Remote opportunity at
RainSecurity Engineer - AppSec
Rain operates a global stablecoin payments platform for neobanks, developers, enterprises, and AI agents, enabling instant and compliant money movement through global cards, wallets, and cross-border…
Career Tools
About This Role
Rain operates a global stablecoin payments platform for neobanks, developers, enterprises, and AI agents, enabling instant and compliant money movement through global cards, wallets, and cross-border rails. The company recently raised a Series C funding round and holds Principal Membership with both Visa and Mastercard. Rain seeks a remote Security Engineer - AppSec to serve as the primary application security authority for non-blockchain systems. This position focuses on safeguarding backend…
Job Description
Rain operates a global stablecoin payments platform for neobanks, developers, enterprises, and AI agents, enabling instant and compliant money movement through global cards, wallets, and cross-border rails. The company recently raised a Series C funding round and holds Principal Membership with both Visa and Mastercard.
Rain seeks a remote Security Engineer - AppSec to serve as the primary application security authority for non-blockchain systems. This position focuses on safeguarding backend services, edge defenses, and APIs that process financial transactions for global users. The ideal candidate acts as the quality gate for security findings, filters false positives from AI-driven red team outputs, hardens infrastructure, and collaborates closely with the Security Operations group to establish clear configuration rules and detection mechanisms.
This role suits an experienced engineer who enjoys hands-on technical work, prefers building automated checks over drafting long documentation, and maintains strong working relationships with engineering teams while upholding strict security standards. Daily responsibilities include reviewing red team findings, writing secure configuration baselines, managing edge defenses such as WAF and rate limiting, and expanding PR security gates to block vulnerabilities prior to code merges.
Responsibilities
- Review and triage red team findings by reproducing issues, removing false positives, setting severity levels, and writing actionable tickets
- Harden backend services and APIs, particularly those handling financial transactions
- Manage edge defenses including DDoS protection, rate limiting, Web Application Firewall rules, and abuse controls
- Develop secure configuration baselines for cloud environments, codebases, and SaaS platforms, turning them into automated validation checks
- Expand pull request security gates to intercept and block vulnerabilities prior to merging
- Govern attack surface coverage and perform architecture reviews on new or high-risk systems
- Evaluate, test, and select security tooling through build, buy, or adopt decisions
Requirements
- At least four years of professional experience in application security, product security, or security-focused backend engineering
- Demonstrated history of owning security decisions and influencing senior engineers on architectural changes
- Proficiency in reading unfamiliar codebases written in TypeScript or Node.js to identify critical bugs
- Hands-on technical background in cloud security, specifically with GCP, along with Terraform and edge defense mechanisms
- Practical experience conducting threat modeling, architecture reviews, and security tool evaluations
- Familiarity with leveraging AI tools heavily in daily workflows
Qualifications
- Background working in fintech, payments, or card issuing domains
- Familiarity with PCI DSS compliance requirements
- Prior experience in penetration testing, bug bounty programs, or red teaming
- Track record of building security scanners, static analysis rules, or LLM-based review solutions
- Knowledge of AI security principles for autonomous agents or agentic payments
- Experience managing corporate security alongside IT functions
Core Skills
Benefits
- Unlimited time off with a mandatory minimum of 10 vacation days per year
- Flexible working arrangements allowing remote work, office attendance, or a hybrid schedule
- A home workspace setup stipend for new employees
- Health, dental, and vision insurance coverage at 95% for employees and 90% for dependents for US staff
- Company-subsidized life insurance plan
- 401(k) retirement plan featuring a 4% company match
- Equity option plan for all team members
- Monthly health and wellness stipend for fitness, gym memberships, and related activities
- DoorDash credit provided for in-office meals
- Domestic and international team summits and offsites
Frequently Asked Questions
Answers are based only on the employer’s listing; where it doesn’t say, neither do we.
Is this position remote?
Yes, this role is fully remote with flexible working options that allow employees to work from home, visit an office, or combine both.
What is the employment type for this job?
This is a full-time position.
What salary does Rain offer for this Security Engineer role?
The salary is not stated in the job posting.
What level of experience is required?
Candidates must have four or more years of experience in application security, product security, or security-minded backend engineering.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.