WFH.teamOpen app
Back to remote jobs
Remote job detail

Sr. Application Security Engineer

Mitek Systems

LocationUnited States
Senioritysenior
CompanyMitek Systems
Fresh sinceJul 24
Compensation

$130k-$190k

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Skills and signals
APICloudComputeDataGoOperationsPlatformProductReactRustSaasSecurityremote
Job description

Sr. Application Security Engineer at Mitek Systems

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. com.

We are Virtual 1st! Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process.

” At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. ​ We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs. This person will be the company's technical authority on the security of its software products.

Bridges Information Security and Engineering — embedding security into the SDLC for a ~50-person development team building internet-hosted banking and financial software. Owns the vulnerability remediation program, builds upstream controls that prevent vulnerabilities, and serves as the AppSec authority in customer and regulatory engagements.

The company invests from a position of strength — a recent penetration test returned zero findings — ahead of an expected rise in AI-assisted vulnerabilities targeting the financial sector. Why this role now The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector.

The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly. We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters.

Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable

Compensation

&

Benefits

programs and career development opportunities.

Benefit offerings – may vary based on geographic location Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics Financial future: retirement/pension plan contributions, MTK stock plan participation Income protection: life event & disability coverage Paid time off: generous annual leave, company holidays, volunteer time off Learning: e-learning license, tuition reimbursement, hackathons Home office setup allowance Additional/optional

Benefits

: pet insurance, identity theft protection, legal assistance We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!

What you’ll do

(Essential

Responsibilities

) To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The

Requirements

listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Vulnerability Remediation Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs Work with development squads to explain findings, validate fixes, and confirm remediation Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs Secure Development Lifecycle Define and own the SDLC — security gates and review checkpoints in sprint and release processes Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output Embed security

Requirements

0, mTLS, rate limiting, and abuse prevention Conduct or coordinate manual secure code review of security-sensitive components Lead application penetration-testing cycles — scoping, managing testers, validating findings Developer Enablement Build and run a Security Champions program across development squads Deliver developer security training on OWASP Top 10 and secure-coding patterns Create runbooks, coding standards, and pattern libraries developers can apply independently This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and

Responsibilities

to this job at any time. Managerial

Responsibilities

Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount) What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities) Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering Application penetration testing including business-logic and API testing Hands-on SAST, DAST, and SCA tuning and operationalization Secure code review across at least two web-application languages Threat modeling using STRIDE, PASTA, or equivalent Depth in OWASP Top 10 and API security risks; ability to influence development teams What Would be Nice (Preferred Skills & Experience) Financial services, fintech, or SaaS for regulated industries Financial-sector threat knowledge — fraud, account takeover, API abuse Cloud-native application security including container security PCI-DSS application security

Requirements

com. Department: Global Depts. ATS provider: Lever. Salary: USD 130000-190000 per-year-salary.

Sr. Application Security Engineer at Mitek Systems - Remote Job | WFH.team