Talent.com
A vaga não está disponível no seu país.
Senior Application Security Engineer

Senior Application Security Engineer

RainSão Bernardo do Campo, São Paulo, Brasil
Há 26 dias
Descrição da vaga

Get AI-powered advice on this job and more exclusive features.Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus.

We've raised nearly $400M in funding—including the largest Series A in fintech history—and just closed our Series B to fuel our next stage of hypergrowth.We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team.

This role demands a proactive approach to secure software development and cloud-native defense.

You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain's application and platform security posture.This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.Key ResponsibilitiesCollaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.Integrate security checks into CI / CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.Contribute to runtime security initiatives, such as container / Kubernetes hardening, RASP, and eBPF-based detection.Build and maintain a security issues dashboard to track remediation status and metrics.Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (e.g., exploited vuln, credential stuffing, web / API attacks).

Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring).

Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).

Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required QualificationsStrong problem-solving and analytical mindset.Excellent communication skills to convey security risks to technical and non-technical stakeholders.3–5+ years of experience in application security, penetration testing roles, and / or secure code development, including work with QA teams.Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).

Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).

Proven expertise in performing code review or security assessments and writing clear reports.Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2 / OpenID Connect.Experience securing CI / CD pipelines and integrating AppSec tooling into SDLC.Solid knowledge of containerization and Kubernetes security fundamentals.Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.Comfortable with Agile development methodologies and working within cross-functional squads.Software supply chain security (e.g., SBOM, artifact signing).

Preferred QualificationsCertifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.AWS, GCP, or Azure Security Specialty certification.Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).

Experience implementing RASP or eBPF runtime protection tools.Exposure to LLM / AI security considerations and secure code generation practices.Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).

Who We AreRain is filled with people with a deeply rooted passion for our mission, who embrace diversity throughout our global team, and grow personally and professionally.

We own what we do and let data guide our actions while working quickly and adapting to new challenges everyday.As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws.

If you need assistance or accommodation due to a disability, you may contact us at

  • 're removing barriers and enabling growth for a diverse, inclusive team.

#J-18808-Ljbffr

Criar um alerta de emprego para esta pesquisa

Application Engineer • São Bernardo do Campo, São Paulo, Brasil

Vagas relacionadas
  • Promovida
QA / Red Teaming Expert

QA / Red Teaming Expert

Innodata Inc.cabreúva, estado de são paulo, br
We are seeking highly analytical and detail-oriented professionals with hands-on experience in.Red Teaming, Prompt Evaluation. The ideal candidate will help us rigorously test and evaluate AI-genera...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Analista de Processos Senior

Analista de Processos Senior

FOURSYSBarueri, SP, Osasco (microrregião); São Paulo (estado), BR
A Foursys é um time apaixonado por inovação, design e transformação digital.Na Foursys, celebramos a diversidade e acreditamos que são as diferentes ideias e perspecti...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Senior DevOps Engineer

Senior DevOps Engineer

Sankhya Gestão de Negóciossantana de parnaíba, estado de são paulo, br
DTI da Sankhya, você terá a missão de contribuir significativamente com a evolução da nossa cultura de DevOps, elevando a maturidade de processos, ferramentas e práticas. Essa posição terá forte imp...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Application Security Engineer

Application Security Engineer

DefensepointOsasco, São Paulo, Brasil
Be among the first 25 applicantsDirect message the job poster from DefensePointWe are seeking an Application Security Engineer to join a leading company in the AppSec industry and work on an exciti...Mostre maisÚltima atualização: 4 dias atrás
  • Promovida
Security Engineer

Security Engineer

Cloudwalk, Inc.São Paulo, Brasil
About CloudWalk : We are not just another fintech unicorn.We are a pack of dreamers, makers, and tech enthusiasts building the future of payments. With millions of happy customers and a hunger for inn...Mostre maisÚltima atualização: 25 dias atrás
  • Promovida
Application Engineer

Application Engineer

AdvantechSão Paulo, SP, São Paulo (microrregião); São Paulo (estado), BR
Analista de Aplicação Pleno IIoT.A Advantech está em busca de um.O profissional desempenha um papel fundamental ao fornecer suporte técnico especializado e consultivo aos clientes e parceiros da em...Mostre maisÚltima atualização: 10 dias atrás
  • Promovida
On-Site IT Support Engineer

On-Site IT Support Engineer

TECEZEGuarulhos, SP, Guarulhos (microrregião); São Paulo (estado), BR
We are looking for a dedicated and proactive.This role ensures smooth IT operations, continuity of services, and timely resolution of incidents during the designated support period.The engineer wil...Mostre maisÚltima atualização: 7 dias atrás
  • Promovida
Desenvolvedor C# Especialista

Desenvolvedor C# Especialista

FOURSYSBarueri, SP, Osasco (microrregião); São Paulo (estado), BR
A Foursys é um time apaixonado por inovação, design e transformação digital.Na Foursys, celebramos a diversidade e acreditamos que são as diferentes ideias e perspecti...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Analista de Infraestrutura PL (Command Center / NOC) - Presencial - Alphaville

Analista de Infraestrutura PL (Command Center / NOC) - Presencial - Alphaville

Iterative;Barueri, SP, Osasco (microrregião); São Paulo (estado), BR
Analista de Infraestrutura PL (Command Center / NOC) - Presencial - Alphaville - Segunda à Sexta.Responsabilidades e atribuições. Executar a gestão de eventos e incidentes de ti.Gestão de War room, es...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Instalação de Alarmes em Santa Isabel

Instalação de Alarmes em Santa Isabel

Cronoshare.com.brSanta Isabel, São Paulo, br
Cronoshare é uma plataforma on-line para profissionais que desejam encontrar novos clientes.Estamos procurando um(a) Instalação de Alarmes em Santa Isabel e arredores. Não há nenhum custo para perte...Mostre maisÚltima atualização: há mais de 30 dias
  • Promovida
Senior Application Security Engineer

Senior Application Security Engineer

RainJundiaí, São Paulo, Brasil
Get AI-powered advice on this job and more exclusive features.Rain is the fastest-growing earned wage access (EWA) fintech in the U. We've raised nearly $400M in funding—including the largest Series...Mostre maisÚltima atualização: 26 dias atrás
  • Promovida
  • Nova!
Application Security Engineer

Application Security Engineer

MonksSão Paulo, Brasil
Please note that we will never request payment or bank account information at any stage of the recruitment process.As we continue to grow our teams, we urge you to be cautious of fraudulent job pos...Mostre maisÚltima atualização: 4 horas atrás
  • Promovida
Application Security Specialist

Application Security Specialist

Unico IdSão Paulo, Brasil
A Unico é a maior rede de verificação de identidade do mundo e um pilar de confiança na sociedade digital.Com soluções baseadas em biometria facial, machine learning e camadas reforçadas de seguran...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Security Engineer

Security Engineer

AliceGuarulhos, São Paulo, Brasil
AliceNa Alice, nossa missão é tornar o mundo mais saudável.Somos uma empresa de tecnologia que oferece planos de saúde empresariais. Nossa plataforma de cuidado contínuo garante que cada membro rece...Mostre maisÚltima atualização: 2 dias atrás
  • Promovida
Azure Security Engineer

Azure Security Engineer

Tata Consultancy ServicesSão Paulo, Brasil
Come to one of the biggest IT Services companies in the world Here you can transform your careerWhy to join TCS?.Here at TCS we believe that people make the difference, that's why we live a culture...Mostre maisÚltima atualização: 25 dias atrás
  • Promovida
SAP Developer

SAP Developer

Insight Globalcaieiras, estado de são paulo, br
This is a fully remote role with one of our US clients.Years with SAP Commerce (Hybris) Experience.The Senior Software Engineer for SAP Commerce (Hybris) is responsible for the reliability, perform...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Senior Security Engineer Latam

Senior Security Engineer Latam

WizdaaSão Paulo, Brasil
Let's be direct : We're looking for a technical powerhouse.If you're the developer who : Is the clear technical leader on your teamConsistently solves problems others can't crackShips complex features...Mostre maisÚltima atualização: 14 dias atrás
  • Promovida
Incident Analyst Senior (Applications)

Incident Analyst Senior (Applications)

TSYSSão Paulo, SP, São Paulo (microrregião); São Paulo (estado), BR
TSYS, a Global Payments company, is the payment stack for the future and operating in more than 75 countries around the world, we process billions of card transactions each year.We are looking for ...Mostre maisÚltima atualização: 19 dias atrás
  • Promovida
System Engineer (Hosting)

System Engineer (Hosting)

Think Hugecaieiras, estado de são paulo, br
Fully Remote : Experience working in Hosting world is mandatory.VPS / Linux / Windows and Solus / KVM / WHMCS.Linux / Windows / Network Administrator. To speed things up, you can share your detailed CV at recru...Mostre maisÚltima atualização: 1 dia atrás
  • Promovida
Senior ServiceNow Developer

Senior ServiceNow Developer

apricot jamsanto andré, estado de são paulo, br
Apricot Jam | Minneapolis-based | Global Delivery.Full-Time | Remote | Contractor or FTE.Brazil or broader LATAM (English-speaking). Our mission is to foster creativity and ignite it, empowering ind...Mostre maisÚltima atualização: 1 dia atrás