Security Engineer
Lead application security assessments, vulnerability scanning, code reviews, and threat modeling. Partner with product and development teams to drive remediation, integrate security tooling across CI/CD, develop security standards and guardrails, support application-level incident response, improve secure coding practices, and track security metrics.
Responsibilities
- Lead application security assessments including vulnerability scanning, code review, and threat modeling
- Partner with product and development squads to drive remediation and resolve security findings
- Integrate and scale automated security tooling across CI/CD pipelines using SAST, DAST, SCA, and IaC
- Develop and maintain application security standards, patterns, and guardrails
- Drive threat modeling and risk assessments for new features, APIs, and services
- Collaborate with cloud and infrastructure security to align controls
- Support incident response for application-level security events and perform root-cause analysis
- Build internal secure coding training and awareness programs
- Track and report security metrics, trends, and continuous improvement insights
Requirements
- 4–8+ years of experience in security engineering, application security, offensive security, or secure software development
- Hands-on experience with Semgrep, Burp Suite, Snyk, Trivy, or similar security tools
- Understanding of web, API, and mobile security vulnerabilities, including OWASP Top 10 and API Top 10
- Experience with threat modeling and secure design reviews
- Familiarity with cloud concepts and securing cloud workloads
- Collaborative approach to working with engineers
- Understanding of SDLC and integrating security into development workflows
- Ability to identify, prioritize, and drive remediation of critical findings
- Experience balancing security risks with business and technical constraints
- Experience with or exposure to RASP, advanced monitoring, cloud security automation, security certifications, compliance frameworks, fintech or payments, or API security tooling is beneficial
Benefits
- Unlimited time off with a minimum of 10 days required
- Flexible working and home office stipend
- Comprehensive health, dental, and vision plans for US employees
- Company-subsidized life insurance
- 401(k) with 4% company match
- Equity option plan
- Company-issued Rain Cards for product testing
- Health and wellness spending
- Domestic and international team and company off-sites