Security Engineer - AppSec

Rain helps users buy, sell, and swap cryptocurrencies with regulated custody, bank-grade security, and 24/7 support across web and mobile.

United Arab Emirates
About Rain

Rain is a centralized crypto platform for retail and business users to buy, sell, and swap digital assets. The platform is licensed by the Central Bank of Bahrain and ADGM’s FSRA, offers cold storage custody, and provides bilingual 24/7 human support. Users can manage portfolios, use advanced trading with charts and order types, and access an OTC desk for large orders. The service includes clear fees, verification, and mobile apps.

View jobs by Rain

Skills

About the Role

You will serve as the application-security expert for non-blockchain systems. You will validate red-team findings, prioritize genuine risks, and help engineers resolve vulnerabilities. You will strengthen backend services, APIs, cloud configurations, edge defenses, pull-request security controls, and architecture reviews.

Requirements

  • 4+ years of experience in application security, product security, or security-minded backend engineering
  • Experience owning security decisions and influencing engineers to change designs
  • Ability to review unfamiliar TypeScript and Node.js codebases and distinguish real vulnerabilities from false positives
  • Hands-on cloud security experience, ideally with GCP
  • Experience with Terraform, WAFs, rate limiting, and edge defenses
  • Experience with threat modeling or architecture reviews
  • Experience evaluating security tools
  • Ability to use AI tools effectively while validating their output

Responsibilities

  • Review, reproduce, and prioritize red-team findings before they reach engineers
  • Write clear remediation tickets and improve finding-scoring methods
  • Harden backend services and APIs, including money-moving paths
  • Implement fixes for security issues when needed
  • Own DDoS protection, rate limiting, WAF rules, and abuse controls
  • Define secure configuration baselines for cloud, code, and SaaS systems and automate checks
  • Expand pull-request security gates to block bugs before merge
  • Own attack-surface coverage and conduct architecture reviews for new and high-risk systems
  • Evaluate and select security tools to buy, adopt, or build

Benefits

  • Unlimited time off with a 10-day minimum vacation requirement
  • Flexible workplace options, including working from home or an office
  • Home workspace setup stipend
  • US health, dental, and vision coverage with 95% of employee costs and 90% of dependent costs covered
  • Company-subsidized life insurance
  • 401(k) with a 4% company match
  • Equity option plan
  • Monthly health and wellness stipend
  • DoorDash credit for office lunches and dinners
  • Domestic and international team and company offsites