Security Engineer

RAIN, Inc
New York, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Burp Suite Cloud Computing Cloud Computing Security Code Review Open Web Application Security Systems Development Life Cycle Cloud Services Secure Coding Mobile Security Software Engineering Tripwire
+6 more
Sonatype Software Security GWAPT Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

As a Security Engineer with a focus on Application Security, you’ll be a key contributor in embedding security into Rain’s engineering lifecycle and supporting delivery of secure, trusted applications:

  • Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams
  • Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently
  • Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left
  • Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery
  • Drive threat modeling and risk assessments for new features, APIs, and services
  • Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements
  • Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies
  • Help build internal training and awareness programs to elevate secure coding and developer security literacy
  • Track and surface key security metrics, trends, and continuous improvement insights to leadership

Requirements

  • 4-8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications
  • Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis
  • Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10)
  • Experience driving or participating in threat modeling and secure design reviews
  • Familiarity with cloud concepts and securing cloud workloads
  • Collaborative mindset - you enjoy working closely with engineers to co-create practical security solutions

  • Practical understanding of SDLC and integrating security into development workflows
  • Ability to independently identify, prioritize, and drive remediation on critical findings
  • Experience balancing security risk with business and technical constraints

Nice to have, but not mandatory

  • Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling)
  • Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements
  • Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar
  • Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls
  • Prior experience in fintech, payments, or highly regulated environments
  • Exposure to API security tooling and design best practices

Benefits & conditions

Unlimited time off Unlimited vacation can be daunting, so we require Rainmakers to take 10 days minimum for themselves.

Flexible working We support a flexible workplace - work from home, come into an office, or both. We want everyone to work in an environment where they’re their most confident and productive selves. New Rainmakers receive a stipend to set up a comfortable home workspace.

Easy to access benefits For US Rainmakers, we cover 95% of your health, dental, and vision plan costs and 90% for your dependents, plus a 100% company-subsidized life insurance plan.

Retirement goals Plan for the future with confidence. We offer a 401(k) with a 4% company match.

About the company

Rain is the global stablecoin payments platform for enterprises, neobanks, platforms, developers, and AI agents. Our technology allows partners to move, store, and use stablecoins instantly and compliantly through global payment cards, rewards, on/offramps, wallets, and cross-border rails. As both a Visa and Mastercard Principal Member, Rain issues cards that work at more than 175 million merchant locations in over 220 countries and territories. Built natively for stablecoins and trusted by more than 100 organizations worldwide, Rain delivers secure, scalable infrastructure that makes money move freely and instantly around the world.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · World Congress 2024

3:44 min

Integrating static security scanning in the build phase

Milecia Mcgregor · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all