Senior Application Security Engineer
Build security frameworks to make secure development frictionless and enthusiastic
As a Senior Application Security Engineer at RevenueCat, you will work closely with engineering teams and PMs to ensure product security at speed. Your mission includes investing in automatic tooling to prevent security issues, identifying common patterns, and creating frameworks that make building secure applications the default. You will participate in security code and system reviews, threat modeling, risk assessments, and support the Bug B...
Why This Role?
Help keep security aligned with a fast-shipping culture used by hundreds of millions of end-users
Key Responsibilities
- Participate in security code and system reviews
- Conduct threat modeling and risk assessments
- Support Bug Bounty program triage, prioritization, and fix tracking
- Collaborate with infra security to improve overall security posture
- Identify common security patterns and create automation frameworks
- Work with engineering teams and PMs to ensure secure product delivery
Requirements
- 5+ years in Application Security
- Deep understanding of common security flaws in web and mobile environments
- Experience with security tools such as SAST and proxies
- Experience identifying security issues through code review
- Interest in using AI and LLMs to enhance security practices
- Ability to build frameworks and automation that encourage secure-by-default development
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from 4dayweek.io
Original description from 4dayweek.io
RevenueCat removes the headaches of building and scaling in‑app subscriptions. Since graduating from YC’s S18 batch we’ve grown into the default monetization platform for mobile: we’re in >40% of newly shipped subscription apps, we process $12B+ in annual purchase volume, and we help everyone from a solo dev in Brazil to the OpenAI mobile team understand and grow their revenue. We’re a remote‑first crew of 150+, spread across 25+ countries, and guided by values we actually practice: Customer Obsession, Always Be Shipping, Own It, and Balance. If you want your work to touch hundreds of millions of end‑users (and help the developers behind them get paid), you’ll fit right in. #### The role: We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure. RevenueCat has a fast-shipping culture. Your mission is to help to keep security at that speed, invest in automatic tooling to prevent certain kinds of security issues, identify common patterns and create frameworks that make building secure applications the default, so frictionless that adoption is natural and enthusiastic. Our product is used extensively in top-tier apps, and is used to gate access to paid features. As such it needs to implement novel methods to prevent tampering and keep security high. Other responsibilities will be: - Participate in security code and system reviews, threat modeling and risk assessments. - Support the Bug Bounty program, helping teams on triaging, prioritizing and fixing issues, learning the common issues and using that information to improve the foundations. - Collaborate closely with infra security to level up our security posture. #### About you: - **You have 5+ years in Application Security, including:** - deep understanding of common security flaws and ways to address them, both in web and mobile app environments. - experience with common security tools and services, like SAST tools, proxies, etc. - experience identifying security issues through code review. - **You love building frameworks and automation:** You see that the best way to ensure that security and best practices are followed is to make something so easy and joyful to use that nobody wants to use anything else. - **You are AI-Curious:** Youunderstand how LLMs and AI coding tools are changing engineering, you want to embrace and use them effectively to keep security level up. At the same time, you are familiar with new AI security risks regarding MCPs, prompt injection, etc, and want to build safer guardrails for agentic development and AI adoption in the product. - **You are proactive:** You see what is needed, you take action and own problems to turn them into solutions. - **You are agile**: You move fast, iterate quickly, pivot and reprioritize when needed to maximize impact. **Ideally, you have:** - Experience securing mobile SDKs (iOS/Android) and backend services (Python) #### In the first month, you'll: - Meet your team! - Get up to speed on our infrastructure, services and codebases. - Familiarize yourself with SDK and backend, how they interact. - Explore the bug bounty platform and reports. - **Ship your first project**. #### Within the first 3 months, you'll: - Be able to scope and work on tasks self-sufficiently. - Participate in code reviews, security design reviews. - Participate actively in the bug bounty program. #### Within the first 6 months, you'll: - Understand deeply risks and threats on SDK, how SDK and backend interact and the backend application. - Actively contribute to improve security, pushing and introducing frameworks, tools or services that have measurable impact. - Collaborate closely with other teams, creating ties, trust relationships, providing security guidance. #### Within the first 12 months, you'll: - Be the go-to expert for application security issues, seek for security reviews, threat assessments. - Have your own initiat
Salary Context
Similar Engineering roles on LokerDollar pay around $197.5k/yr (range $38.623k–395k/yr, n=273 active listings).
Hiring at RevenueCat
RevenueCat has 1 other active role on LokerDollar and has been hiring here since May 12, 2026 — across Engineering.
View all RevenueCat openings →Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume
Frequently asked questions
- Is Senior Application Security Engineer at RevenueCat a remote job?
- Yes. Senior Application Security Engineer at RevenueCat is a fully remote role open to candidates worldwide.
- What type of employment is Senior Application Security Engineer at RevenueCat?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at RevenueCat.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- 10 Remote Jobs Nobody Wants (Yet!)Are there remote openings with few applicants? We'll show you 10 high-demand, low-supply positions – and why your skills might be a perfect fit.
- Remote USD Jobs in July 2026: Top OpeningsDiscover the latest remote USD job openings for July 2026, featuring top companies like Tailor, Vanta, and Kyndryl, with salaries up to $166,000 per year.
- Remote Freelance Jobs June 2026: Trends & PayA global look at seven new remote freelance gigs, pay ranges, a contrarian take, and practical tips for landing USD‑paid work.
Free account · no credit card · Log in
Pro $9/mo · unlimited applies + AI resume