
Senior Application Security Engineer
4 semanas atrás
Join to apply for the Senior Application Security Engineer role at Rain .
Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We have raised nearly $400M in funding, including the largest Series A in fintech history, and recently closed our Series B to fuel our next stage of hypergrowth. We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team.
This role requires a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work with our Cloud Security and GRC teams to improve Rain's application and platform security posture. The position is technically grounded, involving direct engagement in application-layer matters and security reviews, while contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.
Key Responsibilities- Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
- Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
- Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
- Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
- Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
- Build and maintain a security issues dashboard to track remediation status and metrics.
- Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (e.g., exploited vulnerabilities, credential stuffing, web/API attacks).
- Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).
- Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
- Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
- Participate in continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).
- Fluent English, including strong verbal and written skills.
- Strong problem-solving and analytical mindset.
- Excellent communication skills to convey security risks to technical and non-technical stakeholders.
- 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
- Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
- Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
- Proven expertise in performing code reviews or security assessments and writing clear reports.
- Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.
- Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
- Experience securing CI/CD pipelines and integrating AppSec tooling into the SDLC.
- Solid knowledge of containerization and Kubernetes security fundamentals.
- Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
- Comfortable with Agile development methodologies and working within cross-functional squads.
- Software supply chain security (e.g., SBOM, artifact signing).
- Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
- AWS, GCP, or Azure Security Specialty certification.
- Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
- Experience implementing RASP or eBPF runtime protection tools.
- Exposure to LLM/AI security considerations and secure code generation practices.
- Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Rain is filled with people who are passionate about our mission, embrace diversity, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.
Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at ******.
#J-18808-Ljbffr-
Senior Infrastructure Engineer
3 semanas atrás
Santo André, São Paulo, Brasil Truelogic Software Tempo inteiroSenior Infrastructure Engineer - Software Development Join to apply for the Senior Infrastructure Engineer - Software Development role at Truelogic Software Senior Infrastructure Engineer - Software Development 1 week ago Be among the first 25 applicants Join to apply for the Senior Infrastructure Engineer - Software Development role at Truelogic Software...
-
Senior Manual/Automation QA Engineer with Tosca
3 semanas atrás
Santo André, São Paulo, Brasil EPAM Systems Tempo inteiroSenior Manual/Automation QA Engineer with Tosca We are seeking a dedicated Senior Manual/Automation QA Engineer with strong expertise in Tosca to join our team and contribute to a Salesforce-driven telecommunications project. The role focuses on enhancing the current Salesforce support system for Connect and supporting sustained business growth through...
-
Microsoft Fabric Data Engineer
3 semanas atrás
Santo André, São Paulo, Brasil Nearsure Tempo inteiroMicrosoft Fabric Data Engineer - Work from home Microsoft Fabric Data Engineer - Work from home 1 day ago Be among the first 25 applicants Join our close-knit LATAM remote team: Connect through fun activities like coffee breaks, tech talks, and games with your team-mates and management. Say goodbye to micromanagement We champion autonomy, open...
-
Senior Full-Stack Engineer
3 semanas atrás
Santo André, São Paulo, Brasil Homera Health Tempo inteiroAbout Homera Health Homera Health is the team behind the team—building the tech, marketing, and growth engine powering some of today's most successful telehealth brands. As we expand into new verticals, including an upcoming men's health platform, we're hiring world-class talent across product design, front-end and back-end engineering, digital marketing,...
-
Data Platform Engineer
4 semanas atrás
Santo André, São Paulo, Brasil BairesDev Tempo inteiroJoin to apply for the Data Platform Engineer - Remote Work | REF# role at BairesDev 1 month ago Be among the first 25 applicants Join to apply for the Data Platform Engineer - Remote Work | REF# role at BairesDev Get AI-powered advice on this job and more exclusive features. At BairesDev, we've been leading the way in technology projects for over 15...
-
Senior SAP Consultant
3 semanas atrás
Santo André, São Paulo, Brasil Asenium Consulting Tempo inteiroOverview Buscamos um Consultor SAP BTP Sênior para integrar um projeto estratégico de transformação digital no setor de varejo. Responsabilidades Projetar e implementar soluções na SAP Business Technology Platform (SAP BTP) . Trabalhar com serviços como SAP Integration Suite, SAP Extension Suite , SAP Build , SAP Business Application Studio , entre...
-
GL - Backend Developer B. - Job0064
3 semanas atrás
Santo André, São Paulo, Brasil Thaloz Tempo inteiroJob Summary We are seeking a highly skilled Senior Backend Engineer to join our dynamic product development team. This role is pivotal in enhancing and scaling our customer-facing website and registration flow, while also contributing to the robustness and scalability of our backend services. As a key member of a Scrum team working in two-week sprints, you...
-
Salesforce FSC Developer
3 semanas atrás
Santo André, São Paulo, Brasil Stott and May Tempo inteiroWe are hiring a Salesforce FSC Developer (Nearshore) for one of our consulting clients - working on a project with a US based Insurance company. This is a remote nearshore role and can be based in any nearshore location (Brazil, Mexico, Uruguay, Argentina, etc.). The contract is to start ASAP initially for 2-3 months, but very likely to extend for 9 months...
-
Grupo | Tech Lead Manager
3 semanas atrás
Santo André, São Paulo, Brasil QuintoAndar Tempo inteiroOverview Grupo QuintoAndar | Tech Lead Manager role at QuintoAndar . We are Grupo QuintoAndar, the largest real estate ecosystem in Latin America. Guided by a shared purpose of helping people love the place where they live, we have a diverse portfolio of brands and solutions that cover all stages of the living journey. We develop technologies and...
-
Senior Specialist, Employee elations
3 semanas atrás
Santo André, São Paulo, Brasil R Tempo inteiroOverview About Remote Remote is solving modern organizations' biggest challenge – navigating global employment compliantly with ease. We make it possible for businesses of all sizes to recruit, pay, and manage international teams. With our core values at heart and future focused work culture, our team works tirelessly on ambitious problems, asynchronously,...