Senior Application Security Engineer

3 semanas atrás


Criciúma, Santa Catarina, Brasil Rain Tempo inteiro
Overview

Senior Application Security Engineer at Rain. Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain's application and platform security posture. The position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Responsibilities
  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (e.g., exploited vulnerabilities, credential stuffing, web/API attacks).
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
  • Participate in continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).
Required Qualifications
  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code reviews or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
  • Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and working within cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).
Preferred Qualifications
  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM/AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Who We Are

Rain is a team of people with a deeply rooted passion for our mission, embracing diversity across our global team and growing personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.

Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at ******.

#J-18808-Ljbffr

  • Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    Avenue Code is the leading software consultancy focused on delivering end-to-end development solutions for digital transformation across every vertical. We're privately held, profitable, and have been on a solid growth trajectory since day one. We care deeply about our clients, our partners, and our people. We prefer the word 'partner' over 'vendor', and our...


  • Criciúma, Santa Catarina, Brasil Nexer Telescope Tempo inteiro

    OverviewExperienced Recruiter For The Swedish IT Industry role at Nexer Telescope. Sweden needs skilled engineers About 30 000 of them by 2030, according to the Swedish Statistical Central Bureau. We currently have ~200 open positions for Software Engineers with our clients in Sweden. Are you ready to help us?Job DescriptionAs a senior headhunter you will...


  • Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    TapGoods is an exciting, fast-growing start-up that is revolutionizing how rental companies optimize and grow their businesses. We're working to make it easy to rent. There are tens of thousands of businesses in the US that provide event, tool, audiovisual, and recreation rentals. This fragmented $722 billion global industry has not yet adopted modern...


  • Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    Engenheiro de softwareDescrição Do TrabalhoEngenheiro de software sênior A X-VIA é uma plataforma tecnológica inspirada no modelo estoniano X-Road, referência mundial em governo digital. Adaptada à realidade brasileira, a solução permite que diferentes órgãos públicos compartilhem dados de forma segura, eficiente e padronizada, promovendo...

  • Data Scientist

    3 semanas atrás


    Criciúma, Santa Catarina, Brasil Microsoft Tempo inteiro

    Data Scientist / Applied Scientist (Mid and Senior Levels) Join to apply for the Data Scientist / Applied Scientist (Mid and Senior Levels) role at Microsoft Data Scientist / Applied Scientist (Mid and Senior Levels) 1 week ago Be among the first 25 applicants Join to apply for the Data Scientist / Applied Scientist (Mid and Senior Levels) role at...


  • Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    Quem é Stone Tech? A Stone nasceu com o propósito de ser protagonista na transformação da indústria de pagamentos, lutando para oferecer as melhores soluções para quem empreende no Brasil. Pensando nisso, construímos a Stone Tech A junção dos times de tecnologia Stone Co. e as empresas financeiras do grupo que reconhecem o potencial empreendedor...

  • Desenvolvedor Python

    3 semanas atrás


    Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    Overview Estamos em busca de um(a) Desenvolvedor Python Sênior para colaborar no design técnico de soluções backend, desenvolvimento de sistemas, garantia da qualidade das implementações e manutenção de novas funcionalidades, trabalhando em conjunto com a equipe de engenharia. Idiomas Inglês B1 Requisitos técnicos Graduação em Ciência da...

  • Desenvolvedor Python

    3 semanas atrás


    Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    OverviewEstamos em busca de um(a) Desenvolvedor Python Sênior para colaborar no design técnico de soluções backend, desenvolvimento de sistemas, garantia da qualidade das implementações e manutenção de novas funcionalidades, trabalhando em conjunto com a equipe de engenharia. IdiomasInglês B1 Requisitos técnicosGraduação em Ciência da...

  • Software Engineer

    3 semanas atrás


    Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    Fetchly Labs is a forward-thinking technology company specializing in innovative software solutions. We pride ourselves on creating a collaborative and dynamic remote work environment that fosters creativity and growth. Our projects focus on delivering high-quality applications utilizing modern technologies, ensuring that our team members are continuously...


  • Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiro

    About UsAbout UsWe're a fully-remote company distributed across the Americas with no physical headquarters. We help companies build great products that matter - that's what defines us as a group.We're a developer-first software development nearshore company. We prioritize building lasting partnerships with our clients. We go beyond just delivering code, we...