1

Appsec Engineer Jobs (NOW HIRING)

Sr. Application Security Engineer

$60.25 - $80.25/hr

The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program ...

About the Role As a Security Engineer, you will play a critical role in safeguarding our ... AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable ...

About the Role As a Security Engineer, you will play a critical role in safeguarding our ... AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable ...

About the Role As a Security Engineer, you will play a critical role in safeguarding our ... AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube * SecOps & Vulnerability: Tenable ...

AppSec Sales Engineer - East

Raleigh, NC · Remote

$57 - $76.25/hr

The AppSec Sales Engineer is the technical liaison who bridges sales and engineering, expertly articulating the technology and product positioning of our AI-Native DevSecOps platform to executive ...

Senior Product Manager, AppSec

Plano, TX · On-site

$121K - $159K/yr

Engineering Partnership: Act as the primary liaison to Security Engineering Enablement and ... Evangelize the AppSec mission through Office Hours and community forums; simplifying complex ...

AppSec Sales Engineer - East

Tampa, FL · Remote

$55.50 - $74.25/hr

The AppSec Sales Engineer is the technical liaison who bridges sales and engineering, expertly articulating the technology and product positioning of our AI-Native DevSecOps platform to executive ...

AppSec Sales Engineer

San Francisco, CA · Remote

$69.25 - $92.50/hr

Position Summary The AppSec Sales Engineer is the technical liaison who bridges sales and engineering, expertly articulating the technology and product positioning of our AI-Native DevSecOps platform ...

AppSec Security Engineer

Arlington, VA · On-site

$67.50 - $90.25/hr

Cybersecurity Engineering Manager Direct Reports: None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this ...

Engineering Manager, Application Security

Austin, TX · On-site

$58.25 - $77.75/hr

Responsibilities : • Lead and grow the Application Security team - coaching senior AppSec engineers, setting goals, and owning delivery against the security roadmap • Build the automated pen ...

AppSec Security Engineer

New York, NY

$64.25 - $86/hr

Cybersecurity Engineering Manager Direct Reports: None POSITION SUMMARY STATEMENT We are seeking an experienced Application Security Engineer to build, mature, and scale our AppSec program. In this ...

AppSec Sales Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Position Summary The AppSec Sales Engineer is the technical liaison who bridges sales and engineering, expertly articulating the technology and product positioning of our AI-Native DevSecOps platform ...

Senior Product Manager, AppSec

Mclean, VA · On-site

$127K - $168K/yr

Engineering Partnership: Act as the primary liaison to Security Engineering Enablement and ... Evangelize the AppSec mission through Office Hours and community forums; simplifying complex ...

Senior Product Manager, AppSec

New York, NY

$138K - $182K/yr

Engineering Partnership: Act as the primary liaison to Security Engineering Enablement and ... Evangelize the AppSec mission through Office Hours and community forums; simplifying complex ...

AppSec Sales Engineer East

Atlanta, GA · Remote

$56.50 - $75.50/hr

Position Summary The AppSec Sales Engineer is the technical liaison who bridges sales and engineering, expertly articulating the technology and product positioning of our AI-Native DevSecOps platform ...

Senior Product Manager, AppSec

Richmond, VA · On-site

$125K - $165K/yr

Engineering Partnership: Act as the primary liaison to Security Engineering Enablement and ... Evangelize the AppSec mission through Office Hours and community forums; simplifying complex ...

Senior Product Manager, AppSec

Mclean, VA

$127K - $168K/yr

Engineering Partnership: Act as the primary liaison to Security Engineering Enablement and ... Evangelize the AppSec mission through Office Hours and community forums; simplifying complex ...

Showing results 41-60

Appsec Engineer information

What does an AppSec engineer do?

An Application Security (AppSec) Engineer is responsible for ensuring the security of software applications by identifying and mitigating vulnerabilities throughout the software development lifecycle. They work closely with development teams to implement secure coding practices, perform code reviews, conduct security assessments, and respond to security incidents. Additionally, AppSec Engineers often use automated tools to scan for security flaws and help educate teams on the latest security threats and best practices.

What are the key skills and qualifications needed to thrive as an AppSec engineer?

To thrive as an AppSec Engineer, you need a solid understanding of application security principles, secure coding practices, and vulnerability assessment, typically supported by a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), OWASP frameworks, and certifications such as CISSP or OSCP is highly valued. Strong analytical thinking, problem-solving abilities, and effective communication skills help you collaborate across development and security teams. These skills are crucial for identifying, mitigating, and preventing security risks in software applications, thereby protecting organizational assets and user data.

What are some common challenges AppSec engineers face when collaborating with development teams?

Appsec Engineers often work closely with software developers to integrate security best practices into the development lifecycle. A common challenge is balancing security requirements with project timelines and feature delivery, as development teams may prioritize speed over thorough security reviews. Effective communication and the ability to educate colleagues about secure coding practices are essential for overcoming these challenges. Additionally, Appsec Engineers may need to adapt to various development methodologies, such as Agile or DevOps, which can impact how and when security is incorporated into projects.
More about Appsec Engineer jobs

What states have the most Appsec Engineer jobs?

States with the most job openings for Appsec Engineer jobs include:

Infographic showing various Appsec Engineer job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 2% Part Time, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution.

Sr. Application Security Engineer

Mitek Systems

Charleston, WV • Remote

$130K - $190K/yr

Full-time

Posted 29 days ago


Job description

Mitek (NASDAQ: MITK) is a global leader in digital & biometric identity authentication, fraud prevention, and mobile deposit solutions. Our verified identity platform and advanced image capture solutions are built on the latest advancements in biometric recognition, artificial intelligence, computer vision and machine learning, and trusted by over 7,500 organizations worldwide. We are headquartered in San Diego, California, with operations in the United Kingdom, Spain, France, Mexico, and the Netherlands. Visit us at www.miteksystems.com.

We are Virtual 1st! Whether you choose to work remotely from your home office or in-person from one of Mitek’s offices, our practices, processes and tools are designed to enable your success. At Mitek, the Future of Work is about flexibility and preference wherever and whenever we are working. Because we care about our candidates, employees and customers, we include an in-person meeting as part of our hiring process. It’s one of the ways we live our mission to “Protect What’s Real.”

At Mitek, we believe that teams are more resilient, effective, and innovative when they benefit from a wide range of ideas, lived experiences, and perspectives. The strength of our organization is deeply rooted in the people who power it.​ We know that a workforce reflecting the richness of our communities and customers helps us better serve their needs.


This person will be the company's technical authority on the security of its software products. Bridges Information Security and Engineering — embedding security into the SDLC for a ~50-person development team building internet-hosted banking and financial software. Owns the vulnerability remediation program, builds upstream controls that prevent vulnerabilities, and serves as the AppSec authority in customer and regulatory engagements. The company invests from a position of strength — a recent penetration test returned zero findings — ahead of an expected rise in AI-assisted vulnerabilities targeting the financial sector. 

Why this role now 

The company is maturing its application security function from a position of strength — a recent penetration test returned zero findings — and is investing ahead of an expected increase in AI-assisted vulnerabilities targeting the financial sector. The AppSec Engineer joins with a clear mandate: own remediation of validated findings, build the secure development lifecycle that prevents future vulnerabilities, and establish the AppSec program credibility that banking customers and their regulators increasingly audit directly. 

What You’ll Do (Essential Responsibilities)

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. 

 Vulnerability Remediation 

  • Own the application vulnerability remediation program with prioritized developer guidance and clear SLAs 

  • Work with development squads to explain findings, validate fixes, and confirm remediation 

  • Drive systemic root-cause fixes rather than one-by-one patching; escalate unresolved criticals and highs 

Secure Development Lifecycle 

  • Define and own the SDLC — security gates and review checkpoints in sprint and release processes 

  • Ensure SAST, DAST, and SCA tooling is configured, tuned, and producing actionable developer output 

  • Embed security requirements into product planning and architecture decisions 

Threat Modeling & Secure Design 

  • Threat-model new features and architectural changes before code is written 

  • Review designs for authentication, authorization, data-flow, and cryptographic risk 

  • Produce written threat models that serve as developer guidance and audit evidence 

API Security & Secure Code Review 

  • Own API security standards — OAuth 2.0, mTLS, rate limiting, and abuse prevention 

  • Conduct or coordinate manual secure code review of security-sensitive components 

  • Lead application penetration-testing cycles — scoping, managing testers, validating findings 

Developer Enablement 

  • Build and run a Security Champions program across development squads 

  • Deliver developer security training on OWASP Top 10 and secure-coding patterns 

  • Create runbooks, coding standards, and pattern libraries developers can apply independently 

 This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time. 

Managerial Responsibilities 

  • Non-Manager: No oversight or accountability for others, an individual contributor, however, leads Security Champions program across development squads (developer-embedded, not security headcount) 

What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
  • Knowledge, skills and abilities typically gained through 5–8 years in application/product security or security-focused software engineering
  • Application penetration testing including business-logic and API testing
  • Hands-on SAST, DAST, and SCA tuning and operationalization
  • Secure code review across at least two web-application languages
  • Threat modeling using STRIDE, PASTA, or equivalent
  • Depth in OWASP Top 10 and API security risks; ability to influence development teams 
What Would be Nice (Preferred Skills & Experience)
  • Financial services, fintech, or SaaS for regulated industries
  • Financial-sector threat knowledge — fraud, account takeover, API abuse
  • Cloud-native application security including container security
  • PCI-DSS application security requirements
  • OSCP, GWEB, or CSSLP
  • Prior experience building a Security Champions program 
Success Metrics -First Year
  • Remediation plan for all critical/high findings within 30 days
  • Critical/high remediation above 90% within SLA by month six
  • Threat modeling applied to all major new features within 90 days
  • Security Champions program launched (1+ per squad) within six months
  • SAST and DAST tuned and developer-actionable within 60 days 
What we Offer
  • Ownership of the AppSec function with clear scope and executive visibility
  • A technically interesting attack surface — internet-facing financial software, complex API integrations, and a dual US/EU regulatory context
  • Direct collaboration with the VP of IT and Security and Engineering leadership
  • A development team that is receptive to security partnership rather than treating it as an external constraint
  • A security program investing proactively from a position of strength — not reactive, not in crisis 
We are proud to offer competitive salary ranges aligned to industry standards. Please note that our ranges are representative and individual compensation specifics may vary based upon experience level, professional competencies and geographic differentials. 

We take pride in enabling career growth in an environment of innovation and teamwork.  Our commitment to all Mitekians is to do meaningful work that matters.  Our culture is defined by delivering our best to our customers by providing high value solutions and impactful outcomes, by continuously challenging convention, and by caring for each other through collaboration and celebrating our successes.  We are committed to creating competitive, equitable compensation & benefits programs and career development opportunities. 

Benefit offerings – may vary based on geographic location

Wellness: Universal, supplemental, and private healthcare plan choices based on country specifics 

Financial future: retirement/pension plan contributions, MTK stock plan participation  

Income protection: life event & disability coverage 

Paid time off: generous annual leave, company holidays, volunteer time off 

Learning: e-learning license, tuition reimbursement, hackathons 

Home office setup allowance

Additional/optional benefits: pet insurance, identity theft protection, legal assistance 

We sincerely appreciate your interest in Mitek. We know your time is valuable and look forward to the potential of speaking with you further! 

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.