高级应用安全工程师
Senior Application Security Engineer
### **关于我们:**
Monarch 是一个功能强大的一站式个人理财平台,旨在让财务的复杂性重新变得简单。自 2021 年推出以来,我们已成为用户和专家推荐的首选个人理财应用。我们的目标是让财务不再成为压力来源,让用户能够专注于真正重要的事情。
我们是一支务实的团队,由有经验的创业者领导,他们热衷于帮助我们的会员实现财务目标。我们专注于打造人们喜爱的产品,并不断寻找能让我们做得更好的优势。AI 是我们运营的核心:团队中的每个人都将 AI 作为合作伙伴,以提升判断力、加快速度并拓展可能性。我们不追求工具的精通,而是追求熟练度和好奇心。重要的是,AI 是你当前工作的一部分,并且你正在不断提升自己使用 AI 的能力。
作为一家完全远程的公司(甚至在新冠疫情之前),我们欢迎几乎所有地方的申请人。我们的团队主要在太平洋时间上午 9 点至下午 2 点进行同步协作,并采用异步工作方式,以保持跨时区的联系。
加入我们,共同完成简化金钱、改变生活的使命。
**职位描述:**
Monarch 正在寻找一名高级应用安全工程师加入我们的安全工程团队,这正处于快速发展的阶段。你将向工程基础设施负责人汇报,作为一位亲力亲为的实践者,嵌入到我们的产品和工程团队中——进行应用安全评审、执行漏洞管理,并随着 Monarch 的发展,应用和改进我们的应用安全(AppSec)和 AI 安全实践。
作为基础安全团队的关键成员,你将直接与产品工程师合作,识别并弥补安全缺口,执行和改进 SAST/DAST 操作,并在 Monarch 不断扩展的 LLM 集成和代理产品表面应用 AI 安全评审流程。这个职位对于确保我们在处理超过一百万用户的日益敏感的财务数据时,应用层的安全性和弹性至关重要。
**你将负责:**
- 对 Monarch 的 Django/Python 堆栈中新功能和重大产品变更进行应用安全评审——威胁建模、代码审查和风险评估
- 执行和改进 SAST/DAST 操作,包括在 CI/CD 流水线中对发现结果进行分类、验证和修复跟踪
- 处理漏洞积压清单,优先处理高风险问题
查看英文原文
### **About Us:**
Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, we've become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters.
We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. We're hyper focused on building a product people love, and on finding every edge that helps us do that better. AI is core to how we operate: every person on the team uses it as a partner to sharpen judgment, move faster, and expand what's possible. We're not looking for tool mastery, we're looking for fluency and curiosity. What matters is that AI is part of how you work today and that you're actively raising your own bar on how to use it well.
As a fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones.
Join us on our mission to transform lives by **simplifying money, together.**
**The Role:**
Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering teams — conducting application security reviews, executing on vulnerability management, and applying and improving our AppSec and AI security practices as Monarch scales.
As a key contributor on the Foundations security team, you'll work directly with product engineers to identify and close security gaps, perform and improve SAST/DAST operations, and apply AI security review processes across Monarch's growing LLM-integrated and agentic product surface. This role is critical in ensuring our application layer remains secure and resilient as we handle increasingly sensitive financial data for over a million users.
**What You'll Do:**
- Conduct application security reviews — threat modeling, code review, and risk assessment — for new features and major product changes across Monarch's Django/Python stack
- Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines
- Work through the vulnerability backlog with urgency — maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads
- Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces
- Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces — covering prompt injection, data leakage, model abuse, and supply chain risk
- Build and maintain security automations and AI-powered tooling, and define and assess security requirements for AI workflows and agentic systems.
- Participate in the weekly security on-call rotation
**What You'll Bring:**
1. 5+ years in security engineering with demonstrated depth in Application and AI security — threat modeling, SAST/DAST, secure code review, and vulnerability management
2. Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns)
3. Hands-on experience with application security tooling — Semgrep, Burp Suite, Nuclei, or equivalents
4. Familiarity with AI/ML security risks — prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk
5. Transformative AI fluency — actively uses AI tools to accelerate security work and build automation
**Nice to Haves:**
- Experience in fintech or with financial data security requirements
- Familiarity with SOC 2, NIST CSF, or similar compliance frameworks
- Cloud security experience (AWS preferred) — IAM, container security, ECS/EKS
- Relevant certifications: OSCP, BSCP, CSSLP, CISSP, or equivalent
- Detection engineering and incident response experience
- Additional offensive security experience — red teaming, bug bounty, or broader penetration testing beyond web/API surfaces
**Typical Process:**
1. Recruiter Video Call
2. Hiring Manager Video Call
3. Take Home Assignment
4. Virtual "Onsite" Round (2–4 interviews)
5. Reference Checks
6. Offer!
### **Benefits :**
- Work wherever you want! As a **fully** remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere.
- Competitive cash and equity compensation in a hyper growth, early stage company 🚀.
- Stipend to set-up your ideal working environment.
- Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan).
- Unlimited PTO.
- 3 day weekend every month! We take off the “First Friday” every month to focus on rest, recuperation, or just having fun!
### **Equal Opportunity & Non-Discrimination**
We are an equal opportunity employer and value diversity. We do not discriminate on the basis of race, religion, color, national origin, sex (including pregnancy and gender identity), sexual orientation, age, marital status, veteran status, disability status, or genetic information.
### **Applicant Notices**
_California & San Francisco:_ Pursuant to the California Fair Chance Act and the San Francisco Fair Chance Ordinance, qualified applicants with arrest and conviction records will be considered for employment. We comply with all applicable fair chance hiring laws.