Senior Application Security Engineer
Cybersecurity
Job Description
About us
Monarch is a powerful, all-in-one personal finance platform designed to help make the complexity of finances feel simple again. Since launching in 2021, we've become the top-recommended personal finance app by users and experts. Our goal? To take the stress out of finances so our members can focus on what truly matters. We are a team of do-ers led by experienced entrepreneurs who are passionate about helping our members reach their financial goals. We're hyper focused on building a product people love, and on finding every edge that helps us do that better. AI is core to how we operate: every person on the team uses it as a partner to sharpen judgment, move faster, and expand what's possible. We're not looking for tool mastery, we're looking for fluency and curiosity. What matters is that AI is part of how you work today and that you're actively raising your own bar on how to use it well. As a fully remote company (even before COVID!), we welcome applicants from almost anywhere. Our team collaborates synchronously mostly from 9 AM – 2 PM PT and embraces asynchronous work to stay connected across time zones. Join us on our mission to transform lives by simplifying money, together.The Role
Monarch is seeking a Senior Application Security Engineer to join our Security Engineering team during a period of rapid growth. Reporting to the Head of Engineering Infrastructure, you will be a hands-on practitioner embedded across our product and engineering teams — conducting application security reviews, executing on vulnerability management, and applying and improving our AppSec and AI security practices as Monarch scales. As a key contributor on the Foundations security team, you'll work directly with product engineers to identify and close security gaps, perform and improve SAST/DAST operations, and apply AI security review processes across Monarch's growing LLM-integrated and agentic product surface. This role is critical in ensuring our application layer remains secure and resilient as we handle increasingly sensitive financial data for over a million users.What You'll Do
- Conduct application security reviews — threat modeling, code review, and risk assessment — for new features and major product changes across Monarch's Django/Python stack - Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines - Work through the vulnerability backlog with urgency — maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads - Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces - Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces — covering prompt injection, data leakage, model abuse, and supply chain risk - Build and maintain security automations and AI-powered tooling, and define and assess security requirements for AI workflows and agentic systems.
- Participate in the weekly security on-call rotation What You'll Bring: 1.
Benefits
- Work wherever you want! As a fully remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere.
- Competitive cash and equity compensation in a hyper growth, early stage company 🚀.
- Stipend to set-up your ideal working environment.
- Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan).
- Unlimited PTO.
- 3 day weekend every month!
How to Stand Out
- Demonstrate AI‑augmented security fluency: In your resume and interview, cite concrete examples where you used AI tools (e.g., GitHub Copilot, Large Language Model code review, threat‑modeling assistants) to accelerate vulnerability discovery or remediation. Monarch values AI as a partner, so a brief case study showing reduced triage time by X% using an LLM‑driven pipeline will stand out.
- Show mastery of Monarch’s tech stack: The job listing mentions modern cloud (AWS), containerization (Docker/Kubernetes), and CI/CD (GitHub Actions). Prepare a short “security‑as‑code” demo repo (public or private link) that includes a Terraform‑based infrastructure scan, a SAST/DAST integration in a GitHub Actions workflow, and automated remediation scripts. Reference this repo in your cover letter.
- Quantify impact on application security programs: Recruiters at Monarch look for results‑driven engineers. Be ready to discuss metrics such as “identified X high‑severity bugs per release,” “cut mean time to detection from Y days to Z days,” or “implemented a bug‑bounty program that reduced external findings by %.” Use numbers, not just responsibilities.
- Tailor your remote collaboration narrative: Highlight tools Monarch uses for async work (e.g., Slack, Notion, Linear). Provide a brief example of how you led a cross‑functional security review across time zones, documented findings in Notion, and tracked remediation tickets in Linear, emphasizing clear communication and ownership without micromanagement.
- Negotiate with Monarch’s equity‑heavy compensation: Research recent equity grants for senior engineers at fast‑growing fintech startups (e.g., 0.05‑0.15 % total pool). When discussing salary, anchor on a total‑comp target that includes base, RSUs, and a performance‑linked bonus. Mention your AI‑driven security efficiencies as a lever for higher equity upside.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.