
Senior Application Security Engineer
Há 5 dias
Join to apply for the Senior Application Security Engineer role at Rain .
Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We have raised nearly $400M in funding, including the largest Series A in fintech history, and recently closed our Series B to fuel our next stage of hypergrowth. We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team.
This role requires a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work with our Cloud Security and GRC teams to improve Rain's application and platform security posture. The position is technically grounded, involving direct engagement in application-layer matters and security reviews, while contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.
Key Responsibilities- Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
- Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
- Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
- Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
- Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
- Build and maintain a security issues dashboard to track remediation status and metrics.
- Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (e.g., exploited vulnerabilities, credential stuffing, web/API attacks).
- Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).
- Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
- Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
- Participate in continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).
- Fluent English, including strong verbal and written skills.
- Strong problem-solving and analytical mindset.
- Excellent communication skills to convey security risks to technical and non-technical stakeholders.
- 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
- Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
- Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
- Proven expertise in performing code reviews or security assessments and writing clear reports.
- Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.
- Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
- Experience securing CI/CD pipelines and integrating AppSec tooling into the SDLC.
- Solid knowledge of containerization and Kubernetes security fundamentals.
- Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
- Comfortable with Agile development methodologies and working within cross-functional squads.
- Software supply chain security (e.g., SBOM, artifact signing).
- Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
- AWS, GCP, or Azure Security Specialty certification.
- Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
- Experience implementing RASP or eBPF runtime protection tools.
- Exposure to LLM/AI security considerations and secure code generation practices.
- Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Rain is filled with people who are passionate about our mission, embrace diversity, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.
Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at ******.
#J-18808-Ljbffr-
Chief Cloud Security Architect
Há 7 dias
Santo André, São Paulo, Brasil beBeeApplication Tempo inteiro US$150.000 - US$200.000Secure Software Development and Cloud-Native DefenseWe are seeking a skilled and driven Senior Application Security Engineer to partner closely with engineering and development squads, and work with our Cloud Security and GRC teams to improve application and platform security posture.This role requires a proactive approach to secure software development and...
-
Senior Infrastructure Engineer
Há 2 dias
Santo André, São Paulo, Brasil Truelogic Software Tempo inteiroSenior Infrastructure Engineer - Software Development Join to apply for the Senior Infrastructure Engineer - Software Development role at Truelogic Software Senior Infrastructure Engineer - Software Development 1 week ago Be among the first 25 applicants Join to apply for the Senior Infrastructure Engineer - Software Development role at Truelogic Software...
-
Senior AI Application Developer
1 semana atrás
Santo André, São Paulo, Brasil beBeeFrontend Tempo inteiro US$100.000 - US$120.000AI-Powered Front-end Engineer OpportunityWe are seeking a highly skilled and experienced front-end engineer to contribute to the development of our AI-powered applications.Develop, test, and maintain responsive and intuitive user interfaces for our AI tools.Collaborate with designers and backend developers to implement new features and improve existing...
-
Senior Network Operations Center Engineer
2 semanas atrás
Santo André, São Paulo, Brasil Itprotech Tempo inteiroOur client is seeking a Senior NOC Operations Engineer to work remotely for their american team.This role combines the day-to-day responsibilities of a NOC operator with senior-level leadership: acting as an escalation point, mentoring teammates, and driving process improvements.ResponsibilitiesDaily NOC monitoring, troubleshooting, and incident...
-
QA Automation Engineer
2 semanas atrás
Santo André, São Paulo, Brasil BairesDev Tempo inteiroJoin to apply for the QA Automation Engineer - Remote Work | REF# role at BairesDev 3 months ago Be among the first 25 applicants Join to apply for the QA Automation Engineer - Remote Work | REF# role at BairesDev Get AI-powered advice on this job and more exclusive features. At BairesDev, we've been leading the way in technology projects for over 15...
-
Microsoft Fabric Data Engineer
Há 2 dias
Santo André, São Paulo, Brasil Nearsure Tempo inteiroMicrosoft Fabric Data Engineer - Work from home Microsoft Fabric Data Engineer - Work from home 1 day ago Be among the first 25 applicants Join our close-knit LATAM remote team: Connect through fun activities like coffee breaks, tech talks, and games with your team-mates and management. Say goodbye to micromanagement We champion autonomy, open...
-
Santo André, São Paulo, Brasil EPAM Systems Tempo inteiroSenior Manual/Automation QA Engineer with Tosca We are seeking a dedicated Senior Manual/Automation QA Engineer with strong expertise in Tosca to join our team and contribute to a Salesforce-driven telecommunications project. The role focuses on enhancing the current Salesforce support system for Connect and supporting sustained business growth through...
-
QA Automation Engineer
3 semanas atrás
Santo André, São Paulo, Brasil BairesDev Tempo inteiroJoin to apply for the QA Automation Engineer - Remote Work | REF#283342 role at BairesDev 3 months ago Be among the first 25 applicants Join to apply for the QA Automation Engineer - Remote Work | REF#283342 role at BairesDev Get AI-powered advice on this job and more exclusive features. At BairesDev, we've been leading the way in technology projects for...
-
Highly Skilled Software Engineer
2 semanas atrás
Santo André, São Paulo, Brasil beBeeBackendDeveloper Tempo inteiro US$90.000 - US$120.000Senior Backend DeveloperWe are seeking a skilled Senior Backend Developer to join our team.Develop and maintain scalable backend APIs and processes for cloud-based applications.Work on technical challenges involving .NET, cloud technologies, and software development best practices.Required SkillsTo be successful in this role, you will need:Experience with...
-
Senior Full-Stack Engineer
Há 2 dias
Santo André, São Paulo, Brasil Homera Health Tempo inteiroAbout Homera Health Homera Health is the team behind the team—building the tech, marketing, and growth engine powering some of today's most successful telehealth brands. As we expand into new verticals, including an upcoming men's health platform, we're hiring world-class talent across product design, front-end and back-end engineering, digital marketing,...