Senior Application Security Engineer
Senior Application Security Engineer embedded with product and engineering teams at Monarch, a personal finance platform. Conduct AppSec reviews, SAST/DAST, vulnerability management, and AI security for LLM features on Django/Python stack. Requires 5+ years in security engineering with Python and web security expertise.
About the job
Responsibilities
- Conduct application security reviews — threat modeling, code review, and risk assessment — for new features and major product changes across Monarch's Django/Python stack.
- Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines.
- Work through the vulnerability backlog with urgency — maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads.
- Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces.
- Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces — covering prompt injection, data leakage, model abuse, and supply chain risk.
- Build and maintain security automations and AI-powered tooling, and define and assess security requirements for AI workflows and agentic systems.
- Participate in the weekly security on-call rotation.
Requirements
- 5+ years in security engineering with demonstrated depth in Application and AI security — threat modeling, SAST/DAST, secure code review, and vulnerability management.
- Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns).
- Hands-on experience with application security tooling — Semgrep, Burp Suite, Nuclei, or equivalents.
- Familiarity with AI/ML security risks — prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk.
- Transformative AI fluency — actively uses AI tools to accelerate security work and build automation.
Nice-to-Haves
- Experience in fintech or with financial data security requirements.
- Familiarity with SOC 2, NIST CSF, or similar compliance frameworks.
- Cloud security experience (AWS preferred) — IAM, container security, ECS/EKS.
- Relevant certifications: OSCP, BSCP, CSSLP, CISSP, or equivalent.
- Detection engineering and incident response experience.
- Additional offensive security experience — red teaming, bug bounty, or broader penetration testing beyond web/API surfaces.
Compensation
- Competitive cash and equity compensation.
- Salary range: $180,000 - $215,000.
Skills
Application Security, Ai Security, Python, Threat Modeling, SAST, DAST, Owasp Top 10, Semgrep, Burp Suite, Nuclei, Prompt Injection, Llm Security, Vulnerability Management, Penetration Testing
Similar jobs
Security Engineering jobsOwn and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Leads offensive security, threat intelligence, security testing, and incident response across applications, infrastructure, and networks. The role requires at least five years of relevant experience, cloud security expertise, AI and automation experience, and a bachelor's degree.
Own Anyscale’s secure software development lifecycle, partner with engineering on secure architecture and features, and lead vulnerability management and remediation. The role requires 8+ years of product or application security experience and strong hands-on secure-development expertise.
Own Anyscale’s compliance function end to end, leading SOC 2 and ISO 27001 programs, audit readiness, customer security diligence, and enterprise risk management. The role requires 7+ years in governance, risk, and compliance plus strong cloud and SaaS security-controls expertise.
The Senior Application Security Engineer will build secure-by-default software patterns, supply-chain controls, and developer-facing security tooling across a distributed systems platform. The role requires 5+ years of production software experience, strong application security expertise, and depth in Go or Rust.