Senior Application Security Engineer
New
M
MonarchPersonal finance
Listing locations: USA, Canada; Location base: USA,Canada, The team collaborates synchronously mostly from 9 AM – 2 PM PT.Full-TimeSenior
Salary180,000 - 215,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years in security engineering
- Required Skills
- Python
Requirements
- 5+ years in security engineering with demonstrated depth in application and AI security.
- Experience with threat modeling, SAST/DAST, secure code review, and vulnerability management.
- Proficiency in Python.
- Strong understanding of web application security, including OWASP Top 10, API security, and auth/authz patterns.
- Hands-on experience with application security tooling such as Semgrep, Burp Suite, Nuclei, or equivalents.
- Familiarity with AI/ML security risks such as prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk.
- Actively use AI tools to accelerate security work and build automation.
- Nice to have: experience in fintech or financial data security requirements.
- Nice to have: familiarity with SOC 2, NIST CSF, or similar compliance frameworks.
- Nice to have: cloud security experience, preferably AWS, including IAM, container security, and ECS/EKS.
- Nice to have: OSCP, BSCP, CSSLP, CISSP, or equivalent certifications.
- Nice to have: detection engineering, incident response, red teaming, bug bounty, or additional penetration-testing experience.
Responsibilities
- Conduct threat modeling, code reviews, and risk assessments for new features and major product changes across the Django/Python stack.
- Perform and improve SAST/DAST operations, including triage, validation, and remediation tracking of findings in CI/CD pipelines.
- Manage the vulnerability backlog, maintaining triage criteria, remediation tracking, and escalation paths with engineering squads.
- Perform and coordinate penetration testing and security assessments of web and API surfaces.
- Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces, including prompt injection, data leakage, model abuse, and supply chain risk.
- Build and maintain security automations and AI-powered tooling.
- Define and assess security requirements for AI workflows and agentic systems.
- Participate in the weekly security on-call rotation.
View Full Description & ApplyYou'll be redirected to the employer's site