Himalayas logo
Rain Technologies Inc.RI

Senior Application Security Engineer

Rain is a financial wellness company that offers employees on-demand access to their earned wages, aiming to reduce financial stress and eliminate the need for predatory loans.

Rain Technologies Inc.

Employee count: 51-200

Brazil only

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We’ve raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B to fuel our next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join Rain’s growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain’s application and platform security posture.

This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Key Responsibilities:

  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
  • Integrate security checks into CI/CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives, such as container/Kubernetes hardening, RASP, and eBPF-based detection.
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web/API attacks).
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring, etc.).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain’s architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required Qualifications:

  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 3–5+ years of experience in application security, penetration testing roles, and/or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code review or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2/OpenID Connect.
  • Experience securing CI/CD pipelines and integrating AppSec tooling into SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and working within cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).

Preferred Qualifications:

  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bountytriage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM/AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).

Who We Are:

Rain is filled with people with a deeply rooted passion for our mission, who embrace diversity throughout our global team, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges everyday.

As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at HR-US@rain.us.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Location requirements

Hiring timezones

Brazil +/- 0 hours

About Rain Technologies Inc.

Learn more about Rain Technologies Inc. and their company culture.

View company profile

Rain is a leading provider of employee-centric financial wellness solutions, dedicated to empowering individuals to achieve financial freedom. The company's core offering is an employer-integrated earned wage access (EWA) platform that allows employees to access their earned wages on demand, rather than waiting for a traditional payday. This innovative service is designed to combat predatory financial products like payday loans and overdraft fees, which disproportionately affect the significant portion of the American workforce living paycheck to paycheck. By providing a responsible and transparent alternative, Rain helps workers manage unexpected expenses, reduce financial stress, and improve their overall financial health. The platform seamlessly integrates with major payroll and timekeeping systems across the United States, simplifying implementation for employers and ensuring a smooth, user-friendly experience for employees. This integration minimizes the operational burden on HR and payroll departments while delivering a valuable benefit that has been shown to increase employee retention, boost productivity, and attract more job applicants.

Founded in 2019, Rain has experienced rapid growth, partnering with hundreds of middle-market and enterprise organizations, including prominent names like McDonald's and Marriott. The company has successfully onboarded millions of employees and disbursed billions of dollars in earned wages. Beyond its primary EWA service, Rain offers a comprehensive suite of financial wellness tools within its app. These include resources for budgeting, expense tracking, financial education, and personalized coaching, all aimed at helping users build healthier financial habits and long-term stability. Rain's mission extends beyond simply providing early access to pay; it is focused on fostering a more engaged and financially secure workforce. The company's commitment to this mission is reflected in its continuous innovation, with plans to introduce new products such as savings accounts and credit-building tools. By placing employee well-being at the forefront of its strategy, Rain is not only transforming the way people get paid but also contributing to a more equitable and supportive work environment for millions across the country.

Employee benefits

Learn about the employee benefits and perks provided at Rain Technologies Inc..

View benefits

Top-tier coverage

We cover 95% of Medical, Dental, and Vision premiums.

Home office setup

One-time stipend to create a space that works for you.

401(k) with matching

Invest in your future, just like we're investing in ours.

Unlimited PTO

Because time to rest and reset is just as important as time to ship.

View Rain Technologies Inc.'s employee benefits
Claim this profileRain Technologies Inc. logoRI

Rain Technologies Inc.

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

6 remote jobs at Rain Technologies Inc.

Explore the variety of open remote roles at Rain Technologies Inc., offering flexible work options across multiple disciplines and skill levels.

View all jobs at Rain Technologies Inc.

Remote companies like Rain Technologies Inc.

Find your next opportunity by exploring profiles of companies that are similar to Rain Technologies Inc.. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Rain Technologies Inc. hiring Senior Application Security Engineer • Remote (Work from Home) | Himalayas