Senior Application Security Engineer
New
M
MonarchFintech / Personal Finance
Canada, USA, 9 AM – 2 PM PTFull-TimeSenior
Salary180,000 - 215,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- PythonDjango
Requirements
- 5+ years of experience in security engineering with focus on Application and AI security.
- Proficiency in Python.
- Strong understanding of web application security including OWASP Top 10, API security, and auth/authz patterns.
- Hands-on experience with security tools like Semgrep, Burp Suite, or Nuclei.
- Familiarity with AI/ML security risks such as prompt injection, model abuse, and LLM supply chain risks.
- Demonstrated transformative AI fluency using AI tools to accelerate security work and automation.
- Experience in fintech or financial data security preferred.
- Familiarity with compliance frameworks such as SOC 2 or NIST CSF is a plus.
- Cloud security experience (AWS preferred) in IAM, container security, and ECS/EKS.
- Relevant certifications such as OSCP, BSCP, CSSLP, or CISSP are advantageous.
Responsibilities
- Conduct application security reviews including threat modeling, code review, and risk assessment for new features in a Django/Python stack.
- Perform and improve SAST/DAST operations, including triage, validation, and remediation tracking within CI/CD pipelines.
- Manage the vulnerability backlog, maintaining triage criteria and escalation paths with engineering squads.
- Coordinate and perform penetration testing and security assessments against web and API surfaces.
- Implement and refine AI security review processes to address prompt injection, data leakage, model abuse, and supply chain risks.
- Develop security automations and AI-powered tools while defining security requirements for AI workflows.
- Participate in the weekly security on-call rotation.
View Full Description & ApplyYou'll be redirected to the employer's site