JobMatch
โ† Back to jobs

Security Engineer - AppSec

Rain

RemoteRemote - USAUSD 190kโ€“240kfull-time
Posted
today
Source
web3 jobs (telegram)
Field
Engineering, Security

Skills

Social MediaTypeScriptTerraformSecurityNode.jsGCPLLMsJavaScriptAI

Description

๐Ÿ’ผ Hiring: Security Engineer - AppSec - Rain ๐Ÿ“ Remote - USA | ๐Ÿ• Posted 10 hours ago - October 8, 2026 | ๐Ÿ’ฐ $190K-$240K / year | ๐Ÿง‘โ€๐Ÿ’ป Full-time | ๐Ÿ”— TypeScript / Node.js / GCP / Terraform / AppSec Rain is hiring a Security Engineer - AppSec to set the quality bar for non-chain findings across backend services, APIs, cloud, and edge systems that move real money. The Security Engineering team runs an AI-driven red team, gates pull requests, and writes configuration baselines. Blockchain coverage is already handled; this role owns everything else. ๐Ÿ“‹ Responsibilities include: - Review red-team findings before they reach engineers: reproduce issues, cut false positives, set severity, improve scoring, and write tickets clear enough to fix without a meeting - Harden backend services and APIs, especially money-moving paths, and often write the fix - Own edge defenses: DDoS protection, rate limiting, WAF rules, and abuse controls - Write secure configuration baselines for cloud, code, and SaaS, and turn them into automated checks - Grow the pull-request security gate so more bugs are blocked before merge - Own attack-surface coverage and run architecture reviews on new and high-risk systems - Evaluate, select, adopt, or build security tools ๐Ÿ”‘ Requirements / Must-have: - 4+ years in application security, product security, or security-minded backend engineering - Ownership of security decisions and the ability to push a senior engineer to change a design while keeping a good working relationship - Ability to read an unfamiliar TypeScript/Node.js codebase and separate a real bug from a scary-sounding finding - Hands-on cloud security, ideally GCP, plus Terraform and edge defenses such as WAFs and rate limiting - Experience with threat models or architecture reviews, including tool bake-offs - Preference for shipping a check over writing a document, and heavy but critical use of AI tools ๐Ÿ›  Nice-to-have / Preferred: - Fintech, payments, or card issuing background (PCI DSS a plus) - Pentest, bug bounty, or red team experience - Experience building security scanners, static analysis rules, or LLM-based review tools - AI security for agents and agentic payments, or corporate security alongside IT ๐Ÿ’ก Perks & Benefits: - $190K-$240K / year, equity option plan, and bonus - Unlimited time off, with a minimum of 10 days required - Flexible home, office, or hybrid work, plus a new-hire home-workspace stipend - For US employees: 95% health, dental, and vision coverage, 90% for dependents, and company-subsidized life insurance - 401(k) with a 4% company match and a monthly health and wellness stipend - Office lunch and dinner via DoorDash credit, plus domestic and international offsites ๐Ÿ“ฉ To apply: Apply: https://jobs.ashbyhq.com/rain/7e211b55-5069-45b2-8072-c6555a5b53cd/application ๐Ÿ”— Original post: https://www.linkedin.com/posts/remote-security-engineer-appsec-at-rain-share-7513728376130629632-iBkv ๐Ÿ“Œ New here? Subscribe and mute notifications to avoid noise. ๐Ÿ”Ž Search by role or skill, or check the pinned messages for a short vacancy list. โš ๏ธ DYOR! I do not verify every job. Requests to download and run files or make a payment are major scam warning signs. ๐Ÿšฉ โ—๏ธ I am not hiring. I only share fresh Web3 jobs posted by others. #NFA #DYOR ๐ŸŒŽ All my other social media! Subscribe!๐Ÿ‘‡ ๐Ÿ’ก Intern/Junior Web3/Crypto/Blockchain Roles DAILY ๐Ÿ“ฑ Allweb3jobs on Twitter/X ๐Ÿ“ฑ Allweb3jobs on LinkedIn ๐Ÿ“ฑ Coinmarketcap token analysis ๐Ÿช™ Binance token analysis ๐Ÿ’ฌ Want to promote something or just ask a question? Feel free to reach out: @crypto_vazima

JobMatch aggregates public listings. Always apply through the original posting.