16 ago
|
Socium - Teams Done Differently
|
Castro
16 ago
Socium - Teams Done Differently
Castro
Product Security Engineer — Mobile RASP
This is a Fully Remote role, but the individual needs to be based in Spain.
Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run — on devices the company doesn't control. They're hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.
This is a genuine builder role, not a policy or governance one. You'll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.
What you'll be building
You'll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) — built on top of a licensed RASP core. You'll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.
The product spans both sides of the wire, so you'll also build and operate the platform's Python (Flask) backend — the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.
Because you're building the product, you'll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38) and support the Sales & Solutioning team as a technical pre-sales engineer when needed.
What we're looking for
- Strong, current,
hands-on software engineering — you code daily and ship to production
- Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused
- Experience integrating and extending third-party SDKs via callback/event APIs
- Code-hardening experience — obfuscation and binary hardening across native mobile toolchains
- Applied cryptography fundamentals (secure data-at-rest storage, attestation)
- Backend development in Python (Flask), with solid testing and API-design discipline
- Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)
- Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals
- Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)
- Professional-standard English
Strongly preferred: Spanish (spoken and written), given the company's Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.
Location: Fully remote, based in Spain or London.
If you want to own real runtime security defences end-to-end — mobile client through to backend — and ship at speed with AI as your co-pilot, we'd love to hear from you. Company details shared on application.
#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec
📌 Senior Product Security Engineer (Castro)
🏢 Socium - Teams Done Differently
📍 Castro