About this Sr. Application Security Engineer role at Miteksystems
Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.
We are Virtual 1st! Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”
At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it. We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.
The Senior Application Security Engineer serves as a hands-on technical authority for the security of Mitek’s software products. This role bridges Information Security and Engineering, working directly with developers to identify, investigate, and remediate security weaknesses throughout the software development lifecycle.
This is a highly technical individual contributor role. The ideal candidate combines deep Application Security expertise with strong software engineering skills and is comfortable working directly in Java, Python, and Go codebases to trace vulnerabilities, understand root cause, assess exploitability, and partner with developers on secure remediation.
The role will help mature Mitek’s Secure SDLC, improve application security tooling and developer workflows, strengthen vulnerability remediation, and build preventative controls that reduce recurring security issues.
Why this role now
Mitek is continuing to mature its Application Security function from a position of strength. As our products, engineering organization, and threat landscape continue to evolve, we are investing proactively in the technical capabilities needed to secure internet-facing financial software and APIs.
This person will have significant ownership and visibility while remaining deeply hands-on with Engineering. The goal is not simply to identify vulnerabilities, but to understand them at the code level, help developers remediate them effectively, and build security into the development process so similar issues are prevented in the future.
.
What You’ll Do (Essential Responsibilities)
Hands-On Application Security Engineering
- Perform hands-on security analysis of applications, services, APIs, and supporting components.
- Work directly in Java, Python, and Go codebases to identify security weaknesses, understand root cause, and recommend practical remediation.
- Conduct manual secure code reviews of security-sensitive components and application changes.
- Partner directly with software engineers to troubleshoot vulnerabilities and develop secure solutions.
- Develop reusable secure coding patterns, controls, and automation that prevent recurring vulnerability classes.
- Own application vulnerability remediation from initial finding through validation, prioritization, remediation, retesting, and closure.
- Personally reproduce and validate vulnerabilities rather than relying solely on scanner severity or external reports.
- Assess actual application risk using factors such as exploitability, code reachability, application exposure, data sensitivity, business criticality, and compensating controls.
- Work with development teams to explain findings, identify root cause, and determine the appropriate remediation.
- Drive systemic fixes rather than repeatedly addressing individual instances of the same vulnerability.
- Maintain clear remediation SLAs and escalate unresolved Critical and High findings when appropriate.
- Help define and mature security gates and review checkpoints throughout the SDLC.
- Embed security requirements into architecture, design, sprint, and release processes.
- Integrate preventative security controls into developer workflows and CI/CD pipelines.
- Partner with Engineering to make secure development practices practical and scalable.
- Operate, configure, and tune SAST, DAST, and SCA tooling to produce actionable developer findings.
- Investigate scanner output and distinguish meaningful security risk from false positives and low-risk findings.
- Evaluate software dependency vulnerabilities using application context, including reachability, vulnerable-function usage, exploitability, and remediation options.
- Partner with developers on dependency upgrades, replacement strategies, exceptions, and compensating controls.
- Improve security automation and feedback within CI/CD workflows.
- Threat-model new features and significant architectural changes before code is written.
- Review designs for authentication, authorization, trust boundaries, data flows, cryptographic controls, and abuse scenarios.
- Use methodologies such as STRIDE, PASTA, or equivalent approaches.
- Translate threat-model findings into practical engineering requirements and security controls.
- Review application and API security controls including authentication, authorization, OAuth 2.0/OIDC, mTLS, rate limiting, and abuse prevention.
- Partner with teams building cloud-native applications in AWS, Kubernetes/EKS, containers, and Linux/Ubuntu environments.
- Evaluate application security risks across distributed services and cloud-native architectures.
- Build strong working relationships with Engineering and operate as a technical partner rather than a security gatekeeper.
- Provide developers with clear, actionable remediation guidance.
- Deliver secure-coding guidance and training based on real vulnerabilities and recurring patterns.
- Help develop and mature a Security Champions program across development teams.
- Create runbooks, standards, and secure-development patterns teams can use independently.
- Validate application and API vulnerabilities through hands-on testing when needed.
- Coordinate external penetration-testing engagements, validate reported findings, and drive remediation.
- Hands-on application or API penetration-testing experience is strongly preferred.
Vulnerability Validation & Remediation
Secure Development Lifecycle
SAST, DAST & Software Composition Analysis
Threat Modeling & Secure Design
API & Cloud-Native Security
Developer Enablement
Application Security Testing
What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
What Would be Nice (Preferred Skills & Experience)
Success Metrics -First Year
What we Offer
We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters. Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities.
Benefit offerings – may vary based on geographic location
Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics
Financial future: retirement/pension plan contributions, MTK stock plan participation
Income protection: life event & disability coverage
Paid time off: generous annual leave, company holidays, volunteer time off
Learning: e-learning license, tuition reimbursement, hackathons
Home office setup allowance
Additional/optional benefits: pet insurance, identity theft protection, legal assistance
We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further!