About the job
About Rain
At Rain, we are pioneering the future of global payments, creating an innovative infrastructure that enables real-world applications of stablecoins. Our dedicated team comprises passionate builders and seasoned founders committed to revolutionizing how financial transactions occur. We collaborate with fintech companies, neobanks, and institutions to launch solutions that are global, inclusive, and efficient. Join us to make a significant impact in a rapidly growing company backed by leading investors in fintech, crypto, and SaaS.
Our Ethos
We promote an open and collaborative work environment where every team member can thrive. You will have the opportunity to steer your career path in alignment with your aspirations while contributing to the company's vision.
Key Responsibilities
As a Security Engineer specializing in Application Security, you will play a pivotal role in integrating security throughout Rain’s engineering lifecycle and ensuring the delivery of secure, reliable applications:
- Conduct thorough application security assessments, including vulnerability scanning, code reviews, and threat modeling in collaboration with engineering teams.
- Work closely with product and development teams to facilitate remediation and assist in understanding and addressing security vulnerabilities effectively.
- Implement and scale automated security tools across CI/CD pipelines (SAST, DAST, SCA, IaC) to enhance proactive security measures.
- Create and maintain application security standards, patterns, and protocols that mitigate risk while enabling fast delivery.
- Lead threat modeling and risk assessments for new features, APIs, and services.
- Partner with Cloud & Infrastructure Security teams to ensure alignment of security controls and support cloud-native security needs.
- Assist in incident response for application-level security events, conduct root-cause analysis, and develop mitigation strategies.
- Contribute to the development of internal training programs to enhance secure coding practices and developer security awareness.
- Monitor and report on key security metrics, trends, and insights for continuous improvement to leadership.

