15 ago
|
Socium - Teams Done Differently
|
Badajoz
15 ago
Socium - Teams Done Differently
Badajoz
? Product Security Engineer — Mobile RASP
This is a Fully Remote role, but the individual needs to be based in Spain.
Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run — on devices the company doesn't control. They're hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.
This is a genuine builder role, not a policy or governance one. You'll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.
What you'll be building:
You'll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) — built on top of a licensed RASP core. You'll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.
The product spans both sides of the wire, so you'll also build and operate the platform's Python (Flask) backend — the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.
Because you're building the product, you'll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38) and support the Sales & Solutioning team as a technical pre-sales engineer when needed.
What we're looking for:
- Strong, current,
hands-on software engineering — you code daily and ship to production
- Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused
- Experience integrating and extending third-party SDKs via callback/event APIs
- Code-hardening experience — obfuscation and binary hardening across native mobile toolchains
- Applied cryptography fundamentals (secure data-at-rest storage, attestation)
- Backend development in Python (Flask), with solid testing and API-design discipline
- Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)
- Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals
- Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)
- Professional-standard English
Strongly preferred: Spanish (spoken and written), given the company's Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.
Location: Fully remote, based in Spain or London.
If you want to own real runtime security defences end-to-end — mobile client through to backend — and ship at speed with AI as your co-pilot, we'd love to hear from you. Company details shared on application.
#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec
📌 Senior Product Security Engineer (Badajoz)
🏢 Socium - Teams Done Differently
📍 Badajoz