Senior Application Security Engineer at Monarch focusing on application security reviews and AI security practices to manage sensitive financial data effectively.
Responsibilities
Conduct application security reviews — threat modeling, code review, and risk assessment — for new features and major product changes across Monarch's Django/Python stack
Perform and improve SAST/DAST operations including triage, validation, and remediation tracking of findings in CI/CD pipelines
Work through the vulnerability backlog with urgency — maintaining triage criteria, remediation tracking, and escalation paths in partnership with engineering squads
Perform and coordinate penetration testing and security assessments against Monarch's web and API surfaces
Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces — covering prompt injection, data leakage, model abuse, and supply chain risk
Build and maintain security automations and AI-powered tooling, and define and assess security requirements for AI workflows and agentic systems.
Participate in the weekly security on-call rotation
Requirements
5+ years in security engineering with demonstrated depth in Application and AI security — threat modeling, SAST/DAST, secure code review, and vulnerability management
Proficiency in Python and strong understanding of web application security (OWASP Top 10, API security, auth/authz patterns)
Hands-on experience with application security tooling — Semgrep, Burp Suite, Nuclei, or equivalents
Familiarity with AI/ML security risks — prompt injection, model abuse, agentic attack surfaces, or LLM supply chain risk
Transformative AI fluency — actively uses AI tools to accelerate security work and build automation.
Benefits
Work wherever you want! As a fully remote company with no central office, we want you to work wherever you are happiest and most productive. Whether that’s out of your home, a co-working space, or elsewhere.
Competitive cash and equity compensation in a hyper growth, early stage company 🚀.
Stipend to set-up your ideal working environment.
Competitive Benefit Plans for employees based on your location (e.g. in the US we offer: Medical, dental and vision benefits and the ability to contribute to a 401k plan).
Unlimited PTO.
3 day weekend every month! We take off the “First Friday” every month to focus on rest, recuperation, or just having fun!
Applications Engineer developing technical and commercial quotations for Innomotics’ motors, VFDs, and drive systems. Supporting mining and heavy - industrial customers across Canada from proposal through execution.
Senior Application Security Engineer leading Trimble’s global SCA and SAST strategy. Embedding automated security into CI/CD pipelines across diverse technology stacks.
Sales Application Engineer advancing Intel connectivity solutions for Canadian telecom customers. Developing technical solutions, supporting design wins, and guiding telecom OEMs through the sales cycle.
Senior power systems engineer developing protection and control algorithms for GE Vernova’s grid automation products. Leading simulations, product specifications, technical guidance, and innovation.
Customer Applications Engineering intern at Nokia, a global connectivity company, maintaining network management platforms. Applying Linux, Java, scripting, and networking skills to customer infrastructure challenges.
Security Engineer securing Sentry’s application - monitoring platform through threat modeling, vulnerability management, and secure development practices. Partnering with product and engineering teams on emerging cloud and AI security challenges.
Join CIBC's Capital Markets Technology group as a Consultant, Application Development. Lead design and development of complex enterprise applications, enhancing compliance and reporting efficiency.