Security Engineer - AppSec
RemoteRemote - USAUSD 190kโ240kfull-time
- Posted
- today
- Source
- web3 jobs (telegram)
- Field
- Engineering, Security
Skills
Social MediaTypeScriptTerraformSecurityNode.jsGCPLLMsJavaScriptAI
Description
๐ผ Hiring: Security Engineer - AppSec - Rain
๐ Remote - USA | ๐ Posted 10 hours ago - October 8, 2026 | ๐ฐ $190K-$240K / year | ๐งโ๐ป Full-time | ๐ TypeScript / Node.js / GCP / Terraform / AppSec
Rain is hiring a Security Engineer - AppSec to set the quality bar for non-chain findings across backend services, APIs, cloud, and edge systems that move real money. The Security Engineering team runs an AI-driven red team, gates pull requests, and writes configuration baselines. Blockchain coverage is already handled; this role owns everything else.
๐ Responsibilities include:
- Review red-team findings before they reach engineers: reproduce issues, cut false positives, set severity, improve scoring, and write tickets clear enough to fix without a meeting
- Harden backend services and APIs, especially money-moving paths, and often write the fix
- Own edge defenses: DDoS protection, rate limiting, WAF rules, and abuse controls
- Write secure configuration baselines for cloud, code, and SaaS, and turn them into automated checks
- Grow the pull-request security gate so more bugs are blocked before merge
- Own attack-surface coverage and run architecture reviews on new and high-risk systems
- Evaluate, select, adopt, or build security tools
๐ Requirements / Must-have:
- 4+ years in application security, product security, or security-minded backend engineering
- Ownership of security decisions and the ability to push a senior engineer to change a design while keeping a good working relationship
- Ability to read an unfamiliar TypeScript/Node.js codebase and separate a real bug from a scary-sounding finding
- Hands-on cloud security, ideally GCP, plus Terraform and edge defenses such as WAFs and rate limiting
- Experience with threat models or architecture reviews, including tool bake-offs
- Preference for shipping a check over writing a document, and heavy but critical use of AI tools
๐ Nice-to-have / Preferred:
- Fintech, payments, or card issuing background (PCI DSS a plus)
- Pentest, bug bounty, or red team experience
- Experience building security scanners, static analysis rules, or LLM-based review tools
- AI security for agents and agentic payments, or corporate security alongside IT
๐ก Perks & Benefits:
- $190K-$240K / year, equity option plan, and bonus
- Unlimited time off, with a minimum of 10 days required
- Flexible home, office, or hybrid work, plus a new-hire home-workspace stipend
- For US employees: 95% health, dental, and vision coverage, 90% for dependents, and company-subsidized life insurance
- 401(k) with a 4% company match and a monthly health and wellness stipend
- Office lunch and dinner via DoorDash credit, plus domestic and international offsites
๐ฉ To apply: Apply: https://jobs.ashbyhq.com/rain/7e211b55-5069-45b2-8072-c6555a5b53cd/application
๐ Original post: https://www.linkedin.com/posts/remote-security-engineer-appsec-at-rain-share-7513728376130629632-iBkv
๐ New here? Subscribe and mute notifications to avoid noise.
๐ Search by role or skill, or check the pinned messages for a short vacancy list.
โ ๏ธ DYOR! I do not verify every job. Requests to download and run files or make a payment are major scam warning signs. ๐ฉ
โ๏ธ I am not hiring. I only share fresh Web3 jobs posted by others.
#NFA #DYOR
๐ All my other social media! Subscribe!๐
๐ก Intern/Junior Web3/Crypto/Blockchain Roles DAILY
๐ฑ Allweb3jobs on Twitter/X
๐ฑ Allweb3jobs on LinkedIn
๐ฑ Coinmarketcap token analysis
๐ช Binance token analysis
๐ฌ Want to promote something or just ask a question? Feel free to reach out: @crypto_vazima
JobMatch aggregates public listings. Always apply through the original posting.