Sr. Application Security Engineer
$130k - $190kMitek
Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at
We are Virtual 1st!Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”
At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it. We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.
The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.
This is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.
The role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.
Why this role now
Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.
This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.
.
\n What You’ll Do (Essential Responsibilities)Hands-On Application Security Engineering
- Perform hands-on security analysis of applications, services, APIs, and supporting components.
- Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
- Conduct manual secure code reviews of security-sensitive components and application changes.
- Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
- Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.
Vulnerability Validation & Remediation
- Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
- Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
- Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
- Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
- Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
- Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.
Secure Development Lifecycle
- Help define and mature security gates and review checkpoints throughout the SDLC.
- Embed security requirements into architecture, design, sprint, and release processes.
- Integrate preventative security controls into developer workflows and CI/CD pipelines.
- Partner with Engineering to make secure development practices practical and scalable.
SAST, DAST & Software Composition Analysis
- Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
- Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
- Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
- Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
- Improve security automation and feedback within CI/CD workflows.
Threat Modeling & Secure Design
- Threat-model new features and significant architectural changes before code is written.
- Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
- Use methodologies such as STRIDE, PASTA, or equivalent approaches.
- Translate threat-model findings into practical engineering requirements and security controls.
API & Cloud-Native Security
- Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
- Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
- Evaluate application security risks across distributed services and cloud-native architectures.
Developer Enablement
- Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
- Provide developers with clear, actionable remediation guidance.
- Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
- Help develop and mature a Security Champions program across development teams.
- Create runbooks, standards, and secure-development patterns teams can use independently.
Application Security Testing
- Validate application and API vulnerabilities through hands-on testing when needed.
- Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
- Hands-on application or API penetration-testing experience is strongly preferred.
- 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline.
- Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
- Strong hands-on coding and secure code review experience in Java, Python, and Go.
- Ability to read, debug, and reason about production application code and communicate effectively with software engineers.
- Ability to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
- Hands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows.
- Strong knowledge of software dependency and supply-chain security.
- Experience prioritizing vulnerabilities using application and business context rather than scanner severity alone.
- Strong understanding of OWASP Top 10 and OWASP API Security risks.
- Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
- Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
- Strong communication skills and the ability to influence developers, architects, and engineering leadership.
- Hands-on application and API penetration-testing experience.
- Financial services, fintech, identity, fraud, or regulated SaaS experience.
- Experience with PCI-DSS application security requirements.
- Experience building or leading a Security Champions program.
- Experience developing AppSec automation or internal security tooling.
- OSCP, GWEB, CSSLP, or similar technical security certification.
- Establish trusted working relationships across Security and Engineering.
- Improve the quality and actionability of SAST, DAST, and SCA findings.
- Ensure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs.
- Apply threat modeling consistently to major new features and architectural changes.
- Reduce recurring vulnerability classes through upstream controls and secure development patterns.
- Improve software dependency and supply-chain security practices.
- Help launch and mature a Security Champions program across development teams.
- Strengthen the overall technical credibility and effectiveness of Mitek’s Application Security function.
- Ownership of the AppSec function with clear scope and executive visibility
- A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
- Direct collaboration with the VP of IT and Security and Engineering leadership
- A development team that is receptive to security partnership rather than treating it as an external constraint
- A security program investing proactively from a position of strength — not reactive, not in crisis
We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters. Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities.
Benefit offerings – may vary based on geographic location
Wellness : Universal, supplemental, and private healthcare plan choices based on country specifics
Financial future : retirement/pension plan contributions, MTK stock plan participation
Income protection: life event & disability coverage
Paid time off : generous annual leave, company holidays, volunteer time off
Learning : e-learning license, tuition reimbursement, hackathons
Home office setup allowance
Additional/optional benefits : pet insurance, identity theft protection, legal assistance
We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!
$125k - $160k
...for focusing on the implementation and maintenance of the application security program across research, development, quality assurance, support... ...code reviews, and security testing Work closely with engineering and product teams to design and implement security-related...SeniorFull timeCurrently hiringRemote work$93.6k - $157.56k
Overview As someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative... ...technology-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping...Senior$104.3k - $193.7k
...success and offer an inclusive and collaborative culture where your voice is valued. We are seeking an experienced Senior Application Security Engineer to join our team in the corporate travel industry. This remote position requires a unique blend of application...SeniorFull timeImmediate startRemote workFlexible hours$170k - $235k
...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets and spacecraft to deploy Starlink, the world’s most...SeniorPermanent employmentTemporary workWork at officeWorldwideMonday to FridayFlexible hoursWeekend work$98k - $146k
...technologies in support of U.S. National Security and Defense. For the past forty-five... ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will... ...an immediate opportunity for a talented engineer to support our programs delivering Next-...SeniorTemporary workFor contractorsWork experience placementImmediate startRemote workFlexible hours$192k - $240k
...support you need to grow your career. Engineering at Brex Engineering at Brex is... ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy... .... What you’ll do As a Senior Application Security Engineer, you will focus on...SeniorWork experience placementRemote work- ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has... ...ABOUT THE ROLE We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across...SeniorWork at officeRemote workWork from homeVisa sponsorshipWork visa
- ...Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to...SeniorFull timeLocal areaRemote workFlexible hoursShift work
$140k - $200k
...offering a wide range of simple, reliable, and secure crypto products and services to... ..., reach, and impact. The Department: Application Security Gemini operates at the intersection... ...The Role: Senior Application Security Engineer As a Senior Application Security...SeniorWork at officeRemote workFlexible hours$169k - $220k
...lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team,...SeniorWork experience placementWork at officeRemote workFlexible hours$200k - $235k
...Senior Security Application EngineerSan Francisco, California, United StatesBitGo is the leading infrastructure provider of digital asset solutions... ...-solving.We are seeking a Senior Application Security Engineer to lead the technical execution of our product security strategy...SeniorFull timeWork at officeWorldwide$143k - $183k
...Senior Application Security Engineer Forward Financing is a financial technology company based in Boston, Massachusetts with team members throughout the United States, Dominican Republic, and Canada. The company is on a mission to unlock the capital that fuels small...SeniorWork at officeRemote workWork from homeFlexible hours$160.3k - $240.5k
...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top... ...of creators and their users. We are seeking a Senior Application Security Engineer with profound expertise in application security. In this...SeniorWork at officeRemote workWorldwide$109k - $156k
...providing a level of professionalism and service unsurpassed in the lending industry. Position Summary The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled...SeniorMinimum wageWork at officeLocal areaRemote workWork from homeMonday to FridayShift work$190k - $237k
...and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and...SeniorRemote workWorldwideFlexible hours- ...About the Opportunity Our SRE/Cloud Security teams are a dynamic blend of proactive... ...mitigation strategies, and empower engineering teams through clear guidance and practical... ...design process. Perform and support application security assessments, including...SeniorContract workWork at officeLocal areaRemote workRelocationHome officeFlexible hours
$165k - $200k
...Responsibilities Provide hands-on technical security guidance to software developers... ...into technical requirements. Train engineers on secure coding practices, security standards... ..., including at least one year in application security or performing security tasks in...SeniorFull timeWork at office3 days per week$125k - $145k
...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across...SeniorFull timeRemote work- ...Educate and train development teams on secure coding practices and emerging security... ...prioritize remediation, and partner with engineering to address authentication,... ...At least 4 years of experience as an Application Security Engineer or Product Security Engineer...SeniorFull timeWork at officeImmediate start3 days per week
- ...Senior Application Security Engineer with Hands on Python Location- Princeton, NJ & NYC, NY (Hybrid) We need a candidate with hands on Python automation and good exp in AI/ML & LLM 8-15+ years in software engineering and application security, with substantial...SeniorFull time
- Estée Lauder Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration... ...and partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat modeling,...Senior
- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...Senior
$170k - $225k
...Responsibilities Penetrate the web application, APIs, infrastructure, Android application... ...cloud, and identity-focused offensive security assessments. Conduct purple-team... ...including support for phishing and social-engineering assessments. Document findings with...SeniorFull timeWork at officeImmediate start3 days per week- ...Responsibilities Own security tooling and vulnerability management across SAST, dependency... ...a security champions practice. Set application security standards, define secure... ...~5+ years of experience in software engineering or security, including 3+ years in application...SeniorFull timeTemporary workWork at officeRemote workMonday to Friday
$118.65k - $166.1k
...Cyber Defense, Application Security Engineer III Location – Irvine, CA Company Overview Hyundai AutoEver America (HAEA) , the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate,...SeniorFull timeWork experience placementLocal area$125k - $145k
...direct impact on our success. We're invested in your growth because when you grow, so do we. About the Job: The Senior Application Security Engineer reports to the Chief Information Security Officer (CISO) and works directly with the software development and production...SeniorLocal areaRemote work- ...Facebook , Instagram , X and YouTube. Job Description Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software development...SeniorFull timeLocal area
$111k - $144.4k
...The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies...SeniorFull timeTemporary workWork experience placementRemote work$67.3 - $78.2 per hour
Senior Application Security Engineer Our client, a diversified financial services company providing banking and investing services, is seeking a Senior Application Security Engineer for a 6 month contract role located in Jacksonville, FL. This role is fully onsite. Position...SeniorContract work- ...making a difference through technology. Job Description The Application Security program defines, promotes, assures, and measures the... ...technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead resource for the...SeniorFull timeWork at officeShift workNight shiftWeekend workAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Application Security Engineer. Be the first to apply!
- hydraulic application engineer United States
- application system engineer United States
- junior application support engineer United States
- application engineer United States
- application performance engineer United States
- network applications engineer United States
- project application engineer United States
- application support engineer United States
- application operations engineer United States
- senior application support engineer United States


