Sr. Application Security Engineer

45 minutes ago
Full-time
Senior
Cybersecurity
Mitek Systems

Mitek Systems

Mitek Systems develops and provides mobile capture and identity verification software solutions that enable enterprises to securely verify user identities and facilitate transactions through mobile devices, enhancing customer experiences while preventi...

Communications Equipment
251-1K
Founded 1985

Description

  • Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs.
  • Work with development squads to explain findings, validate fixes, and confirm remediation.
  • Drive systemic root-cause fixes and escalate unresolved critical and high findings.
  • Define and own the secure development lifecycle, including security gates and review checkpoints.
  • Configure, tune, and operationalize SAST, DAST, and SCA tools to produce actionable output.
  • Embed security requirements into product planning and architecture decisions.
  • Threat-model new features and architectural changes before code is written.
  • Review authentication, authorization, data-flow, and cryptographic risks in designs.
  • Produce written threat models for developer guidance and audit evidence.
  • Own API security standards such as OAuth 2.0, mTLS, rate limiting, and abuse prevention.
  • Conduct or coordinate manual secure code reviews of security-sensitive components.
  • Lead application penetration-testing cycles, including scoping, tester management, and finding validation.
  • Build and run a Security Champions program across development squads.
  • Deliver developer security training on OWASP Top 10 and secure-coding patterns.
  • Create runbooks, coding standards, and pattern libraries developers can use independently.

Requirements

  • 5–8 years of experience in application/product security or security-focused software engineering.
  • Experience with application penetration testing, including business-logic and API testing.
  • Hands-on experience tuning and operationalizing SAST, DAST, and SCA.
  • Secure code review experience across at least two web-application languages.
  • Threat modeling experience using STRIDE, PASTA, or equivalent methods.
  • Strong knowledge of OWASP Top 10 and API security risks, with the ability to influence development teams.
  • Experience in financial services, fintech, or SaaS for regulated industries (preferred).
  • Knowledge of financial-sector threats such as fraud, account takeover, and API abuse (preferred).
  • Cloud-native application security, including container security, is preferred.
  • Understanding of PCI-DSS application security requirements is preferred.
  • OSCP, GWEB, or CSSLP certification is preferred.
  • Prior experience building a Security Champions program is preferred.

Benefits

  • Ownership of the AppSec function with clear scope and executive visibility.
  • Work on internet-facing financial software with complex API integrations in a US/EU regulatory context.
  • Direct collaboration with the VP of IT and Security and engineering leadership.
  • A security-minded development team that is open to partnership.
  • A proactive security program investing from a position of strength.
  • Competitive, equitable compensation and benefits programs.
  • Universal, supplemental, and private healthcare plan choices.
  • Retirement/pension contributions and MTK stock plan participation.
  • Generous annual leave, company holidays, and volunteer time off.
  • Learning benefits including an e-learning license, tuition reimbursement, and hackathons.
  • Home office setup allowance.
  • Optional benefits such as pet insurance, identity theft protection, and legal assistance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Product Security Engineer

Action1 11-50 Internet Software & Services

Action1 is seeking a Product Security Engineer to help secure its multi-tenant SaaS platform by partnering with engineering, product, and security teams to identify risks early and strengthen secure development practices.

AWS C++ Cybersecurity DevSecOps JavaScript Network Security Penetration Testing
30 minutes ago

Manager, Product Security Engineering

Dragos 251-1K Professional Services

Dragos is hiring a Manager, Product Security Engineering to lead a working security team securing critical infrastructure products while driving compliance, remediation, and certification work.

Agile AWS Azure CI/CD Cybersecurity GCP
45 minutes ago

DevSecOps

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring an Application Security Engineer (DevSecOps) to embed security across its cloud-based software development lifecycle and help R&D teams deliver secure applications at scale.

Agile AWS CI/CD DevSecOps Docker Go Java Kubernetes Microservices Network Security Python Terraform
2 days, 23 hours ago

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
6 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers