Senior Platform Security Engineer
About Monstro
Monstro is a governed AI platform for regulated financial institutions. We give banks and wealth managers a way to deliver trusted advice digitally — to every client, not just the top tier. Institutions already have the relationships, data, and context to understand each client. Monstro turns that understanding into advice. It gives every client the experience of a personal advisor: bringing together their full financial picture, identifying what matters, and delivering personalized guidance across investments, tax, retirement, insurance, legal, and more. For clients, that means clearer decisions, proactive support when life changes, and a better view of their financial lives. For institutions, it means deeper relationships, more clients served consistently, and more of each client's financial life managed in one place.
About the Role
We are looking for a Senior Platform Security Engineer to help build and secure the infrastructure that powers Monstro's AI platform. This is a hands-on engineering role focused on creating reliable, scalable, and secure systems while embedding security throughout the software development lifecycle. You'll sit at the intersection of platform engineering, cloud infrastructure, security operations, and compliance. Your mission is to build and maintain scalable, secure, and compliant infrastructure that enables engineering teams to move quickly with confidence. Alongside building and securing our platform, you'll help mature the controls, processes, and evidence required to support compliance initiatives such as SOC 2 and ISO 27001 as Monstro continues to scale.
- Work on technology that brings real financial advice to people who have rarely had access to it.
- Think clearly, move with urgency, hold a high bar, and take responsibility for work that matters.
- Shape the systems, controls, and operational practices that protect both our platform and our customers while enabling engineering teams to move quickly and safely.
What You'll Own
- Platform Engineering & Infrastructure Design, build, and maintain scalable cloud infrastructure across GCP and supporting cloud platforms.
- Implement and manage infrastructure-as-code using Terraform. Experience with Terraform is preferred, though equivalent experience with infrastructure automation tools such as Pulumi, CloudFormation, Ansible, or similar technologies is also valued.
- Manage containerized environments and orchestration platforms including Docker and Kubernetes.
- Drive reliability, performance, and scalability improvements across production systems.
- Support disaster recovery, business continuity, and infrastructure resilience initiatives.
- Partner with engineering teams to improve developer experience and deployment velocity.
- Partner with AI and product engineering teams to build the infrastructure foundations for agentic systems, enabling secure, scalable, and reliable deployment of AI-powered workflows and services.
DevOps & CI/CD
- Design, implement, and optimize CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or similar technologies.
- Automate build, testing, deployment, and operational workflows to reduce manual effort and improve consistency.
- Champion GitOps and infrastructure automation practices across engineering teams.
- Establish monitoring, observability, and alerting frameworks using tools such as Prometheus, Grafana, Datadog, and ELK.
- Improve deployment reliability and operational metrics through continuous platform enhancements.
Security Operations & Governance
- Embed security controls throughout the software development lifecycle through a DevSecOps approach.
- Manage vulnerability scanning, remediation programs, and patch management processes.
- Implement and maintain security monitoring, SIEM tooling, intrusion detection, and threat detection capabilities.
- Manage secrets, credentials, certificates, and key management systems.
- Lead incident response activities, root cause investigations, and post-incident reviews.
- Conduct threat modelling and security risk assessments for new and existing systems.
- Partner with engineering teams to improve security awareness and secure development practices.
Cloud Security & Compliance
- Apply cloud security best practices including least-privilege access controls, encryption, and network segmentation.
- Design and maintain secure networking architectures including VPCs, VPNs, firewalls, load balancers, and zero-trust controls.
- Support compliance initiatives aligned to frameworks such as SOC 2, ISO 27001, CIS Benchmarks, NIST, and GDPR.
- Contribute to audit readiness activities and remediation efforts.
- Help ensure Monstro's infrastructure meets the security expectations required within regulated financial environments.
Collaboration & Engineering Excellence
- Work closely with engineering, product, and leadership teams to build a security-first engineering culture.
- Maintain high-quality technical documentation including runbooks, architecture diagrams, operational procedures, and security policies.
- Lead and participate in on-call rotations and operational incident management.
- Mentor engineers and contribute to knowledge sharing across the organization.
- Help establish best practices that improve reliability, security, and operational maturity as we scale.