wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/Application Security Engineer Role(56)/Mitek Systems (1) - Sr. Application Security Engineer
Pro members applied to this job 36 hours before you saw itGet Pro ›
Mitek Systems

Mitek Systems - Sr. Application Security Engineer

Remote - UK$130k - $190k4d ago
RemoteSeniorEMEAFintechSoftwareApplication Security EngineerManaging DirectorProgram ManagementPhoenix

Requirements

• Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering • Application penetration testing including business-logic and API testing • Hands-on SAST, DAST, and SCA tuning and operationalization • Secure code review across at least two web-application languages • Threat modeling using STRIDE, PASTA, or equivalent • Depth in OWASP Top 10 and API security risks; ability to influence development teams • What Would be Nice (Preferred Skills & Experience) • Financial services, fintech, or SaaS for regulated industries • Financial-sector threat knowledge — fraud, account takeover, API abuse • Cloud-native application security including container security • PCI-DSS application security requirements • OSCP, GWEB, or CSSLP • Prior experience building a Security Champions program • Success Metrics -First Year • Remediation plan for all critical/high findings within 30 days • Critical/high remediation above 90% within SLA by month six • Threat modeling applied to all major new features within 90 days • Security Champions program launched (1+ per squad) within six months • SAST and DAST tuned and developer-actionable within 60 days

Responsibilities

• To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. • Vulnerability Remediation • Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs • Work with development squads to explain findings, validate fixes, and confirm remediation • Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs • Secure Development Lifecycle • Define and own the SDLC — security gates and review checkpoints in sprint and release processes • Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output • Embed security requirements into product planning and architecture decisions • Threat Modeling & Secure Design • Threat-model new features and architectural changes before code is written • Review designs for authentication, authorization, data-flow, and cryptographic risk • Produce written threat models that serve as developer guidance and audit evidence • API Security & Secure Code Review • Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention • Conduct or coordinate manual secure code review of security-sensitive components • Lead application penetration-testing cycles — scoping, managing testers, validating findings • Build and run a Security Champions program across development squads • Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount)

Benefits

• The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly. • Ownership of the AppSec function with clear scope and executive visibility • A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context • Direct collaboration with the VP of IT and Security and Engineering leadership • A development team that is receptive to security partnership rather than treating it as an external constraint • A security program investing proactively from a position of strength — not reactive, not in crisis • $130,000 - $190,000 a year • We are proud to offer competitive salary ranges aligned to industry standards. Please note that our ranges are representative and individual compensation specifics may vary based upon experience level, professional competencies and geographic differentials. • We take pride in enabling career growth in an environment of innovation and teamwork. Our commitment to all Mitekians is to do meaningful work that matters. Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes. We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities. • Benefit offerings – may vary based on geographic location • Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics • Financial future: retirement/pension plan contributions, MTK stock plan participation • Income protection: life event & disability coverage • Paid time off: generous annual leave, company holidays, volunteer time off • Learning: e-learning license, tuition reimbursement, hackathons • Additional/optional benefits: pet insurance, identity theft protection, legal assistance • We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further! • We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

BugcrowdBugcrowd - Application Security Engineer II5mo ago
·Remote - UK
RemoteEMEAMidPublic SectorApplication Security EngineerProgram ManagementLinuxPhoenix
SolidgateSolidgate - Application Security Engineer6mo ago
·Warsaw, Poland
In OfficeEMEAMidFintechPaymentsApplication Security EngineerSoftware EngineerPhoenixAppDynamicsClose
Thought MachineThought Machine - Senior Application Security Engineer1mo ago
·Lisbon, Portugal·€80k - €105k/year
In OfficeEMEASeniorCloud ComputingSoftwareApplication Security EngineerGoJavaPythonPerformance ReviewsAWS
igaminghuntigaminghunt - Application Security Engineer5d ago
·Hybrid - Europe *
In OfficeEMEACloud ComputingSoftwareApplication Security EngineerPythonShellPerformance ReviewsJavaScriptTypeScriptTerraformHelmDockerIstioKubernetesAWS
CAISCAIS - Lead Application Security Engineer1w ago
·London, England·Equity
In OfficeEMEAStaffCloud ComputingSoftwareApplication Security EngineerJavaJavaScriptAWSKotlinTypeScriptReactDocumentation
MoonPayMoonPay - Application Security Engineer5mo ago
·Remote - Portugal·$250k - $250k/year + Equity
RemoteEMEACryptocurrencyFintechApplication Security EngineerJavaScriptTypeScriptTraining DevelopmentCloudflareDocumentation
monarchmoneymonarchmoney - Senior Application Security Engineer1mo ago
·Remote - PT (Pacific)·$180k - $215k/year + Equity
RemoteNASeniorFintechCloud ComputingApplication Security EngineerRecruiterPythonPhoenixDjangoRisk AssessmentCPC
NinjaTraderNinjaTrader - Director, Technical Account Management1mo ago
·Remote - Chicago or Remote*·$165k - $165k/year
RemoteNADirectorFintechCloud ComputingSoftwareTechnical Account ManagerManaging DirectorTeam LeadershipAccount ManagementCustomer SuccessProgram ManagementTeam Management
Spring HealthSpring Health - Senior Application Security Engineer II1w ago
·Remote - USA·$180k - $206k/year
RemoteNASeniorDigital HealthCloud ComputingApplication Security EngineerGoRubyPythonJavaScriptDocumentationPerformance ReviewsRisk ManagementAWSAzureGCPCross-functional CollaborationPhoenixVector

Browse more by category

Show 56 moreApplication Security EngineerShow 50 moreManaging DirectorShow 855 moreProgram ManagementShow 133 morePhoenix
Privacy·Terms··Contact·FAQ·Wagey on X