
Senior Application Security Engineer
Há 16 horas
OverviewSenior Application Security Engineer role at Rain.Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus.
We have raised nearly $400M in funding including the largest Series A in fintech history and just closed our Series B. This role is on Rain's Security team, focusing on secure software development and cloud-native defense.You will partner closely with engineering, Cloud Security, and GRC teams to improve Rain's application and platform security posture.
The role is technically grounded, involving application-layer security reviews and security automation across the SDLC.
Key Responsibilities
Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
Design, implement, and oversee automated processes for securely updating application and code dependencies, ensuring timely vulnerability remediation.
Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC) using tools like Semgrep, Snyk, Trivy, and Burp Suite.
Contribute to runtime security initiatives (container/Kubernetes hardening, RASP, eBPF-based detection).
Build and maintain a security issues dashboard to track remediation status and metrics.
Provide real-time support during cybersecurity incidents impacting applications or cloud infrastructure.
Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub automations, DLP monitoring).
Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
Collaborate with the GRC team to develop and deliver internal security awareness initiatives and developer training (secure coding, API security).
Participate in the continuous improvement of AppSec maturity (e.g., OWASP SAMM, ISO 27001, SOC 2).
Qualifications
Fluent English, including strong verbal and written skills.
Strong problem-solving and analytical mindset.
Excellent communication skills to convey security risks to technical and non-technical stakeholders.
3–5+ years of experience in application security, penetration testing, and/or secure code development, including work with QA teams.
Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
Proven expertise in performing code reviews or security assessments and writing clear reports.
Proficiency in at least one backend language (e.g., Go, Python, ) and understanding of React/React Native front-ends.
Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
Experience securing CI/CD pipelines and integrating AppSec tooling into the SDLC.
Solid knowledge of containerization and Kubernetes security fundamentals.
Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
Comfortable with Agile development methodologies and cross-functional squads.
Software supply chain security (e.g., SBOM, artifact signing).
Preferred Qualifications
Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
AWS, GCP, or Azure Security Specialty certification.
Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
Experience implementing RASP or eBPF runtime protection tools.
Exposure to LLM/AI security considerations and secure code generation practices.
Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Who We Are
Rain is a diverse team united by a mission-driven culture.
We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.
Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable laws.
If you need assistance or accommodations due to a disability, you may contact us at ******.
Job Details
Seniority level: Mid-Senior level
Employment type: Full-time
Job function: Information Technology
Referrals increase your chances of interviewing at Rain.
Get notified about new Senior Application Security Engineer jobs in Caxias do Sul, Rio Grande do Sul, Brazil.
#J-18808-Ljbffr
-
Manager Endpoint Engineers
1 semana atrás
Caxias do Sul, Rio Grande do Sul, Brasil Pathlock Tempo inteiroPosition Overview We are seeking a Manager of Endpoint Engineers to lead our endpoint management team in maintaining and securing 600+ corporate devices across our global organization.This remote position requires a leader with a relentless focus on automation, efficiency, and reducing contact time while ensuring compliance across multiple security...
-
Internal Security Specialist
Há 6 dias
Caxias do Sul, Rio Grande do Sul, Brasil beBeeSecurity Tempo inteiro R$32.540 - R$46.128Fiscal de Loja Job DescriptionThe Fiscal de Loja is a key role within our organization, responsible for monitoring internal security circuits and reporting any incidents or thefts to the store manager.Monitor internal security circuits to prevent unauthorized access and report any incidents or thefts to the store manager.Approach customers in cases of...
-
Senior Automation Engineer
Há 6 horas
Caxias do Sul, Rio Grande do Sul, Brasil beBeeEngineering Tempo inteiro R$100.000 - R$180.000About the RoleLincoln Electric is a world leader in engineering, design, and manufacturing of advanced arc welding solutions, automated joining, assembly and cutting systems, plasma and oxy-fuel cutting equipment. Our company has a leading global position in brazing and soldering alloys.We are recognized as the Welding Expert for our materials science,...
-
Automation & AI Engineer
Há 6 horas
Caxias do Sul, Rio Grande do Sul, Brasil Adaptive Teams Tempo inteiroReady to build smart automation with serious brains behind it ? We're looking for a Python-first engineer with a background in AI/ML, data science, or engineering to craft scalable workflows powered by LLMs. Start part-time and grow into full-time. Your Mission: Day to Day Responsibilities Design and implement automation workflows , integrating AI when...
-
UI Development Expert with Blazor Hybrid
Há 2 dias
Caxias do Sul, Rio Grande do Sul, Brasil beBeeWebDevelopment Tempo inteiro R$70.000 - R$95.000Job Title:UI Development Expert with Blazor Hybrid About the Role:The role of a UI development expert with Blazor Hybrid involves creating user interfaces using ASP.NET and .NET Core 9. This entails developing rich UI applications in Blazor, designing and implementing secure application development using OAuth, JWT, and RBAC, and collaborating with an...
-
Caxias do Sul, Rio Grande do Sul, Brasil Latamcent Tempo inteiroRole Overview We are seeking a Senior Software Developer who thrives in fast-paced startup environments and enjoys building exceptional product experiences.As a key contributor to our core product, you will work across the stack to solve complex problems, deliver new features, and help shape the future of demo automation.You will collaborate closely with...
-
Senior Developer latam Work
2 semanas atrás
Caxias do Sul, Rio Grande do Sul, Brasil BairesDev Tempo inteiroWho We areBairesDev is proud to be the fastest-growing company in America. With people in five continents and world-class clients, we are only as strong as the multicultural teams at the heart of our business. To consistently deliver the highest quality solutions to our clients, we only hire the Top 1% of the best talents and nurture their professional...
-
Analista de Supply Chain Senior
1 semana atrás
Caxias do Sul, Rio Grande do Sul, Brasil Danfoss Tempo inteiro**Requisition ID**:45742**Job Location(s)**:Caxias do Sul, BR**Employment Type**:Full Time**Segment**:Danfoss Power Solutions Segment**Job Function**:Supply Chain and Operations**Work Location Type**:On-site**Você na Danfoss...**- Como ANALISTA DE SUPPLY CHAIN SENIOR na Danfoss Power Solutions em Caxias do Sul, você fará parte de um time de especialistas...
-
Digital Architect for Enterprise Solutions
2 semanas atrás
Caxias do Sul, Rio Grande do Sul, Brasil beBeeDrupal Tempo inteiro US$21.600 - US$28.800Senior Drupal Developer JobWe are seeking a seasoned Senior Drupal Developer to join our team. As a key member, you will play a pivotal role in designing and implementing cutting-edge software solutions.About the RoleDesign and architect robust enterprise-scale websites using DrupalLead configuration management initiativesDevelop object-oriented programming...
-
Drupal Developer
2 semanas atrás
Caxias do Sul, Rio Grande do Sul, Brasil Aubay Portugal Tempo inteiroYour connection with Aubay starts in the following lines:Aubay Portugal is a multinational French company, in Portugal since 2007.We have offices in Lisbon and Oporto and we are a specialized consultant in Management, Implementation, Development and Maintenance of Information Systems.We have more than 150 active partners and we operate in sectors such as...