Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Application Security Engineer

$130k - $190k

Mitek

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at 

We are Virtual 1st!Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”

At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it.​ We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.

The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.

This is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.

The role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.

Why this role now 

Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.

This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.

\n What You’ll Do (Essential Responsibilities)

Hands-On Application Security Engineering

  • Perform hands-on security analysis of applications, services, APIs, and supporting components.
  • Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
  • Conduct manual secure code reviews of security-sensitive components and application changes.
  • Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
  • Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.

Vulnerability Validation & Remediation

  • Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
  • Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
  • Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
  • Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
  • Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
  • Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.

Secure Development Lifecycle

  • Help define and mature security gates and review checkpoints throughout the SDLC.
  • Embed security requirements into architecture, design, sprint, and release processes.
  • Integrate preventative security controls into developer workflows and CI/CD pipelines.
  • Partner with Engineering to make secure development practices practical and scalable.

SAST, DAST & Software Composition Analysis

  • Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
  • Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
  • Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
  • Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
  • Improve security automation and feedback within CI/CD workflows.

Threat Modeling & Secure Design

  • Threat-model new features and significant architectural changes before code is written.
  • Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
  • Use methodologies such as STRIDE, PASTA, or equivalent approaches.
  • Translate threat-model findings into practical engineering requirements and security controls.

API & Cloud-Native Security

  • Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
  • Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
  • Evaluate application security risks across distributed services and cloud-native architectures.

Developer Enablement

  • Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
  • Provide developers with clear, actionable remediation guidance.
  • Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
  • Help develop and mature a Security Champions program across development teams.
  • Create runbooks, standards, and secure-development patterns teams can use independently.

Application Security Testing

  • Validate application and API vulnerabilities through hands-on testing when needed.
  • Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
  • Hands-on application or API penetration-testing experience is strongly preferred.
What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
  • 7+ years of progressive experience in Application Security, Product Security, security-focused software engineering, or a closely related discipline.
  • Demonstrated senior-level ownership of Application Security initiatives and vulnerability remediation.
  • Strong hands-on coding and secure code review experience in Java, Python, and Go.
  • Ability to read, debug, and reason about production application code and communicate effectively with software engineers.
  • Ability to independently reproduce vulnerabilities, trace findings to root cause, assess exploitability and reachability, and validate remediation.
  • Hands-on experience with SAST, DAST, and SCA tooling and integrating security testing into engineering workflows.
  • Strong knowledge of software dependency and supply-chain security.
  • Experience prioritizing vulnerabilities using application and business context rather than scanner severity alone.
  • Strong understanding of OWASP Top 10 and OWASP API Security risks.
  • Experience with threat modeling using STRIDE, PASTA, or similar methodologies.
  • Experience securing cloud-native applications running in AWS and Kubernetes/EKS environments.
  • Strong communication skills and the ability to influence developers, architects, and engineering leadership.
What Would be Nice (Preferred Skills & Experience)
  • Hands-on application and API penetration-testing experience.
  • Financial services, fintech, identity, fraud, or regulated SaaS experience.
  • Experience with PCI-DSS application security requirements.
  • Experience building or leading a Security Champions program.
  • Experience developing AppSec automation or internal security tooling.
  • OSCP, GWEB, CSSLP, or similar technical security certification.
Success Metrics -First Year
  • Establish trusted working relationships across Security and Engineering.
  • Improve the quality and actionability of SAST, DAST, and SCA findings.
  • Ensure Critical and High application vulnerabilities are appropriately prioritized and remediated within agreed SLAs.
  • Apply threat modeling consistently to major new features and architectural changes.
  • Reduce recurring vulnerability classes through upstream controls and secure development patterns.
  • Improve software dependency and supply-chain security practices.
  • Help launch and mature a Security Champions program across development teams.
  • Strengthen the overall technical credibility and effectiveness of Mitek’s Application Security function.
What we Offer
  • Ownership of the AppSec function with clear scope and executive visibility
  • A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  • Direct collaboration with the VP of IT and Security and Engineering leadership
  • A development team that is receptive to security partnership rather than treating it as an external constraint
  • A security program investing proactively from a position of strength — not reactive, not in crisis 
\n$130,000 - $190,000 a year We are proud to offer competitive salary ranges aligned to industry standards. Please note that our ranges are representative and individual compensation specifics may vary based upon experience level, professional competencies and geographic differentials. \n

We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters. Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities. 

Benefit offerings – may vary based on geographic location

Wellness : Universal, supplemental, and private healthcare plan choices based on country specifics 

Financial future : retirement/pension plan contributions, MTK stock plan participation

Income protection: life event & disability coverage 

Paid time off : generous annual leave, company holidays, volunteer time off 

Learning : e-learning license, tuition reimbursement, hackathons 

Home office setup allowance

Additional/optional benefits : pet insurance, identity theft protection, legal assistance 

We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. Application Security Engineer in United States vacancy
  • $125k - $160k

     ...for focusing on the implementation and maintenance of the application security program across research, development, quality assurance, support...  ...code reviews, and security testing Work closely with engineering and product teams to design and implement security-related... 
    Senior
    Full time
    Currently hiring
    Remote work

    Henry Schein One

    Remote
    6 days ago
  • $93.6k - $157.56k

    Overview As someone experienced with securing a wide variety of applications, you are looking for an opportunity to use your skills in an innovative...  ...technology-oriented environment. As an Application Security Engineer at Esri, you will fill a critical role in helping... 
    Senior

    Esri

    Vienna, VA
    17 days ago
  • $104.3k - $193.7k

     ...success and offer an inclusive and collaborative culture where your voice is valued. We are seeking an experienced Senior Application Security Engineer to join our team in the corporate travel industry. This remote position requires a unique blend of application... 
    Senior
    Full time
    Immediate start
    Remote work
    Flexible hours

    American Express Global Business Travel

    Tallahassee, FL
    4 days ago
  • $170k - $235k

     ...is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SR. APPLICATION SECURITY ENGINEER At SpaceX we’re leveraging our experience in building rockets and spacecraft to deploy Starlink, the world’s most... 
    Senior
    Permanent employment
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours
    Weekend work

    SpaceX

    Redmond, WA
    4 days ago
  • $98k - $146k

     ...technologies in support of U.S. National Security and Defense. For the past forty-five...  ...require U.S. citizenship for all employees. Applicants that do not meet this requirement will...  ...an immediate opportunity for a talented engineer to support our programs delivering Next-... 
    Senior
    Temporary work
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Flexible hours

    SciTec

    Princeton, NJ
    29 days ago
  • $192k - $240k

     ...support you need to grow your career. Engineering at Brex Engineering at Brex is...  ...intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy...  .... What you’ll do As a Senior Application Security Engineer, you will focus on... 
    Senior
    Work experience placement
    Remote work

    Brex

    United States
    4 days ago
  •  ...across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has...  ...ABOUT THE ROLE We are looking for a Senior Application Security Engineer to strengthen secure coding and DevSecOps practices across... 
    Senior
    Work at office
    Remote work
    Work from home
    Visa sponsorship
    Work visa

    AgileEngine

    United States
    1 day ago
  •  ...Premium and maintain $1.21 billion in surplus.Amerisure is hiring!! This role can sit remote. We’re looking for a Senior Application Security Engineer who can take ownership of security initiatives, shape our strategy, and partner closely with engineering teams to... 
    Senior
    Full time
    Local area
    Remote work
    Flexible hours
    Shift work

    Amerisure Insurance

    United States
    1 day ago
  • $140k - $200k

     ...offering a wide range of simple, reliable, and secure crypto products and services to...  ..., reach, and impact. The Department: Application Security Gemini operates at the intersection...  ...The Role: Senior Application Security Engineer As a Senior Application Security... 
    Senior
    Work at office
    Remote work
    Flexible hours

    Gemini

    United States
    3 days ago
  • $169k - $220k

     ...lower cost through early diagnosis and longitudinal care management of chronic conditions. We are looking for a Senior Application Security Engineer to break Counterpart Assistant before anyone else does. This is a hands-on offensive security role on our Eng Core team,... 
    Senior
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Counterpart Health

    United States
    3 days ago
  • $200k - $235k

     ...Senior Security Application EngineerSan Francisco, California, United StatesBitGo is the leading infrastructure provider of digital asset solutions...  ...-solving.We are seeking a Senior Application Security Engineer to lead the technical execution of our product security strategy... 
    Senior
    Full time
    Work at office
    Worldwide

    BitGo, Inc.

    San Francisco, CA
    2 days ago
  • $143k - $183k

     ...Senior Application Security Engineer Forward Financing is a financial technology company based in Boston, Massachusetts with team members throughout the United States, Dominican Republic, and Canada. The company is on a mission to unlock the capital that fuels small... 
    Senior
    Work at office
    Remote work
    Work from home
    Flexible hours

    Forward Financing

    United States
    19 hours ago
  • $160.3k - $240.5k

     ...architecture, retail, energy, and government. Our Product Security team keeps that platform, and the software built on top...  ...of creators and their users. We are seeking a Senior Application Security Engineer with profound expertise in application security. In this... 
    Senior
    Work at office
    Remote work
    Worldwide

    Unity Technologies

    United States
    2 days ago
  • $109k - $156k

     ...providing a level of professionalism and service unsurpassed in the lending industry. Position Summary The Senior Application Security Engineer at Guild Mortgage will play a lead role in strengthening the security of our applications, including AI-enabled... 
    Senior
    Minimum wage
    Work at office
    Local area
    Remote work
    Work from home
    Monday to Friday
    Shift work

    Guild Mortgage

    United States
    2 days ago
  • $190k - $237k

     ...and counts the former President and COO of Hubspot, JD Sherman, among its board members. Role Overview The Senior Application Security Engineer is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and... 
    Senior
    Remote work
    Worldwide
    Flexible hours

    Apollo Inc

    United States
    2 days ago
  •  ...About the Opportunity Our SRE/Cloud Security teams are a dynamic blend of proactive...  ...mitigation strategies, and empower engineering teams through clear guidance and practical...  ...design process.  Perform and support application security assessments, including... 
    Senior
    Contract work
    Work at office
    Local area
    Remote work
    Relocation
    Home office
    Flexible hours

    MoonPay

    United States
    3 days ago
  • $165k - $200k

     ...Responsibilities Provide hands-on technical security guidance to software developers...  ...into technical requirements. Train engineers on secure coding practices, security standards...  ..., including at least one year in application security or performing security tasks in... 
    Senior
    Full time
    Work at office
    3 days per week

    Heartflow

    San Francisco, CA
    3 days ago
  • $125k - $145k

     ...This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Application Security Engineer based in the United States. This role offers the opportunity to strengthen application security across... 
    Senior
    Full time
    Remote work

    jobgether

    United States
    2 days ago
  •  ...Educate and train development teams on secure coding practices and emerging security...  ...prioritize remediation, and partner with engineering to address authentication,...  ...At least 4 years of experience as an Application Security Engineer or Product Security Engineer... 
    Senior
    Full time
    Work at office
    Immediate start
    3 days per week

    Altruist

    Los Angeles, CA
    9 days ago
  •  ...Senior Application Security Engineer with Hands on Python Location- Princeton, NJ & NYC, NY (Hybrid) We need a candidate with hands on Python automation and good exp in AI/ML & LLM 8-15+ years in software engineering and application security, with substantial... 
    Senior
    Full time

    Purple Hires Inc

    New York, NY
    3 days ago
  • Estée Lauder Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration...  ...and partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat modeling,... 
    Senior

    Estée Lauder Companies

    New York, NY
    3 days ago
  • The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software... 
    Senior

    The Estée Lauder Companies Inc.

    New York, NY
    2 days ago
  • $170k - $225k

     ...Responsibilities Penetrate the web application, APIs, infrastructure, Android application...  ...cloud, and identity-focused offensive security assessments. Conduct purple-team...  ...including support for phishing and social-engineering assessments. Document findings with... 
    Senior
    Full time
    Work at office
    Immediate start
    3 days per week

    Altruist

    Los Angeles, CA
    9 days ago
  •  ...Responsibilities Own security tooling and vulnerability management across SAST, dependency...  ...a security champions practice. Set application security standards, define secure...  ...~5+ years of experience in software engineering or security, including 3+ years in application... 
    Senior
    Full time
    Temporary work
    Work at office
    Remote work
    Monday to Friday

    CharterUP

    Austin, TX
    17 days ago
  • $118.65k - $166.1k

     ...Cyber Defense, Application Security Engineer III   Location – Irvine, CA Company Overview   Hyundai AutoEver America (HAEA) , the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate,... 
    Senior
    Full time
    Work experience placement
    Local area

    Hyundai Autoever America

    Irvine, CA
    7 days ago
  • $125k - $145k

     ...direct impact on our success. We're invested in your growth because when you grow, so do we. About the Job:  The Senior Application Security Engineer reports to the Chief Information Security Officer (CISO) and works directly with the software development and production... 
    Senior
    Local area
    Remote work

    Radicle Health

    Chicago, IL
    3 days ago
  •  ...Facebook ,  Instagram ,  X and  YouTube. Job Description Become a key player in our Information Security team as a Senior Application Security Engineer, where you will leverage your expertise in application security, security engineering, and software development... 
    Senior
    Full time
    Local area

    AbbVie Inc.

    Irvine, CA
    a month ago
  • $111k - $144.4k

     ...The Sr. Application Security Engineer is responsible for validating that application services are designed and implemented with high security standards. The role analyzes the security of applications in tandem with their underlying services, including connected dependencies... 
    Senior
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital | CubiCasa | restb.ai

    Remote
    11 days ago
  • $67.3 - $78.2 per hour

    Senior Application Security Engineer Our client, a diversified financial services company providing banking and investing services, is seeking a Senior Application Security Engineer for a 6 month contract role located in Jacksonville, FL. This role is fully onsite. Position... 
    Senior
    Contract work

    Corps Team

    Jacksonville, FL
    4 days ago
  •  ...making a difference through technology. Job Description The Application Security program defines, promotes, assures, and measures the...  ...technical member of the team, the Senior Application Security Engineer serves as an expert-level specialist and lead resource for the... 
    Senior
    Full time
    Work at office
    Shift work
    Night shift
    Weekend work
    Afternoon shift

    CITY OF NEW YORK INC

    Brooklyn, NY
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Application Security Engineer. Be the first to apply!