Sr. Application Security Engineer at Mitek Systems
$130,000–$190,000
Jul 22, 2026
—
Jul 23, 2026
What this job asks for AI summary
An individual-contributor application security role embedded within a roughly 50-person engineering team building internet-facing banking and financial software. The position owns vulnerability remediation, shapes the secure development lifecycle (including SAST, DAST, and SCA tooling), conducts threat modeling, and leads API security standards. It also involves running a Security Champions program and representing the AppSec function in customer and regulatory engagements. Suited to someone with a background in application or product security and hands-on penetration testing experience.
Senior level · 5+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 450 people nationally plausibly meet what this posting asks for (information security analysts). range 95–680
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The title 'AppSec Engineer' carries no explicit seniority level, so the title states no level; the 5–8 year experience range and program-ownership scope support a Senior classification.
The role is explicitly an individual contributor ('Non-Manager') but leads a Security Champions program across development squads — this is technical/program leadership, not people management, so 15-1212 is retained over 11-3021.
15-1252 (Software Developers) is noted as a runner-up because the role requires hands-on secure code review across web-application languages and embeds deeply into the SDLC, but the primary day-to-day work is security analysis, vulnerability remediation, and threat modeling.
STRIDE and PASTA are listed as interchangeable threat-modeling methodologies in the requirements section ('STRIDE, PASTA, or equivalent'); STRIDE is used as the primary skill name with PASTA in alternatives.
OSCP, GWEB, and CSSLP appear under the 'What Would be Nice (Preferred Skills & Experience)' section and are treated as a single interchangeable certification requirement.
PCI-DSS and container security appear under 'What Would be Nice' and are preferred, not required.
No compensation figures are stated in the posting.
The company is headquartered in San Diego but explicitly operates as 'Virtual 1st,' making this a fully remote role; the CBSA reflects HQ location.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.