Hiring.Camp

Senior Application Security Engineer

RevenueCat

·

Yesterday

Salary
$230k+/yr
Workplace
Remote
Type
Full-time
Department
Engineering
Seniority
Senior
Source
Y Combinator

Description

RevenueCat removes the headaches of building and scaling in‑app subscriptions. Since graduating from YC’s S18 batch we’ve grown into the default monetization platform for mobile: we’re in >40% of newly shipped subscription apps, we process $12B+ in annual purchase volume, and we help everyone from a solo dev in Brazil to the OpenAI mobile team understand and grow their revenue.

We’re a remote‑first crew of 150+, spread across 25+ countries, and guided by values we actually practice: Customer Obsession, Always Be Shipping, Own It, and Balance. If you want your work to touch hundreds of millions of end‑users (and help the developers behind them get paid), you’ll fit right in.

The role:

We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure.

RevenueCat has a fast-shipping culture. Your mission is to help to keep security at that speed, invest in automatic tooling to prevent certain kinds of security issues, identify common patterns and create frameworks that make building secure applications the default, so frictionless that adoption is natural and enthusiastic.

Our product is used extensively in top-tier apps, and is used to gate access to paid features. As such it needs to implement novel methods to prevent tampering and keep security high.

Other responsibilities will be:

  • Participate in security code and system reviews, threat modeling and risk assessments.

  • Support the Bug Bounty program, helping teams on triaging, prioritizing and fixing issues, learning the common issues and using that information to improve the foundations.

  • Collaborate closely with infra security to level up our security posture.

About you:

  • You have 5+ years in Application Security, including:

  • You love building frameworks and automation: You see that the best way to ensure that security and best practices are followed is to make something so easy and joyful to use that nobody wants to use anything else.

  • You are AI-Curious: You understand how LLMs and AI coding tools are changing engineering, you want to embrace and use them effectively to keep security level up. At the same time, you are familiar with new AI security risks regarding MCPs, prompt injection, etc, and want to build safer guardrails for agentic development and AI adoption in the product.

  • You are proactive: You see what is needed, you take action and own problems to turn them into solutions.

  • You are agile : You move fast, iterate quickly, pivot and reprioritize when needed to maximize impact.

Ideally, you have:

  • Experience securing mobile SDKs (iOS/Android) and backend services (Python)

In the first month, you'll:

  • Meet your team!

  • Get up to speed on our infrastructure, services and codebases.

  • Familiarize yourself with SDK and backend, how they interact.

  • Explore the bug bounty platform and reports.

  • Ship your first project.

Within the first 3 months, you'll:

  • Be able to scope and work on tasks self-sufficiently.

  • Participate in code reviews, security design reviews.

  • Participate actively in the bug bounty program.

Within the first 6 months, you'll:

  • Understand deeply risks and threats on SDK, how SDK and backend interact and the backend application.

  • Actively contribute to improve security, pushing and introducing frameworks, tools or services that have measurable impact.

  • Collaborate closely with other teams, creating ties, trust relationships, providing security guidance.

Within the first 12 months, you'll:

  • Be the go-to expert for application security issues, seek for security reviews, threat assessments.

  • Have your own initiatives for improving application security.

What we offer:

  • Competitive equity in a fast-growing, Series C startup backed by top-tier investors, including Y Combinator

  • 10-year window to exercise vested equity options

  • Fully remote and flexible work environment

  • 4-5 weeks of suggested time off annually for mental, physical, and emotional recharge

  • $2,000 USD for workspace setup and $1,000 USD annual stipend for continuous learning

Curious about the interview process? Discover more in our blog post about how we hire and learn tips to help you succeed.

Skills

PythoniOSAndroid

Similar Jobs

30

B3 Senior Application Operations Engineer in Social Security Scotland

Scottish Government Recruitment · Glasgow, United Kingdom, GB · Hybrid

Yesterday

Sr. Application Security Engineer

Lplfinancial · Fort Mill/Charlotte, United States of America +4

Yesterday

Senior Application & AI Security Engineer

Ringcentral · Bulgaria · Onsite

Yesterday

Sr Application Security Engineer

Nelnet as the nation · Lincoln - Nelnet Center, United States of America +1 · Remote

Yesterday

Senior Security Engineer - Application Security

Khealthcareers · New York, NY

3 days ago

IT Systems Engineer Sr - Application Security

Luriechildrens · Chicago, IL, United States of America

4 days ago

Senior Application Security Engineer

Clover Health · Remote - USA · Remote

4 days ago

Senior Application Security Engineer

Unlimit · Belgrade · Onsite

5 days ago

Senior Security Engineer - Application Security

Outsystems · PT - Remote, Portugal · Remote

5 days ago

HQ - Senior Application Security Engineer (Remote)

Jobandtalent · Madrid HQ, ES · Remote

6 days ago

Sr Product Application Security Engineer

Leidos · 6314 Remote/Teleworker US, United States of America · Remote

6 days ago

Senior Application Security Consultant

Kallesgroup · Seattle, WA +1

6 days ago

Senior / Staff Application Security Engineer

Suno · Boston +3 · Onsite

1 week ago

Application Security Senior Consultant (Remote)

Crowdstrike · USA TX Remote, United States of America · Remote

1 week ago

Senior Web Application Security Engineer

Qualys Careers · Pune, India

1 week ago

Sr. IT Application Security Engineer

Monolithicpower · Kirkland, WA, United States of America +1 · Onsite

1 week ago

Senior Software Engineer, Application Security

Discord · San Francisco Bay Area +1

1 week ago

Senior Application Security Engineer

AbbVie · Irvine, CA, United States · Hybrid

1 week ago

Senior Application Security Engineer

AbbVie · North Chicago, IL, United States · Hybrid

1 week ago

Senior Application Security Engineer

Hewlett Packard Enterprise (HP) · San Jose, California, United States of America · Hybrid

1 week ago

Senior Application Security Engineer

Hewlett Packard Enterprise (HP) · San Jose, California, United States of America · Hybrid

1 week ago

Senior Application Security Engineer

Vanguard · Malvern, PA, United States of America +2

1 week ago

Senior Application Security Engineer

Hewlett Packard Enterprise (HP) · San Jose, California, United States of America · Hybrid

1 week ago

Senior Application Security Engineer

Vanguard · Malvern, PA, United States of America +2

1 week ago

Senior Director- Application Solutions, Cloud & Security Delivery

Nttlimited · Kallang, Singapore

1 week ago

Senior Product Security Engineer, Application Security (Remote)

Crowdstrike · USA CA Remote, United States of America · Remote

1 week ago

SOFTWARE ENGINEER Sênior - APPLICATION SECURITY | TECH - CYBERSEC

iFood Indicações · Osasco +1

1 week ago

SOFTWARE ENGINEER Sênior - APPLICATION SECURITY | TECH - CYBERSEC

Ifoodcarreiras · Brasil +1

1 week ago

Senior Manager - Application Security Engineering EMEA

"Black Duck Software, Inc." · n/a

1 week ago

Senior Application Developer- Python (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

1 week ago