Senior Remote AppSec Engineer: Secure SDLC & API

Miteksystems 2

United States

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Home office setup allowance
Stock plan participation
Paid time off

Job summary

Mitek is seeking an AppSec Engineer to own remediation of findings and advance the secure development lifecycle across product teams. You will drive vulnerability remediation, threat modeling, and secure design reviews in a fast-paced environment focused on financial technology security.

Responsibilities include leading penetration testing cycles, embedding security into architecture decisions, and building the Security Champions program to raise developer awareness of OWASP Top 10 and secure

Qualifications

  • 5-8 years in application security or security-focused software engineering.
  • Experience with application penetration testing including API testing.
  • Hands-on SAST, DAST, and SCA tuning and operation.
  • Secure code review across multiple web languages.
  • Threat modeling using STRIDE or PASTA.
  • Knowledge of OWASP Top 10 and API security risks; ability to influence development teams.
  • Experience in financial services, fintech, or SaaS for regulated industries is a plus.
  • Cloud-native application security including container security.

Responsibilities

  • Own remediation of validated findings with prioritized SLAs and drive root-cause fixes.
  • Define and own the Secure Development Lifecycle security gates and review checkpoints.
  • Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable output.
  • Embed security requirements into product planning and architecture decisions.
  • Threat-model new features and architectural changes before code is written; review designs for authentication, authorization, data-flow, and cryptographic risk.
  • Lead API security standards—OAuth 2.0, mTLS, rate limiting—and oversee secure code review and pen-testing cycles.
  • Build and run a Security Champions program across development squads and deliver developer security training.
  • Collaborate with VP IT/Security and Engineering leadership; ensure proactive security investments.

Skills

Application security
Penetration testing
Threat modeling
OWASP Top 10
Secure SDLC
API security
Security champions

Education

OSCP
GWEB
CSSLP

Tools

SAST tooling
DAST tooling
SCA tooling

Job description

Mitek is seeking an AppSec Engineer to own remediation of findings and advance the secure development lifecycle across product teams. You will drive vulnerability remediation, threat modeling, and secure design reviews in a fast-paced environment focused on financial technology security.

Responsibilities include leading penetration testing cycles, embedding security into architecture decisions, and building the Security Champions program to raise developer awareness of OWASP Top 10 and secure

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AppSec Engineer: Threat Modeling & Secure SDLC
Senior AppSec Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Senior AppSec Engineer: AI-Driven Secure SDLC Lead
Senior AppSec Engineer: AI-Driven Secure SDLC Lead

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Hybrid App Security Engineer—Secure SDLC Leader
Hybrid App Security Engineer—Secure SDLC Leader

Packsize • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Lead Application Security Engineer: Threat Modeling & Secure SDLC
Lead Application Security Engineer: Threat Modeling & Secure SDLC

Mach7 Technologies • Burlington (VT), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote Application Security Engineer | Secure SDLC Expert
Remote Application Security Engineer | Secure SDLC Expert

Compu-Link • Austin (TX)

On-site
USD 115,000 - 130,000
Medical, dental, vision
Health Savings Account
401(k) with match
+2
Remote Application Security Engineer: Strengthen the SDLC
Remote Application Security Engineer: Strengthen the SDLC

Bright-Vision-Technologies • United States

Remote
USD 85,000 - 105,000
AppSec Engineer I: Secure SDLC & Automation Lead
AppSec Engineer I: Secure SDLC & Automation Lead

Transaction Network Services (TNS) • Town of Texas (WI)

On-site
USD 75,000 - 83,000
Medical and dental coverage
401K with company match
Paid holidays and vacations
AppSec Analyst I: SDLC Security & Automation
AppSec Analyst I: SDLC Security & Automation

Socket.dev • United States

Remote
USD 75,000 - 83,000
Medical & dental coverage
Life insurance
Paid holidays and vacations
+1
AppSec Engineer: Secure Web & Mobile Applications
AppSec Engineer: Secure Web & Mobile Applications

Socket.dev • United States

Remote
USD 107,000 - 147,000
Remote Web Security Engineer: DevSecOps for Federal Apps
Remote Web Security Engineer: DevSecOps for Federal Apps

careers-dminc • United States

On-site
USD 70,020 - 85,580