Skip to content
Monarch Money logo

Senior Application Security Engineer

Monarch MoneyPersonal Finance company
RemoteSenior
FPV Ventures
Forerunner Ventures logo
Forerunner Ventures
Menlo Ventures logo
Menlo Ventures
Accel logo
Accel
SignalFire logo
SignalFire
Clocktower Ventures
Software Engineering

About the role

TL;DR

Conduct application security reviews and improve AI security practices for Monarch's growing product.

  • Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth.
  • Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering teams
  • conducting application security reviews, executing on vulnerability management, and applying and improving our AppSec and AI security practices as Monarch scales.
  • Key Responsibilities Conduct application security reviews
  • threat modeling, code review, and risk assessment
  • for new features and major product changes across Monarch's Django/Python stack Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines Work through the vulnerability backlog with urgency
  • maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces
  • covering prompt injection, data leakage, model abuse, and supply chain risk Requirements 5+ years in security engineering with demonstrated depth in Application and AI security
  • threat modeling, SAST/DAST, secure code review, and vulnerability management Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns) Hands-on experience with application security tooling
  • Semgrep, Burp Suite, Nuclei, or equivalents Familiarity with AI/ML security risks
  • prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk Transformative AI fluency
  • actively uses AI tools to accelerate security work and build automation
View original posting →

Required skills

PythonOWASP

Nice-to-have skills

AWSIAMECSEKSSOC 2Penetration Testing

Domain expertise

fintech

Benefits & perks

Work wherever you want, Competitive cash and equity compensation, Stipend to set-up your ideal working environment, Competitive Benefit Plans, Unlimited PTO, 3 day weekend every month

Tech stack

PythonDjangoAWSIAMECSEKS

Similar jobs

A

Senior Fullstack Software Engineer

A

Software Engineer, Data Quality

A

Security Architect