Sr. Application Security Engineer

    United States
    Full-Time
    Senior (7+ yrs)
    IT & Security
    Posted on July 23, 2026
    This person will be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50-person development team building internet-hosted banking and financial software. Owns the vulnerability remediation program, builds upstream controls that prevent vulnerabilities, and serves as the AppSec authority in customer and regulatory engagements. The company invests from a position of strength — a recent penetration test returned zero findings — ahead of an expected rise in AI-assisted vulnerabilities targeting the financial sector.

    Why this role now

    The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly.

    What You’ll Do (Essential Responsibilities)

    To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

    Vulnerability Remediation

    • Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs

    • Work with development squads to explain findings, validate fixes, and confirm remediation

    • Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs

    Secure Development Lifecycle

    • Define and own the SDLC — security gates and review checkpoints in sprint and release processes

    • Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output

    • Embed security requirements into product planning and architecture decisions

    Threat Modeling & Secure Design

    • Threat-model new features and architectural changes before code is written

    • Review designs for authentication, authorization, data-flow, and cryptographic risk

    • Produce written threat models that serve as developer guidance and audit evidence

    API Security & Secure Code Review

    • Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention

    • Conduct or coordinate manual secure code review of security-sensitive components

    • Lead application penetration-testing cycles — scoping, managing testers, validating findings

    Developer Enablement

    • Build and run a Security Champions program across development squads

    • Deliver developer security training on OWASP Top 10 and secure-coding patterns

    • Create runbooks, coding standards, and pattern libraries developers can apply independently

    This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.

    Managerial Responsibilities

    • Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)

    What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
  1. Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering
  2. Application penetration testing including business-logic and API testing
  3. Hands-on SAST, DAST, and SCA tuning and operationalization
  4. Secure code review across at least two web-application languages
  5. Threat modeling using STRIDE, PASTA, or equivalent
  6. Depth in OWASP Top 10 and API security risks; ability to influence development teams
  7. What Would be Nice (Preferred Skills & Experience)
  8. Financial services, fintech, or SaaS for regulated industries
  9. Financial-sector threat knowledge — fraud, account takeover, API abuse
  10. Cloud-native application security including container security
  11. PCI-DSS application security requirements
  12. OSCP, GWEB, or CSSLP
  13. Prior experience building a Security Champions program
  14. Success Metrics -First Year
  15. Remediation plan for all critical/high findings within 30 days
  16. Critical/high remediation above 90% within SLA by month six
  17. Threat modeling applied to all major new features within 90 days
  18. Security Champions program launched (1+ per squad) within six months
  19. SAST and DAST tuned and developer-actionable within 60 days
  20. What we Offer
  21. Ownership of the AppSec function with clear scope and executive visibility
  22. A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  23. Direct collaboration with the VP of IT and Security and Engineering leadership
  24. A development team that is receptive to security partnership rather than treating it as an external constraint
  25. A security program investing proactively from a position of strength — not reactive, not in crisis
  26. Company:  Mitek Systems

    Develops advanced identity verification technologies and global platform for digital access and fraud prevention.
    Remote-First Company
    501-1000 employees
    Software & IT Services
    HQ: United States