MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Senior Application Security Engineer

Rain Technologies Inc.

Full-time
USA
security
engineer
nodejs
python
react native
Apply for this position

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. Weve raised nearly $400M in fundingincluding the largest Series A in fintech historyand just closed our Series B to fuel our next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join Rains growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rains application and platform security posture.

This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Key Responsibilities:

  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.

  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.

  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.

  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.

  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.

  • Build and maintain a security issues dashboard to track remediation status and metrics.

  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web/API attacks).

  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring, etc.).

  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rains architecture.

  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).

  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required Qualifications:

  • Fluent English, including strong verbal and written skills.

  • Strong problem-solving and analytical mindset.

  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.

  • 35+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.

  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).

  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).

  • Proven expertise in performing code review or security assessments and writing clear reports.

  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.

  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.

  • Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.

  • Solid knowledge of containerization and Kubernetes security fundamentals.

  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.

  • Comfortable with Agile development methodologies and working within cross-functional squads.

  • Software supply chain security (e.g., SBOM, artifact signing).

Preferred Qualifications:

  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.

  • AWS, GCP, or Azure Security Specialty certification.

  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).

  • Experience implementing RASP or eBPF runtime protection tools.

  • Exposure to LLM/AI security considerations and secure code generation practices.

  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).

Who We Are:

Rain is filled with people with a deeply rooted passion for our mission, who embrace diversity throughout our global team, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges everyday.

As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at [emailprotected].

Apply for this position
Bookmark Report

About the job

Full-time
USA
Senior Level
Posted 11 hours ago
security
engineer
nodejs
python
react native

Apply for this position

Bookmark
Report
Enhancv advertisement

30,000+
REMOTE JOBS

Unlock access to our database and
kickstart your remote career
Join Premium

Senior Application Security Engineer

Rain Technologies Inc.

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. Weve raised nearly $400M in fundingincluding the largest Series A in fintech historyand just closed our Series B to fuel our next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join Rains growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rains application and platform security posture.

This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Key Responsibilities:

  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.

  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.

  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.

  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.

  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.

  • Build and maintain a security issues dashboard to track remediation status and metrics.

  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web/API attacks).

  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring, etc.).

  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rains architecture.

  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).

  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required Qualifications:

  • Fluent English, including strong verbal and written skills.

  • Strong problem-solving and analytical mindset.

  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.

  • 35+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.

  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).

  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).

  • Proven expertise in performing code review or security assessments and writing clear reports.

  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.

  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.

  • Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.

  • Solid knowledge of containerization and Kubernetes security fundamentals.

  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.

  • Comfortable with Agile development methodologies and working within cross-functional squads.

  • Software supply chain security (e.g., SBOM, artifact signing).

Preferred Qualifications:

  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.

  • AWS, GCP, or Azure Security Specialty certification.

  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).

  • Experience implementing RASP or eBPF runtime protection tools.

  • Exposure to LLM/AI security considerations and secure code generation practices.

  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).

Who We Are:

Rain is filled with people with a deeply rooted passion for our mission, who embrace diversity throughout our global team, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges everyday.

As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at [emailprotected].

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Reviews
Job Alerts

Job Skills
Jobs by Location
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.