Monarch Money logo
Monarch Money·

Senior Application Security Engineer - Monarch Money

About Us

Monarch is a powerful, all-in-one personal finance platform designed to make the complexity of finances feel simple again. Since launching in 2021, we've become the top-recommended personal finance app by users and experts.

As a fully remote company, we welcome applicants from almost anywhere in the US and Canada. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones.

The Role

Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering teams—conducting application security reviews, executing on vulnerability management, and applying and improving our AppSec and AI security practices as Monarch scales.

What You'll Do

  • Conduct application security reviews — threat modeling, code review, and risk assessment — for new features and major product changes across Monarch's Django/Python stack.
  • Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines.
  • Work through the vulnerability backlog with urgency — maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads.
  • Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces.
  • Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces — covering prompt injection, data leakage, model abuse, and supply chain risk.
  • Build and maintain security automations and AI-powered tooling, and define and assess security requirements for AI workflows and agentic systems.
  • Participate in the weekly security on-call rotation.

What You'll Bring

  1. 5+ years in security engineering with demonstrated depth in Application and AI security — threat modeling, SAST/DAST, secure code review, and vulnerability management.
  2. Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns).
  3. Hands-on experience with application security tooling — Semgrep, Burp Suite, Nuclei, or equivalents.
  4. Familiarity with AI/ML security risks — prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk.
  5. Transformative AI fluency — actively uses AI tools to accelerate security work and build automation.

Nice to Haves

  • Experience in fintech or with financial data security requirements.
  • Familiarity with SOC 2, NIST CSF, or similar compliance frameworks.
  • Cloud security experience (AWS preferred) — IAM, container security, ECS/EKS.
  • Relevant certifications: OSCP, BSCP, CSSLP, CISSP, or equivalent.
  • Detection engineering and incident response experience.
  • Additional offensive security experience — red teaming, bug bounty, or broader penetration testing beyond web/API surfaces.

Benefits

  • Work wherever you want! Fully remote company with no central office.
  • Competitive cash and equity compensation.
  • Stipend to set up your ideal working environment.
  • Competitive benefit plans based on your location (e.g., US medical, dental, vision, and 401k).
  • Unlimited PTO.
  • 3-day weekend every month (take off the "First Friday" every month).

Timezone overlap

UTC-8–-4

Culture

Async-friendly

Open to

NA

Sign in to track applications and earn points.

More roles at Monarch Money

Similar remote roles