurity","Fraud Detection"],"lifecycle":[{"event":"open","at":"2026-09-16T04:44:11Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 6","filings_12m":6,"filings_prev_12m":5,"green_card_filings_12m":0,"median_offered_wage_usd":142500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":0}],"liveness":{"score":23,"band":"cold","label":"Long shot","p_open":1,"p_active":0.646,"p_room":0.36,"age_days":72,"expected_fill_days":41,"reasons":["conf:14","win:tail","crowd:"],"computed_at":"2026-10-03T05:45:00Z"},"pay":{"stated_usd_annual":190000,"is_top_pay":true},"html_url":"https://alion.io/job/mitek-systems-sr-application-security-engineer","json_url":"https://alion.io/job/mitek-systems-sr-application-security-engineer.json","meta":{"generated_at":"2026-10-04T02:42:23Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4015,"day_limit":5000,"remaining_today":985,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}