> Markdown version of [/jobs/ext/2720572-security-engineer](https://www.wearedevelopers.com/jobs/ext/2720572-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** RAIN, Inc - **Location:** New York, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Burp Suite, Cloud Computing, Cloud Computing Security, Code Review, Open Web Application Security, Systems Development Life Cycle, Cloud Services, Secure Coding, Mobile Security, Software Engineering, Tripwire, Sonatype, Software Security, GWAPT, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-engineer-rain-xyz-7849287 ## About the Role * 4-8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications * Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis * Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10) * Experience driving or participating in threat modeling and secure design reviews * Familiarity with cloud concepts and securing cloud workloads * Collaborative mindset - you enjoy working closely with engineers to co-create practical security solutions * Practical understanding of SDLC and integrating security into development workflows * Ability to independently identify, prioritize, and drive remediation on critical findings * Experience balancing security risk with business and technical constraints Nice to have, but not mandatory * Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling) * Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements * Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar * Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls * Prior experience in fintech, payments, or highly regulated environments * Exposure to API security tooling and design best practices ## Description As a Security Engineer with a focus on Application Security, you'll be a key contributor in embedding security into Rain's engineering lifecycle and supporting delivery of secure, trusted applications: * Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams * Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently * Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left * Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery * Drive threat modeling and risk assessments for new features, APIs, and services * Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements * Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies * Help build internal training and awareness programs to elevate secure coding and developer security literacy * Track and surface key security metrics, trends, and continuous improvement insights to leadership ## Related Videos - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Open sourcing a library: how hard can that be?](https://www.wearedevelopers.com/videos/1058-open-sourcing-a-library-how-hard-can-that-be) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)