FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security, particularly in backend services and APIs, with a focus on threat modeling, security tool evaluation, and automated security checks. Proven ability to influence engineering teams and uphold security quality standards while collaborating effectively with security operations.
Highest-signal resume keywords
Application Security ExpertiseTypeScript/Node.js Vulnerability AssessmentCloud Security (GCP)Terraform ProficiencyWAF and Edge Defense Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityThreat ModelingVulnerability AssessmentSecurity Tool EvaluationAutomated Security ChecksConfiguration BaselinesDDoS ProtectionRate LimitingSecurity FixesArchitecture Reviews
Soft Skills
CollaborationInfluencing Senior EngineersQuality Standards Enforcement
Tools & Technologies
TerraformWAFAI ToolsSecurity ScannersStatic Analysis Tools
Certifications & Qualifications
PCI DSS Experience
Industry Keywords
FintechPaymentsCard IssuingRed Team ExperiencePentest Experience
Tech Stack
Tools & technologiesCloudGoogle Cloud PlatformJavaScriptNode.jsTerraformTypeScript
About the role
Key responsibilities & impact- Serve as Rain's application security expert and quality bar for non-chain security findings
- Review red team findings before they reach engineers
- Reproduce findings, eliminate false positives, assign severity, and write actionable remediation tickets
- Improve the scoring used to grade security findings
- Harden backend services and APIs, especially money-moving paths
- Write security fixes when appropriate
- Own edge defenses including DDoS protection, rate limiting, WAF rules, and abuse controls
- Write secure configuration baselines for cloud, code, and SaaS
- Convert configuration baselines into automated checks
- Expand the pull-request security gate to block more vulnerabilities before merge
- Own attack-surface coverage
- Conduct architecture reviews for new and high-risk systems
- Evaluate, select, adopt, or build security tools
- Collaborate with Security Operations by providing high-quality findings and configuration rules for detection development
- Hold security quality standards with engineers and build agreement around necessary fixes
Requirements
What you’ll need- 4+ years in application security, product security, or security-minded backend engineering
- Experience owning security decisions and influencing senior engineers
- Ability to read unfamiliar TypeScript/Node.js codebases and identify meaningful vulnerabilities
- Hands-on cloud security, ideally GCP
- Experience with Terraform
- Experience with WAFs, rate limiting, and other edge defenses
- Experience with threat models or architecture reviews
- Experience running security tool evaluations and assessing tool cost-effectiveness
- Preference for shipping automated security checks rather than documentation
- Heavy use of AI tools with appropriate skepticism
- Fintech, payments, or card issuing background is a bonus
- PCI DSS experience is a plus
- Pentest, bug bounty, or red team experience is a bonus
- Experience building security scanners, static analysis rules, or LLM-based review tools is a bonus
- AI security for agents and agentic payments, or corporate security alongside IT, is a bonus
- Must be legally authorized to work in the United States for any employer without restrictions
- Must answer whether employer sponsorship is required
- Application form asks whether the candidate graduated from a 4-year university
Benefits
Comp & perks- Unlimited time off, with a requirement to take at least 10 days
- Flexible working; work from home, come into an office, or both
- Home workspace setup stipend for new Rainmakers
- For US Rainmakers, 95% coverage of health, dental, and vision plan costs and 90% for dependents
- 100% company-subsidized life insurance for US Rainmakers
- 401(k) with a 4% company match
- Equity option plan
- Monthly health and wellness stipend
- Lunch and dinner covered with a DoorDash credit for employees working from the office
- Domestic and international team and company offsites
- Bonus offered
- Equity offered
