Security Engineer
Full Description
ABOUT THE COMPANY Rain makes the next generation of payments possible across the globe. We’re a lean and mighty team of passionate builders and veteran founders. Our infrastructure makes stablecoins usable in the real-world by powering card transactions, cross-border payments, B2B purchases, remittances, and more. We partner with fintechs, neobanks, and institutions to help them launch solutions that are global, inclusive, and efficient. You will have the opportunity to deliver massive impact at a hypergrowth company that is funded by some of the top investors in fintech, crypto, and SaaS, including Sapphire Ventures, Norwest, Galaxy Ventures, Lightspeed, Khosla, and several more. If you’re curious, bold, and excited to help shape a borderless financial future, we’d love to talk. OUR ETHOS We believe in an open and flat structure. You will be able to grow into the role that most aligns with your goals. Our team members at all levels have the freedom to explore ideas and impact the roadmap and vision of our company. WHAT YOU’LL DO As a Security Engineer with a focus on Application Security, you’ll be a key contributor in embedding security into Rain’s engineering lifecycle and supporting delivery of secure, trusted applications: - Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams - Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently - Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left - Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery - Drive threat modeling and risk assessments for new features, APIs, and services - Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements - Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies - Help build internal training and awareness programs to elevate secure coding and developer security literacy - Track and surface key security metrics, trends, and continuous improvement insights to leadership WHAT WE'RE LOOKING FOR - 4–8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications - Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis - Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10) - Experience driving or participating in threat modeling and secure design reviews - Familiarity with cloud concepts and securing cloud workloads - Collaborative mindset — you enjoy working closely with engineers to co-create practical security solutions - Practical understanding of SDLC and integrating security into development workflows - Ability to independently identify, prioritize, and drive remediation on critical findings - Experience balancing security risk with business and technical constraints NICE TO HAVE, BUT NOT MANDATORY - Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling) - Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements - Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar - Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls - Prior experience in fintech, payments, or highly regulated environments - Exposure to API security tooling and design best practices THINGS THAT ENABLE A FULFILLING, HEALTHY, AND HAPPY EXPERIENCE AT RAIN: - Unlimited time off 🌴 Unlimited vacation can be daunting, so we require Rainmakers to take at least 10 days off. - Flexible working ☕ We support a flexible workplace. If you feel comfortable at home, please work from home. If you’d like to work with others in an office, feel free to come in. We want everyone to be able to work in the environment in which they are their most confident and productive selves. New Rainmakers will receive a stipend to create a comfortable home environment. - Easy to access benefits 🧠For US Rainmakers, we offer comprehensive health, dental, and vision plans for you and your dependents, as well as a 100% company subsidized life insurance plan. - Retirement goals💡Plan for the future with confidence. We offer a 401(k) with a 4% company match. - Equity plan 📦 We offer every Rainmaker an equity option plan so we can all benefit from our success. - Rain Cards 🌧️ We want Rainmakers to be knowledgeable about our core products and services. To support this mission, we issue a card for our team to use for testing. - Health and Wellness 📚 High performance begins from within. Rainmakers are welcome to use their card for eligible health and wellness spending like gym memberships/fitness classes, massages, acupuncture - whatever recharges you! - Team summits ✨ Summits play an important role at Rain! Time spent together helps us get to know each other, strengthen our relationships, and build a common destiny. Expect team and company off-sites both domestically and internationally.
Why This Role?
Kamu akan bekerja di perusahaan fintech yang berkembang pesat dan memiliki dukungan dari investor terkemuka.
Key Responsibilities
- Lakukan penilaian keamanan aplikasi termasuk pemindaian kerentanan, ulasan kode, dan pemodelan ancaman
- Kerjasama dengan tim produk dan pengembangan untuk memperbaiki dan memahami temuan keamanan
- Integrasikan dan skalakan alat keamanan otomatis di dalam CI/CD pipelines
- Bangun dan perbarui standar keamanan aplikasi untuk mengurangi risiko
- Lakukan pemodelan ancaman dan penilaian risiko untuk fitur baru, API, dan layanan
- Kerjasama dengan tim Cloud & Infrastructure Security untuk memastikan kontrol keamanan konsisten
Requirements
- Pernah bekerja sebagai Security Engineer atau bidang terkait selama 4-8 tahun
- Paham tentang pemindaian kerentanan, ulasan kode, dan pemodelan ancaman
- Pengalaman dalam mengintegrasikan alat keamanan otomatis di dalam CI/CD pipelines
- Paham tentang standar keamanan aplikasi dan pemodelan ancaman
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
ABOUT THE COMPANY Rain makes the next generation of payments possible across the globe. We’re a lean and mighty team of passionate builders and veteran founders. Our infrastructure makes stablecoins usable in the real-world by powering card transactions, cross-border payments, B2B purchases, remittances, and more. We partner with fintechs, neobanks, and institutions to help them launch solutions that are global, inclusive, and efficient. You will have the opportunity to deliver massive impact at a hypergrowth company that is funded by some of the top investors in fintech, crypto, and SaaS, including Sapphire Ventures, Norwest, Galaxy Ventures, Lightspeed, Khosla, and several more. If you’re curious, bold, and excited to help shape a borderless financial future, we’d love to talk. OUR ETHOS We believe in an open and flat structure. You will be able to grow into the role that most aligns with your goals. Our team members at all levels have the freedom to explore ideas and impact the roadmap and vision of our company. WHAT YOU’LL DO As a Security Engineer with a focus on Application Security, you’ll be a key contributor in embedding security into Rain’s engineering lifecycle and supporting delivery of secure, trusted applications: - Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams - Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently - Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left - Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery - Drive threat modeling and risk assessments for new features, APIs, and services - Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements - Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies - Help build internal training and awareness programs to elevate secure coding and developer security literacy - Track and surface key security metrics, trends, and continuous improvement insights to leadership WHAT WE'RE LOOKING FOR - 4–8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications - Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis - Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10) - Experience driving or participating in threat modeling and secure design reviews - Familiarity with cloud concepts and securing cloud workloads - Collaborative mindset — you enjoy working closely with engineers to co-create practical security solutions - Practical understanding of SDLC and integrating security into development workflows - Ability to independently identify, prioritize, and drive remediation on critical findings - Experience balancing security risk with business and technical constraints NICE TO HAVE, BUT NOT MANDATORY - Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling) - Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements - Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar - Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls - Prior experience in fintech, payments, or highly regulated environments - Exposure to API security tooling and design best practices THINGS THAT ENABLE A FULFILLING, HEALTHY, AND HAPPY EXPERIENCE AT RAIN: - Unlimited time off 🌴 Unlimited vacation can be daunting, so we require Rainmakers to take at least 10 days off. - Flexible working ☕ We support a flexible workplace. If you feel comfortable at home, please work from home. If you’d like to work with others in an office, feel free to come in. We want everyone to be able to work in the environment in which they are their most confident and productive selves. New Rainmakers will receive a stipend to create a comfortable home environment. - Easy to access benefits 🧠For US Rainmakers, we offer comprehensive health, dental, and vision plans for you and your dependents, as well as a 100% company subsidized life insurance plan. - Retirement goals💡Plan for the future with confidence. We offer a 401(k) with a 4% company match. - Equity plan 📦 We offer every Rainmaker an equity option plan so we can all benefit from our success. - Rain Cards 🌧️ We want Rainmakers to be knowledgeable about our core products and services. To support this mission, we issue a card for our team to use for testing. - Health and Wellness 📚 High performance begins from within. Rainmakers are welcome to use their card for eligible health and wellness spending like gym memberships/fitness classes, massages, acupuncture - whatever recharges you! - Team summits ✨ Summits play an important role at Rain! Time spent together helps us get to know each other, strengthen our relationships, and build a common destiny. Expect team and company off-sites both domestically and internationally.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
