Skip to content
RainRain

Security Engineer

Leads application security assessments, vulnerability scanning, code reviews, and threat modeling. Integrates automated security tools into CI/CD pipelines and drives remediation with engineering teams. Requires 4-8+ years in app sec with hands-on tool experience.

About the job

What You’ll Do

  • Lead application security assessments, including vulnerability scanning, code reviews, and threat modeling with engineering teams
  • Partner closely with product and development squads to drive remediation and help teams understand and resolve security findings efficiently
  • Integrate and scale automated security tooling across CI/CD pipelines (SAST, DAST, SCA, IaC) to shift security left
  • Develop and maintain application security standards, patterns, and guardrails that reduce risk and support rapid delivery
  • Drive threat modeling and risk assessments for new features, APIs, and services
  • Collaborate with Cloud & Infrastructure Security to align security controls across layers and support cloud-native security requirements
  • Support incident response for application-level security events and contribute to root-cause analysis and future mitigation strategies
  • Help build internal training and awareness programs to elevate secure coding and developer security literacy
  • Track and surface key security metrics, trends, and continuous improvement insights to leadership

What we're looking for

  • 4–8+ years of experience in security engineering, application security, offensive security, or secure software development; strong track record of securing modern applications
  • Hands-on experience with security tools such as Semgrep, Burp Suite, Snyk, Trivy, or similar for static, dynamic, and dependency security analysis
  • Solid understanding of web, API, and mobile security vulnerabilities (e.g., OWASP Top 10, API Top 10)
  • Experience driving or participating in threat modeling and secure design reviews
  • Familiarity with cloud concepts and securing cloud workloads
  • Collaborative mindset — you enjoy working closely with engineers to co-create practical security solutions
  • Practical understanding of SDLC and integrating security into development workflows
  • Ability to independently identify, prioritize, and drive remediation on critical findings
  • Experience balancing security risk with business and technical constraints

Nice to have, but not mandatory

  • Experience or exposure to runtime application protection (RASP) or advanced monitoring (e.g., eBPF-based tooling)
  • Experience with cloud security automation frameworks such as Security Hub remediations or DLP improvements
  • Security certifications like CISSP, CSSLP, OSCP, GWAPT, or similar
  • Familiarity with compliance frameworks like SOC 2, ISO 27001, OWASP SAMM and aligning controls
  • Prior experience in fintech, payments, or highly regulated environments
  • Exposure to API security tooling and design best practices

Skills

Semgrep, Burp Suite, Snyk, Trivy, Owasp Top 10, Threat Modeling, SAST, DAST, Sca, Iac, SDLC, Cissp, SOC 2, ISO 27001, Ebpf

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.