
Senior Application Security Engineer
Há 4 dias
OverviewSenior Application Security Engineer at Rain.
Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus.
We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team.
This role demands a proactive approach to secure software development and cloud-native defense.
You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain's application and platform security posture.
The position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.ResponsibilitiesCollaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.Build and maintain a security issues dashboard to track remediation status and metrics.Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (e.g., exploited vulnerabilities, credential stuffing, web/API attacks).
Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).
Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
Participate in continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).
Required QualificationsFluent English, including strong verbal and written skills.Strong problem-solving and analytical mindset.Excellent communication skills to convey security risks to technical and non-technical stakeholders.3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
Proven expertise in performing code reviews or security assessments and writing clear reports.Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React/React Native front-ends.Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.Solid knowledge of containerization and Kubernetes security fundamentals.Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.Comfortable with Agile development methodologies and working within cross-functional squads.Software supply chain security (e.g., SBOM, artifact signing).
Preferred QualificationsCertifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.AWS, GCP, or Azure Security Specialty certification.Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
Experience implementing RASP or eBPF runtime protection tools.Exposure to LLM/AI security considerations and secure code generation practices.Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
Who We AreRain is a team of people with a deeply rooted passion for our mission, embracing diversity across our global team and growing personally and professionally.
We own what we do and let data guide our actions while working quickly and adapting to new challenges every day.Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion under applicable federal, state, or local laws.
If you need assistance or accommodation due to a disability, you may contact us at ******.
#J-18808-Ljbffr
-
Senior Application Security Engineer
1 semana atrás
Criciúma, Santa Catarina, Brasil Rain Tempo inteiroOverview Senior Application Security Engineer at Rain. Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team. This role demands a proactive approach...
-
Senior Application Security Engineer
Há 2 dias
Criciúma, Brasil buscojobs Brasil Tempo inteiroOverviewRain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We’ve raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B to fuel our next stage of hypergrowth. We are seeking a skilled and driven...
-
Senior Security Operations Engineer
Há 4 dias
Região Geográfica Imediata de Criciúma, Brasil Canonical Tempo inteiroJoin to apply for the Senior Security Operations Engineer role at Canonical 3 months ago Be among the first 25 applicants Join to apply for the Senior Security Operations Engineer role at Canonical We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of...
-
Senior Backend Engineer
2 semanas atrás
Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiroOverview Senior Backend Engineer (PHP / Laravel) – Location: Brazil (Remote) Our trusted high-growth healthcare technology partner is seeking a talented Senior Backend Engineer (PHP / Laravel) to join their dynamic team. This innovative company is dedicated to revolutionizing the healthcare industry through cutting-edge technology solutions. ...
-
Senior Cybersecurity Engineer
2 semanas atrás
Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiroAbout the role Yisrael Technology is looking for a highly skilled Senior Cybersecurity Engineer to join a remote project supporting one of our U.S.-based clients. You'll be tasked with safeguarding infrastructure, conducting threat modeling, and implementing best practices in cloud security across enterprise-level systems. Responsibilities Design, implement,...
-
Região Geográfica Imediata de Criciúma, Brasil beBeeCryptographer Tempo inteiro US$108.000 - US$123.000Job Title:Senior Cryptography and Security SpecialistDescriptionThis is a unique opportunity to utilize your software engineering and cryptography skills in building and maintaining the security foundation that enables secure operations and compliance with international information security standards.You will work on enhancing the Ubuntu distribution and...
-
Senior Software Engineer .Net
Há 6 dias
Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiroAvenue Code is the leading software consultancy focused on delivering end-to-end development solutions for digital transformation across every vertical. We're privately held, profitable, and have been on a solid growth trajectory since day one. We care deeply about our clients, our partners, and our people. We prefer the word 'partner' over 'vendor', and our...
-
Senior Software Engineer .Net
Há 4 dias
Criciúma, Brasil buscojobs Brasil Tempo inteiroAvenue Code is the leading software consultancy focused on delivering end-to-end development solutions for digital transformation across every vertical. We’re privately held, profitable, and have been on a solid growth trajectory since day one. We care deeply about our clients, our partners, and our people. We prefer the word ‘partner’ over...
-
Automation Engineer
Há 2 dias
Criciúma, Brasil buscojobs Brasil Tempo inteiroOverview We are seeking a highly skilled Automation Engineer with strong expertise in automating infrastructure, applications, and workflows. The ideal candidate will have experience across configuration management, API development, Microsoft automation tools, and data governance frameworks, with additional exposure to data engineering and scripting....
-
Senior Mobile Developer
2 semanas atrás
Criciúma, Santa Catarina, Brasil buscojobs Brasil Tempo inteiroAbout the Role We are seeking a Senior Mobile Developer with strong expertise in Android and React Native to join our growing crypto and payments team. You'll play a key role in building and scaling mobile applications that power secure digital transactions. This is an exciting opportunity to work in the fast-paced world of crypto and fintech, where you'll...