Security Engineer
Rain · New York, NY (OnSite)
On-site$170–270k
mid
security engineer
Apply on Rain →
About the Company
Rain is the global stablecoin payments platform for enterprises, neobanks, platforms, developers, and AI agents. Our technology allows partners to move, store, and use stablecoins instantly and compliantly through global payment cards, rewards, on/offramps, wallets, and cross-border rails. As both a Visa and Mastercard Principal Member, Rain issues cards that work at more than 175 million merchant locations in over 220 countries and territories. Built natively for stablecoins and trusted by more than 100 organizations worldwide, Rain delivers secure, scalable infrastructure that makes money move freely and instantly around the world.
You will have the opportunity to deliver massive impact at a hypergrowth company backed by some of the top investors in fintech, crypto, and SaaS. In January 2026, we closed a $250M Series C led by ICONIQ, valuing Rain at $1.95B, with Sapphire Ventures, Dragonfly, Bessemer Venture Partners, Galaxy Ventures, FirstMark, Lightspeed, Norwest, and Endeavor Catalyst also participating. If you're curious, bold, and excited to help shape a borderless financial future, we'd love to talk.
Our Ethos
We believe in an open and flat structure. You will be able to grow into the role that most aligns with your goals. Our team members at all levels have the freedom to explore ideas and impact the roadmap and vision of our company.
What You’ll Do
As a Security Engineer with a focus on Application Security, you’ll be a key contributor in embedding security into Rain’s engineering lifecycle and supporting delivery of secure, trusted applications:
Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams
Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently
Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left
Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery
Drive threat modeling and risk assessments for new features, APIs, and services
Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements
Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies
Help build internal training and awareness programs to elevate secure coding and developer security literacy
Track and surface key security metrics, trends, and continuous improvement insights to leadership
What we're looking for
4–8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications
Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis
Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10)
Experience driving or participating in threat modeling and secure design reviews
Familiarity with cloud concepts and securing cloud workloads
Collaborative mindset — you enjoy working closely with engineers to co-create practical security solutions
Practical understanding of SDLC and integrating security into development workflows
Ability to independently identify, prioritize, and drive remediation on critical findings
Experience balancing security risk with business and technical constraints
Nice to have, but not mandatory
Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling)
Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements
Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar
Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls
Prior experience in fintech, payments, or highly regulated environments
Exposure to API security tooling and design best practices
Things that enable a fulfilling, healthy, and happy experience at Rain:
Unlimited time off 🌴 Unlimited vacation can be daunting, so we require Rainmakers to take 10 days minimum for themselves.
Flexible working ☕ We support a flexible workplace – work from home, come into an office, or both. We want everyone to work in an environment where they're their most confident and productive selves. New Rainmakers receive a stipend to set up a comfortable home workspace.
Easy to access benefits 🧠 For US Rainmakers, we cover 95% of your health, dental, and vision plan costs and 90% for your dependents, plus a 100% company-subsidized life insurance plan.
Retirement goals 💡 Plan for the future with confidence. We offer a 401(k) with a 4% company match.
Equity plan 📦 Every Rainmaker gets an equity option plan so we all benefit from our success.
Health and Wellness 📚 High performance begins from within. Rainmakers receive a monthly stipend to be used for eligible health and wellness spending like gym memberships/fitness classes, massages, acupuncture - whatever recharges you!
In-office meals 🍜 Rainmakers working from the office enjoy lunch and dinner on us, covered with a DoorDash credit.
Team summits ✨ Summits play an important role at Rain. Time together helps us build relationships and a common destiny. Expect team and company offsites, both domestic and international.
Posted 2026-01-15