Monarch

Senior Application Security Engineer

Monarch

Remote · Full Time

Be the first to apply

Experience
5+ yrs
Salary
Openings
1
Posted
2 weeks ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Monarch

Monarch is an all-encompassing personal finance platform launched in 2021, designed to simplify financial management and alleviate stress for its users. Our mission is to help members focus on what matters most by transforming how personal finances are handled through innovative solutions and AI integration across all functions.

Operating fully remotely, our team spans various locations and collaborates mainly during 9 AM to 2 PM PT, leveraging asynchronous communication to connect efficiently across time zones.

Role Overview

We are looking for a Senior Application Security Engineer to join our rapidly expanding Security Engineering team. Reporting to the Head of Engineering Infrastructure, you will be deeply involved in application security efforts, collaborating closely with product and engineering teams to conduct thorough security reviews, manage vulnerabilities, and advance security practices in both traditional application and AI-integrated environments.

Responsibilities

  • Carry out comprehensive application security evaluations including threat modeling, secure code reviews, and risk assessments for new features and significant product changes within our Django/Python codebase.
  • Manage and enhance static and dynamic application security testing (SAST/DAST) processes, handling triage, validation, and remediation tracking within CI/CD pipelines.
  • Prioritize and work through existing vulnerabilities, updating triage criteria and tracking fixes while collaborating with engineering teams on escalations.
  • Coordinate and perform penetration testing and security assessments covering web and API endpoints.
  • Implement and refine security review procedures specifically for AI features that involve large language models and agentic systems, addressing risks like prompt injection, data leakage, exploitation, and supply chain threats.
  • Develop and maintain security automation tools, especially those powered by AI, and define security requirements for AI-driven workflows and agentic architectures.
  • Participate actively in the weekly security on-call rotation to address emerging issues.

Qualifications

  • Minimum 5 years of experience in security engineering with extensive expertise in application and AI security, including threat modeling, SAST/DAST, secure code reviews, and vulnerability management.
  • Strong proficiency in Python and in-depth knowledge of web application security concepts such as OWASP Top 10 risks, API security, and authentication/authorization patterns.
  • Hands-on use of security tools like Semgrep, Burp Suite, Nuclei, or their equivalents.
  • Understanding of AI/ML security vulnerabilities, including prompt injection, model abuse, agentic threat surfaces, and supply chain concerns related to large language models.
  • Demonstrated fluency in leveraging AI tools to enhance security workflows and automation.

Preferred Skills

  • Experience working in fintech or securing financial data environments.
  • Familiarity with regulatory and compliance standards such as SOC 2 or NIST Cybersecurity Framework.
  • Knowledge of cloud security practices, especially AWS-related services like IAM, container security, ECS, and EKS.
  • Relevant industry certifications including OSCP, BSCP, CSSLP, CISSP, or similar credentials.
  • Background in detection engineering, incident response, or offensive security techniques such as red teaming and bug bounty participation beyond typical web or API testing.

Hiring Process

  • Initial recruiter video interview
  • Technical interview with hiring manager
  • Take-home assignment
  • Virtual onsite interviews comprising 2 to 4 rounds
  • Reference verifications
  • Offer extended upon successful completion

Benefits

  • Complete remote work flexibility allowing you to choose your preferred workspace.
  • Competitive salary and equity packages typical of a fast-growing early-stage company.
  • Reimbursement for setting up an ideal home office environment.
  • Location-based employee benefit plans, including medical, dental, and vision insurance in applicable regions and access to retirement plans such as a 401(k) in the US.
  • Unlimited paid time off to support work-life balance.
  • Monthly three-day weekends by taking the first Friday off to encourage rest and rejuvenation.

Equal Opportunity Employment

We are firmly committed to diversity and inclusion, offering equal opportunities regardless of race, religion, national origin, gender identity or expression, sexual orientation, age, marital status, veteran status, disability, or genetic information.

Applicant Notices

Compliance with fair chance employment laws in California and San Francisco ensures consideration for candidates with prior arrest or conviction records.

Level

Senior

🤖
Online · instant AI help
Broxer