About the role
Rain is a global stablecoin payments platform serving enterprises, neobanks, platforms, developers, and AI agents. The company enables partners to move, store, and use stablecoins instantly and compliantly through payment cards, on and off ramps, wallets, and cross-border infrastructure. Operating as both a Visa and Mastercard Principal Member, Rain issues cards accepted at over 175 million merchant locations across more than 220 countries and territories. The platform is trusted by more than 100 organizations worldwide and recently closed a $250M Series C funding round at a $1.95B valuation, backed by leading fintech and crypto investors including ICONIQ, Sapphire Ventures, Dragonfly, and Bessemer Venture Partners.
Rain operates with a flat, open structure where team members at all levels have the freedom to explore ideas and shape the company's roadmap and vision. The Security Engineering team is small and focused, running an AI-driven red team against Rain's code and cloud infrastructure, gating pull requests before merge, and establishing configuration baselines across systems. This role sits at the center of that mission, covering everything beyond blockchain: the backend services, APIs, cloud infrastructure, and edge systems that process real money for real customers.
What you'll do
- Evaluate and triage red team findings before engineers see them, reproduce issues, eliminate false positives, assign severity levels, and create clear tickets that drive fixes without requiring meetings
- Strengthen backend services and APIs handling money movement, often implementing fixes yourself
- Manage edge security controls including DDoS mitigation, rate limiting, WAF configuration, and abuse prevention
- Develop and maintain secure configuration baselines for cloud, code, and SaaS systems, then automate their enforcement
- Expand the pull request security gate to catch more vulnerabilities before code merges
- Own attack surface analysis and conduct architecture reviews on new or high-risk systems
- Evaluate, test, and select the right security tools based on whether to buy, adopt, or build
What you'll bring
- Four or more years working in application security, product security, or security-focused backend engineering
- Proven ability to own security decisions and communicate architectural concerns to senior engineers while maintaining strong working relationships
- Capability to read unfamiliar TypeScript or Node.js codebases and identify meaningful bugs while distinguishing serious findings from noise
- Hands-on experience with cloud security in GCP, infrastructure as code with Terraform, and edge defenses such as WAFs and rate limiting
- Background running threat models or architecture reviews and experience conducting tool evaluations
- Bias toward shipping working code over documentation, with extensive hands-on AI tooling experience tempered by healthy skepticism
Nice to have
- Fintech, payments, or card issuing experience with PCI DSS knowledge
- Pentest, bug bounty, or red team background
- Experience developing security scanners, static analysis rules, or LLM-powered code review tools
- AI security expertise for autonomous agents and agentic payment systems
What they offer
- Minimum ten days annual time off plus flexible work arrangements with home office setup stipend for new hires
- For US employees, company covers 95 percent of health, dental, and vision insurance plus 90 percent for dependents, with fully subsidized life insurance
- 401(k) retirement plan with four percent company match and equity options for all employees
- Monthly wellness stipend for gym memberships, fitness classes, and similar health benefits
- Free lunch and dinner via DoorDash credit for office-based work
- Regular team and company summits including domestic and international offsites
Pay, location & hours
$190K–240K / year. Fully remote, open to applicants in any country.
About Rain
6 open roles in this building · Company page → · See it on the map
Mysten · Remote
openzeppelin · Remote
Ihsan Pay · Remote