Ensure the security of RevenueCat's products by collaborating with engineering teams and external parties.
•We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure.
•Key Responsibilities Participate in security code and system reviews, threat modeling and risk assessments.
•Support the Bug Bounty program, helping teams on triaging, prioritizing and fixing issues, learning the common issues and using that information to improve the foundations.
•Collaborate closely with infra security to level up our security posture.
•Requirements You have 5+ years in Application Security, including: deep understanding of common security flaws and ways to address them, both in web and mobile app environments; experience with common security tools and services, like SAST tools, proxies; experience identifying security issues through code review.
•You love building frameworks and automation: You see that the best way to ensure that security and best practices are followed is to make something so easy and joyful to use that nobody wants to use anything else.
•You are AI-Curious: You understand how LLMs and AI coding tools are changing engineering, you want to embrace and use them effectively to keep security level up.
•At the same time, you are familiar with new AI security risks regarding MCPs, prompt injection, etc, and want to build safer guardrails for agentic development and AI adoption in the product.
•You are proactive: You see what is needed, you take action and own problems to turn them into solutions.
•You are agile: You move fast, iterate quickly, pivot and reprioritize when needed to maximize impact.
Competitive equity, 10-year window to exercise vested equity options, Fully remote and flexible work environment, 4-5 weeks of suggested time off annually, $2,000 USD for workspace setup, $1,000 USD annual stipend for continuous learning