Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Rain

Security Engineer – AppSec

Rain

. Serve as Rain's application security expert and quality bar for non-chain security findings .

Posted 10/5/2026full-timeNew York City • New York • United StatesMid-LevelSenior💰 $190,000 - $240,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security, particularly in backend services and APIs, with a focus on threat modeling, security tool evaluation, and automated security checks. Proven ability to influence engineering teams and uphold security quality standards while collaborating effectively with security operations.

Highest-signal resume keywords
Application Security ExpertiseTypeScript/Node.js Vulnerability AssessmentCloud Security (GCP)Terraform ProficiencyWAF and Edge Defense Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityThreat ModelingVulnerability AssessmentSecurity Tool EvaluationAutomated Security ChecksConfiguration BaselinesDDoS ProtectionRate LimitingSecurity FixesArchitecture Reviews
Soft Skills
CollaborationInfluencing Senior EngineersQuality Standards Enforcement
Tools & Technologies
TerraformWAFAI ToolsSecurity ScannersStatic Analysis Tools
Certifications & Qualifications
PCI DSS Experience
Industry Keywords
FintechPaymentsCard IssuingRed Team ExperiencePentest Experience

Tech Stack

Tools & technologies
CloudGoogle Cloud PlatformJavaScriptNode.jsTerraformTypeScript

About the role

Key responsibilities & impact
  • Serve as Rain's application security expert and quality bar for non-chain security findings
  • Review red team findings before they reach engineers
  • Reproduce findings, eliminate false positives, assign severity, and write actionable remediation tickets
  • Improve the scoring used to grade security findings
  • Harden backend services and APIs, especially money-moving paths
  • Write security fixes when appropriate
  • Own edge defenses including DDoS protection, rate limiting, WAF rules, and abuse controls
  • Write secure configuration baselines for cloud, code, and SaaS
  • Convert configuration baselines into automated checks
  • Expand the pull-request security gate to block more vulnerabilities before merge
  • Own attack-surface coverage
  • Conduct architecture reviews for new and high-risk systems
  • Evaluate, select, adopt, or build security tools
  • Collaborate with Security Operations by providing high-quality findings and configuration rules for detection development
  • Hold security quality standards with engineers and build agreement around necessary fixes

Requirements

What you’ll need
  • 4+ years in application security, product security, or security-minded backend engineering
  • Experience owning security decisions and influencing senior engineers
  • Ability to read unfamiliar TypeScript/Node.js codebases and identify meaningful vulnerabilities
  • Hands-on cloud security, ideally GCP
  • Experience with Terraform
  • Experience with WAFs, rate limiting, and other edge defenses
  • Experience with threat models or architecture reviews
  • Experience running security tool evaluations and assessing tool cost-effectiveness
  • Preference for shipping automated security checks rather than documentation
  • Heavy use of AI tools with appropriate skepticism
  • Fintech, payments, or card issuing background is a bonus
  • PCI DSS experience is a plus
  • Pentest, bug bounty, or red team experience is a bonus
  • Experience building security scanners, static analysis rules, or LLM-based review tools is a bonus
  • AI security for agents and agentic payments, or corporate security alongside IT, is a bonus
  • Must be legally authorized to work in the United States for any employer without restrictions
  • Must answer whether employer sponsorship is required
  • Application form asks whether the candidate graduated from a 4-year university

Benefits

Comp & perks
  • Unlimited time off, with a requirement to take at least 10 days
  • Flexible working; work from home, come into an office, or both
  • Home workspace setup stipend for new Rainmakers
  • For US Rainmakers, 95% coverage of health, dental, and vision plan costs and 90% for dependents
  • 100% company-subsidized life insurance for US Rainmakers
  • 401(k) with a 4% company match
  • Equity option plan
  • Monthly health and wellness stipend
  • Lunch and dinner covered with a DoorDash credit for employees working from the office
  • Domestic and international team and company offsites
  • Bonus offered
  • Equity offered