Senior Application Security Engineer

4 semanas atrás


Sapiranga, Brasil Rain Tempo inteiro

1 month ago Be among the first 25 applicants

Get AI-powered advice on this job and more exclusive features.

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We've raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B to fuel our next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain's application and platform security posture. This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Responsibilities
  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web/API attacks).
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).
Required Qualifications
  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code reviews or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
  • Experience securing CI/CD pipelines and integrating AppSec tooling into the SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and working within cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).
Preferred Qualifications
  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM/AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Who We Are

Rain is filled with people who have a deeply rooted passion for our mission, embrace diversity, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.

As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at ******.

Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology

Referrals increase your chances of interviewing at Rain by 2x

Get notified about new Senior Application Security Engineer jobs in Sapiranga, Rio Grande do Sul, Brazil .

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr

  • Sapiranga, Brasil Ledn Tempo inteiro

    OverviewStaff Application Security Engineers, Ledn is interested in hearing from you! Ledn is a global financial services company built for digital assets, helping to improve the everyday lives of Bitcoin holders while building generational wealth for the future. We offer a suite of egalitarian lending, savings and trading products to digital asset holders...

  • Security Engineer

    Há 3 dias


    Sapiranga, Brasil Ledn Tempo inteiro

    OverviewWe are seeking a full time Security Engineer with deep expertise in Application Security, Identity & Access Management, and Confidential Computing to strengthen the security of our Bitcoin-backed loan platform. Security is fundamental to protecting our customers and business, and this role will drive both the tactical improvements and long-term...


  • Sapiranga, Brasil Bebeeendpoint Tempo inteiro

    Remote Endpoint Management LeaderThis is an exciting opportunity to lead our endpoint management team as a Remote Endpoint Management Leader.Job Description:The successful candidate will be responsible for maintaining and securing 600+ corporate devices globally.This role requires a leader focused on automation, efficiency, and compliance across multiple...


  • Sapiranga, Brasil Bebeesoftwaredevelopment Tempo inteiro

    We seek a skilled Senior Rust software engineer to develop high-quality systems.Required Skills and Qualifications:Expert-level Rust proficiency for creating robust software solutionsStrong background in systems programming concepts, including concurrent and parallel processingExtensive experience with asynchronous programming in Rust to ensure efficient...


  • Sapiranga, Brasil Bebeedeveloper Tempo inteiro

    Job Title: Senior Full Stack DeveloperWe are seeking a seasoned full-stack developer with 4+ years of experience producing commercial-grade software that is highly maintainable and supportable.The ideal candidate will be adept at working in a dynamic startup environment, have proven on-time delivery experience and strong problem-solving abilities, quickly...

  • Engenheiro De Dados – Sap

    1 semana atrás


    Sapiranga, Brasil Mouts Ti Tempo inteiro

    ?? Vaga: Data Engineer Specialist – SAP & Databricks | Projeto 100% remotoEstamos em busca de um(a)Data Engineer Specialistaltamente técnico(a) e com perfil autônomo para um projeto estratégico e de grande visibilidade!Atuação: 100% RemotaFulltimeSuas responsabilidades incluirão:Desenvolver e manter pipelines de dados...


  • Sapiranga, Brasil Bebeeartificial Tempo inteiro

    Empowering Innovation Through AI EngineeringCarnegie has been a leader in higher education marketing and enrollment strategy for 30 years.The Full-Stack Engineer will build and maintain cutting-edge AI applications on top of existing LLM APIs.Key responsibilities include designing, developing, and maintaining scalable and secure AI applications, implementing...


  • Sapiranga, Brasil Bebeedevops Tempo inteiro

    Job DescriptionWe are seeking a seasoned DevOps Engineer to support large-scale cloud operations and contribute to key product updates.This role involves managing cloud infrastructure, ensuring security and compliance, optimizing performance and cost, and driving automation across the DevOps lifecycle.Key Responsibilities:Designing, building, and managing...


  • Sapiranga, Brasil Bebeesoftware Tempo inteiro

    As a senior software engineer, you will be part of our team that champions autonomy, open communication, and respect for diversity.We are looking for talented individuals who share our values and are passionate about delivering high-quality solutions.The ideal candidate should have relevant experience in LLMs, web scrapers, and distributed systems.They...


  • Sapiranga, Brasil Bebeeexpert Tempo inteiro

    Job DescriptionWe seek skilled engineers to join our team and design, build, and maintain scalable microservices.The successful candidate will develop RESTful APIs, manage containerized deployments using Kubernetes and Docker, and collaborate with internal stakeholders.Responsibilities:Design and maintain Golang-based microservices.Develop and integrate...