Talent.com
Senior Application Security Engineer
Senior Application Security EngineerRAIN Technologies • Concord, CA, United States
Senior Application Security Engineer

Senior Application Security Engineer

RAIN Technologies • Concord, CA, United States
[job_card.1_day_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Senior Application Security Engineer

Rain is the fastest-growing earned wage access (EWA) fintech in the U.S., serving 3.5 million employees and backed by top investors like QED and Prosus. We've raised nearly $400M in fundingincluding the largest Series A in fintech historyand just closed our Series B to fuel our next stage of hypergrowth.

We are seeking a skilled and driven Senior Application Security Engineer to join Rain's growing Security team. This role demands a proactive approach to secure software development and cloud-native defense. You will partner closely with engineering and development squads, and work alongside our Cloud Security and GRC team members to improve Rain's application and platform security posture.

This position is technically grounded, requiring direct engagement in application-layer matters and security reviews, while also contributing to cloud security automation, awareness initiatives, and secure engineering practices across the SDLC.

Key Responsibilities :

  • Collaborate with development squads to validate vulnerabilities and provide actionable remediation guidance aligned with business risk.
  • Drive threat modeling sessions (e.g., STRIDE, PASTA) for critical systems and APIs.
  • Design, implement, and oversee automated processes for securely updating application and code dependencies, proactively mitigating issues and ensuring timely vulnerability remediation.
  • Integrate security checks into CI / CD pipelines (SAST, DAST, SCA, IaC), working with tools like Semgrep, Snyk, Trivy, and Burp Suite.
  • Contribute to runtime security initiatives, such as container / Kubernetes hardening, RASP, and eBPF-based detection.
  • Build and maintain a security issues dashboard to track remediation status and metrics.
  • Provide real-time support in the event of cybersecurity incidents impacting applications or cloud infrastructure (exploited vuln, credential stuffing, web / API attacks).
  • Partner with the Cloud Security team on security automation tasks and monitoring improvements (e.g., Security Hub remediation automations, DLP monitoring, etc.).
  • Conduct proactive research on new threats, vulnerabilities, and attack techniques relevant to Rain's architecture.
  • Collaborate with the GRC team to develop and deliver internal security awareness initiatives, phishing campaigns, and developer training (e.g., secure coding, API security).
  • Participate in the continuous improvement of AppSec maturity (e.g., aligning with OWASP SAMM, ISO 27001, or SOC 2 frameworks).

Required Qualifications :

  • Fluent English, including strong verbal and written skills.
  • Strong problem-solving and analytical mindset.
  • Excellent communication skills to convey security risks to technical and non-technical stakeholders.
  • 35+ years of experience in application security, penetration testing roles, and / or secure code development, including work with QA teams.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Semgrep, Burp, Snyk).
  • Deep understanding of web, mobile, and API vulnerabilities (OWASP Top 10, API Top 10, MITRE CWE).
  • Proven expertise in performing code review or security assessments and writing clear reports.
  • Proficiency in at least one backend language (e.g., Go, Python, Node.js) and understanding of React / React Native front-ends.
  • Familiarity with secure architecture of microservices, event-driven systems, and REST APIs using OAuth2 / OpenID Connect.
  • Experience securing CI / CD pipelines and integrating AppSec tooling into SDLC.
  • Solid knowledge of containerization and Kubernetes security fundamentals.
  • Understanding of cloud security (preferably AWS), including IAM principles, cloud-native service configurations, and network segmentation.
  • Comfortable with Agile development methodologies and working within cross-functional squads.
  • Software supply chain security (e.g., SBOM, artifact signing).
  • Preferred Qualifications :

  • Certifications such as OSCP, OSWE, GWAPT, CPTE, or CSSLP.
  • AWS, GCP, or Azure Security Specialty certification.
  • Familiarity with bug bounty triage and vulnerability management platforms (e.g., DefectDojo).
  • Experience implementing RASP or eBPF runtime protection tools.
  • Exposure to LLM / AI security considerations and secure code generation practices.
  • Familiarity with logging and monitoring tools (e.g., CloudWatch, Datadog, Grafana).
  • Who We Are :

    Rain is filled with people with a deeply rooted passion for our mission, who embrace diversity throughout our global team, and grow personally and professionally. We own what we do and let data guide our actions while working quickly and adapting to new challenges everyday.

    As part of our dedication to the diversity of our workforce, Rain is committed to Equal Employment Opportunity and does not discriminate based on race, religion, color, national origin, ethnicity, gender, sex (including pregnancy), protected veteran status, age, disability, sexual orientation, gender identity, gender expression, or any unlawful criterion existing under applicable federal, state, or local laws. If you need assistance or accommodation due to a disability, you may contact us at HR-US@rain.us.

    [job_alerts.create_a_job]

    Senior Application Security Engineer • Concord, CA, United States

    [internal_linking.similar_jobs]
    GSOC Operator / Flex Officer

    GSOC Operator / Flex Officer

    Securitas Inc. • Fremont, CA, United States
    [job_card.full_time]
    GSOC Operator / Flex Officer All Shifts We help make your world a safer place.Securitas is a global company that offers the most advanced and sustainable security solutions in the industry.We are lo...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Member of Technical Staff -Product Security

    Member of Technical Staff -Product Security

    Aptiv • Walnut Creek, California, United States
    [job_card.full_time]
    Wind River is a global leader in delivering software for mission-critical intelligent systems.For more than four decades, the company has been an innovator and pioneer, powering billions of systems...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Senior QA Engineer / SDET

    Senior QA Engineer / SDET

    Momento USA • San Ramon, CA, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Role : Senior QA Engineer / SDET Location : San Ramon, CA / Dallas, TX / St.Day's onsite) [show_more]
    [last_updated.last_updated_less] • [new]
    Senior Software Engineer

    Senior Software Engineer

    BlackLine • Pleasanton, CA, United States
    [job_card.full_time]
    It's fun to work in a company where people truly believe in what they're doing!.At BlackLine, we're committed to bringing passion and customer focus to the business of enterprise applications.Since...[show_more]
    [last_updated.last_updated_30] • [promoted]
    Armed Residential Security Team Agent

    Armed Residential Security Team Agent

    Allied Universal • Walnut Creek, California, United States
    [job_card.full_time]
    Armed Residential Security Team Agent.Elevate your security career with Allied Universal Enhanced Protection Services, a global leader in security and threat mitigation. We specialize in risk consul...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    EHS Specialist

    EHS Specialist

    1X Technologies AS • Hayward, CA, US
    [job_card.full_time]
    EHS Specialist (EHS & Security Program Specialist).We build humanoid robots that work alongside people to solve labor shortages and create abundance. Specialist to support the EHS & Security...[show_more]
    [last_updated.last_updated_variable_days]
    Web Application Developer-Onsite

    Web Application Developer-Onsite

    Optimized Technical Solutions • Fairfield, CA, USA
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Maintenance Group Web Application Development.Maintenance Group (MXG) at Travis Air Force Base.This position involves developing and maintaining critical web applications to support the operational...[show_more]
    [last_updated.last_updated_30]
    Senior Technician - Security

    Senior Technician - Security

    Bosch Building Technologies LLC • Hayward, California, United States, 94545
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Bosch Building Technologies – Senior Technician - Security .Headquartered in Germany, Robert Bosch GmbH is a premier global supplier with four primary business sectors : Automotive Technology, Indus...[show_more]
    [last_updated.last_updated_variable_days]
    Cyber Security Analyst

    Cyber Security Analyst

    Sunrise Systems • Concord, California, United States
    [job_card.full_time]
    [filters_job_card.quick_apply]
    Job Title : Cyber Security Threat Analyst / Specialist - Senior (AWS).Location : Concord, CA (Hybrid).Duration : 06 months on W2 contract. Work Schedule : Sunday to Thursday (Swing shift) 2 PM to 8 PM.Mon...[show_more]
    [last_updated.last_updated_30]
    Security Shift Supervisor - Unarmed

    Security Shift Supervisor - Unarmed

    Allied Universal • Concord, California, United States
    [job_card.full_time]
    Security Shift Supervisor - Unarmed.Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose.While working in a...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    _General Application Submission

    _General Application Submission

    Roundhouse Market + Conference Center • San Ramon, CA, USA
    [job_card.full_time]
    [filters_job_card.quick_apply]
    If there are no open positions posted, you are always welcome to submit a resume and complete an application here!.[show_more]
    [last_updated.last_updated_30]
    Senior Software Engineer

    Senior Software Engineer

    Blackline Systems Inc • Pleasanton, CA, United States
    [job_card.full_time]
    It's fun to work in a company where people truly believe in what they're doing!.At BlackLine, we're committed to bringing passion and customer focus to the business of enterprise applications.Since...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    R&D Engineer

    R&D Engineer

    Vector Atomic • Pleasanton, CA, US
    [job_card.full_time] +1
    [filters_job_card.quick_apply]
    Vector Atomic, based in Pleasanton, California, is at the forefront of commercializing quantum technology for critical applications like GPS-free navigation and timing, geophysical exploration, and...[show_more]
    [last_updated.last_updated_30]
    Application Engineer Field - Now Hiring!

    Application Engineer Field - Now Hiring!

    Henkel • Bay Point, CA, United States
    [job_card.full_time]
    At Henkel, you’ll be part of an organization that’s shaping the future through innovation, sustainability and collaboration. With our trusted brands like Persil®, ‘all®, Loctite®, Snuggle®, and Schw...[show_more]
    [last_updated.last_updated_30]
    Senior Software Engineer

    Senior Software Engineer

    Cyrad Solutions LLC • Pleasanton, CA, United States
    [job_card.full_time]
    Citizenship Required; Security Clearance Preferred or Willingness to Obtain.Join a team of expert engineers developing cutting-edge optical communication technology. Our hands-on, results-driven app...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Cyber Security JOB Training Program

    Cyber Security JOB Training Program

    Year Up United • Pleasant Hill, CA, US
    [job_card.full_time]
    Year Up United is a one-year or less, intensive job training program that provides young adults with in-classroom skill development, access to internships and / or job placement services, and persona...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]
    Application Engineer Field - Urgently Hiring!

    Application Engineer Field - Urgently Hiring!

    Henkel • Bay Point, CA, United States
    [job_card.full_time]
    At Henkel, you’ll be part of an organization that’s shaping the future through innovation, sustainability and collaboration. With our trusted brands like Persil®, ‘all®, Loctite®, Snuggle®, and Schw...[show_more]
    [last_updated.last_updated_30]
    Security Practice Lead (Nationwide)

    Security Practice Lead (Nationwide)

    Presidio Networked Solutions, LLC • Pleasanton, California, United States
    [job_card.full_time]
    Presidio, Where Teamwork and Innovation Shape the Future.AtPresidio, we're at the forefront of a global technology revolution, transforming industries throughcutting-edge digital solutions and next...[show_more]
    [last_updated.last_updated_variable_days] • [promoted]