Senior Application Security Engineer

3 semanas atrás


Caxias do Sul, Rio Grande do Sul, Brasil Rain Tempo inteiro
Overview

Senior Application Security Engineer role at Rain.

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We have raised nearly $400M in funding including the largest Series A in fintech history and just closed our Series B. This role is on Rain's Security team, focusing on secure software development and cloud-native defense.

You will partner closely with engineering, Cloud Security, and GRC teams to improve Rain's application and platform security posture. The role is technically grounded, involving application-layer security reviews and security automation across the SDLC.

Key Responsibilities
  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, ensuring timely vulnerability remediation.
  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC) using tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives (container/Kubernetes hardening, RASP, eBPF-based detection).
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support during cybersecurity incidents impacting applications or cloud infrastructure.
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub automations, DLP monitoring).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives and developer training (secure coding, API security).
  • Participate in the continuous improvement of AppSec maturity (e.g., OWASP SAMM, ISO 27001, SOC 2).
Qualifications
  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 3–5+ years of experience in application security, penetration testing, and/or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code reviews or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
  • Experience securing CI/CD pipelines and integrating AppSec tooling into the SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).
Preferred Qualifications
  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM/AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Who We Are

Rain is a diverse team united by a mission-driven culture. We own what we do and let data guide our actions while working quickly and adapting to new challenges every day. Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable laws. If you need assistance or accommodations due to a disability, you may contact us at ******.

Job Details
  • Seniority level: Mid-Senior level
  • Employment type: Full-time
  • Job function: Information Technology

Referrals increase your chances of interviewing at Rain. Get notified about new Senior Application Security Engineer jobs in Caxias do Sul, Rio Grande do Sul, Brazil.

#J-18808-Ljbffr
  • Senior Software Engineer

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Huntress Tempo inteiro

    Reports to: Engineering Manager Location: Remote US Compensation Range: $160,000 to $190,000 base plus bonus and equity Overview What We Do: Huntress is a fully remote, global team of passionate experts and ethical badasses on a mission to break down the barriers to cybersecurity. Whether creating purpose-built security solutions, hunting down hackers,...

  • Senior MLOps Engineer

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Truelogic Software Tempo inteiro

    Job Summary We are seeking a Senior MLOps Engineer to join a cutting-edge AI/ML engineering team. In this high-visibility role, you will design and implement MLOps pipelines, manage cloud-based resources, and optimize AI/ML infrastructure to deliver scalable, precise, and innovative machine learning solutions. From audience segmentation to advanced language...


  • Santa Cruz do Sul, Rio Grande do Sul, Brasil Nexer Telescope Tempo inteiro

    Overview Experienced Recruiter For The Swedish IT Industry – role at Nexer Telescope. Sweden needs skilled engineers. About 30 000 by 2030, according to the Swedish Central Bureau. We currently have ~200 open positions for Software Engineers with our clients in Sweden. As a senior headhunter, you will help us find engineers who are ready to embark on an...

  • Automation & AI Engineer

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Adaptive Teams Tempo inteiro

    Ready to build smart automation with serious brains behind it ? We're looking for a Python-first engineer with a background in AI/ML, data science, or engineering to craft scalable workflows powered by LLMs. Start part-time and grow into full-time. Your Mission: Day to Day Responsibilities Design and implement automation workflows , integrating AI when...


  • Caxias do Sul, Rio Grande do Sul, Brasil Speechify Tempo inteiro

    Join to apply for the Software Engineer, iOS Core Product - Curitiba, Brazil role at Speechify 2 days ago Be among the first 25 applicants Join to apply for the Software Engineer, iOS Core Product - Curitiba, Brazil role at Speechify PLEASE APPLY THROUGH THIS LINK: DO NOT APPLY BELOWThe mission of Speechify is to make sure that reading is never a...

  • Lead Software Engineer

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Upwork Tempo inteiro

    Overview Upwork ($UPWK) is the world's human and AI-powered work marketplace that connects businesses with highly skilled, AI-enabled independent talent from across the globe. From entrepreneurs to Fortune 100 enterprises, companies rely on Upwork's trusted platform and its mindful AI companion, Uma, to find and hire expert talent, leverage AI-powered work...


  • Caxias do Sul, Rio Grande do Sul, Brasil GEICO Tempo inteiro

    Overview Employer Industry: Insurance and Cybersecurity Why consider this job opportunity: Salary up to $260,000.00 Comprehensive Total Rewards program tailored for individual and family well-being 401K savings plan with a 6% match, performance incentives, and tuition assistance Flexible work options, including the ability to work from anywhere in the U.S....

  • Especialista Em Devsecops

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Grupo CPA Tempo inteiro

    Overview VAGA ESPECIALISTA DEVSECOPS II | Grupo CPA Local: Santo Amaro/SP - Híbrido Modalidade de Contratação: PJ ou Cooperado Tempo de Projeto: Indeterminado Descrição Do Cargo Buscamos um(a) Analista Sênior DevSecOps com sólida experiência em práticas de desenvolvimento seguro, automação de segurança em pipelines CI/CD e integração de...


  • Caxias do Sul, Rio Grande do Sul, Brasil Remote Jobs Tempo inteiro

    Employer Industry: Clean Energy and Cybersecurity What to Expect Perform security risk and vulnerability assessments for medium complexity information systems Execute project reporting, monitoring status, timelines, and budgets Assist in planning and implementation of current and future security domains Investigate suspected attacks and manage security...

  • Senior Software Engineer

    3 semanas atrás


    Caxias do Sul, Rio Grande do Sul, Brasil Cotiviti - US Tempo inteiro

    Overview Employer Industry: Healthcare Solutions and Analytics Why consider this job opportunity: Salary up to $145,000 per year Comprehensive benefits package including medical, dental, vision, disability, and life insurance 401(k) savings plans and paid family leave Generous Paid Time Off (PTO) ranging from 17-27 days per year Opportunity for remote work...