HimalayasHimalayas logo
DonorboxDO

Application Security Engineer

Donorbox simplifies online fundraising for nonprofits with a powerful suite of tools to increase donations and strengthen donor relationships.

Donorbox

Employee count: 51-200

Brazil only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Donorbox

Donorbox is a leading fundraising platform and donor management system for nonprofit organizations. Our mission is to accelerate positive impact worldwide by helping nonprofits become highly effective at raising funds and managing their supporter base. Since 2014, we have powered more than 100,000 global organizations to raise over $3B in donations. 🚀

Our fast-growing company is profitable and bootstrapped with a healthy run rate. We have a fully distributed and diverse 150-person team based in 16+ states and 23+ countries. In 2026, Donorbox was named by Built In as one of the Best Places to Work in Washington, DC.

🏅 Donorbox is rated the #1 software for fundraising, donor management, and nonprofit payment on G2 based on hundreds of verified customer reviews — a reflection of the care our team puts into building products that nonprofits trust.

The Role

We’re looking for a high-autonomy Application Security Engineer to help with full-stack security (edge + cloud + app); both defensive and offensive; of our global PaaS platform.

This is not a “ticket-driven” role. You are someone who:

  • Identifies risks before they’re reported
  • Prioritizes based on real-world impact
  • Takes initiative to protect the platform and our customers

You will contribute to our security roadmap end-to-end, balancing platform availability, customer experience, and data protection across a globally distributed infrastructure.

Responsibilities

  • Edge Governance & Traffic Analysis: Own the Cloudflare stack. Monitor traffic patterns to identify threats (DDoS, credential stuffing, scraping) and implement real-time countermeasures. You know how to mitigate a threat without shutting down a "big customer."
    Cloudflare Mastery: You don't just click toggles; you write Cloudflare Workers and custom WAF expressions to intercept sophisticated L7 attacks before they hit our origin.
  • Vulnerability Ecosystem (Intigriti): Lead our 3rd-party researcher program. Triage and validate reports, ensuring we reward the first reporter and immediately implement "kills" at the source (e.g., via Cloudflare rules) to stop the noise.
    You are the bridge between external researchers and our internal dev teams. You move fast to validate, reward, and—most importantly—virtual-patch vulnerabilities at the edge while the permanent fix is escalated to the dev team.
  • Offensive Strategy & Internal Pen-tests: Proactively identify weaknesses across our systems Design and execute targeted internal penetration tests. Focus on real-world attack paths. You will identify and escalate flawed business logic. Not checkbox testing. Partner with engineering teams to ensure fixes are implemented effectively. You see the gaps in how the product is designed and advocate for systemic fixes.
  • Application & Dependency Security: Monitor and respond to vulnerabilities in application dependencies and frameworks (e.g., reviewing alerts from tools like Dependabot and validating real impact). Evaluate real-world impact of supply chain risks (not all CVEs are equal). Work with engineering teams to prioritize and remediate issues effectively. Improve processes around dependency management and secure development practices
  • Incident Response & Global Collaboration: Communicate clearly and effectively under pressure. Coordinate across time zones with SRE, Support, and Product teams. In a crisis, you act decisively but keep the right stakeholders informed. Investigate and respond to cloud-native security signals (e.g., AWS GuardDuty, unusual IAM or network activity)

Qualifications & Experience

  • Experience with Cloudflare at scale (WAF, Workers, rate limiting, bot management)
  • Experience with AWS security tooling (e.g., GuardDuty, IAM analysis, CloudTrail)
  • Familiarity with dependency and supply chain security practices
  • Familiarity with bug bounty platforms (e.g., Intigriti, HackerOne)
  • Experience with vendor-approved security scanners and integrating them into workflows (e.g., SAST, DAST, dependency scanning)
  • Familiarity with compliance automation tools (e.g., Vanta, Drata)
  • Compliance Literacy: Knowledge of PCI DSS or SOC II frameworks. You understand how to translate technical security controls into audit-ready evidence.

Details

  • Fully remote based in Mexico or Brazil
  • Salary depending on experience and location

Benefits & Perks

  • Fully remote work from the comfort of your home
  • Eligibility for employee equity plan (stock options)
  • Reimbursement package for home office expenses and professional development, up to $1.5k
  • Generous time off policy of 21 days (birthday included 🎉), 8 holidays of your choice, and 2 paid volunteer days
  • Wellness program with fitness and mindfulness classes
  • Love your work and our mission of serving nonprofits!

The Application Process

We have 6 stages:

  1. Apply here and fill out our questions to tell us about you!
  2. Prescreen Call with the Talent Team
  3. Interview with Hiring Manager
  4. Assignment
  5. Panel/Final Interview
  6. Background & Reference Checks

If this sounds like the right role for you, please apply today and let us know why. We look forward to hearing from you!

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Location requirements

Hiring timezones

Brazil +/- 0 hours

About Donorbox

Learn more about Donorbox and their company culture.

View company profile

Since our inception in 2014, we at Donorbox have been on a simple yet profound mission: to support nonprofit organizations in their efforts to make a difference in the world. Our journey began with the vision of simplifying charitable giving, enabling nonprofits to maximize their fundraising potential while minimizing the operational hurdles often associated with donation collection.

We understand that fundraising is about more than just transactions; it’s about relationships. That's why we’ve developed an all-in-one donation software suite that empowers over 100,000 nonprofits globally to unlock more donations and foster deeper connections with their supporters. Our platform simplifies the donation process for both organizations and their supporters, allowing nonprofits to focus on what they do best: creating impactful change.

Claim this profileDonorbox logoDO

Donorbox

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

8 remote jobs at Donorbox

Explore the variety of open remote roles at Donorbox, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Donorbox

Remote companies like Donorbox

Find your next opportunity by exploring profiles of companies that are similar to Donorbox. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan