Sr. Application Security Engineer

Mitek Systems
$130,000 - $190,000Hybrid

About The Position

This person will be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50-person development team building internet-hosted banking and financial software. Owns the vulnerability remediation program, builds upstream controls that prevent vulnerabilities, and serves as the AppSec authority in customer and regulatory engagements. The company invests from a position of strength — a recent penetration test returned zero findings — ahead of an expected rise in AI-assisted vulnerabilities targeting the financial sector. Why this role now The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly.

Requirements

  • 5–8 years in application/product security or security-focused software engineering
  • Application penetration testing including business-logic and API testing
  • Hands-on SAST, DAST, and SCA tuning and operationalization
  • Secure code review across at least two web-application languages
  • Threat modeling using STRIDE, PASTA, or equivalent
  • Depth in OWASP Top 10 and API security risks; ability to influence development teams

Nice To Haves

  • Financial services, fintech, or SaaS for regulated industries
  • Financial-sector threat knowledge — fraud, account takeover, API abuse
  • Cloud-native application security including container security
  • PCI-DSS application security requirements
  • OSCP, GWEB, or CSSLP
  • Prior experience building a Security Champions program

Responsibilities

  • Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs
  • Work with development squads to explain findings, validate fixes, and confirm remediation
  • Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs
  • Define and own the SDLC — security gates and review checkpoints in sprint and release processes
  • Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output
  • Embed security requirements into product planning and architecture decisions
  • Threat-model new features and architectural changes before code is written
  • Review designs for authentication, authorization, data-flow, and cryptographic risk
  • Produce written threat models that serve as developer guidance and audit evidence
  • Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention
  • Conduct or coordinate manual secure code review of security-sensitive components
  • Lead application penetration-testing cycles — scoping, managing testers, validating findings
  • Build and run a Security Champions program across development squads
  • Deliver developer security training on OWASP Top 10 and secure-coding patterns
  • Create runbooks, coding standards, and pattern libraries developers can apply independently

Benefits

  • Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics
  • Financial future: retirement/pension plan contributions, MTK stock plan participation
  • Income protection: life event & disability coverage
  • Paid time off: generous annual leave, company holidays, volunteer time off
  • Learning: e-learning license, tuition reimbursement, hackathons
  • Home office setup allowance
  • Additional/optional benefits: pet insurance, identity theft protection, legal assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service