17 ago
|
Socium - Teams Done Differently
|
Madrid
17 ago
Socium - Teams Done Differently
Madrid
Product Security Engineer — Mobile RASP
Lea atentamente toda la información sobre esta ocasión y luego utilice el botón de solicitud de abajo para enviar su CV y su candidatura.
This is a Fully Remote role, but the individual needs to be based in Spain.
Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run — on devices the company doesn't control. They're hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.
This is a genuine builder role, not a policy or governance one. You'll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.
What you'll be building
You'll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) — built on top of a licensed RASP core. You'll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.
The product spans both sides of the wire, so you'll also build and operate the platform's Python (Flask) backend — the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.
Because you're building the product, you'll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38)
and support the Sales & Solutioning team as a technical pre-sales engineer when needed.
What we're looking for
Strong, current, hands-on software engineering — you code daily and ship to production
Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused
Experience integrating and extending third-party SDKs via callback/event APIs
Code-hardening experience — obfuscation and binary hardening across native mobile toolchains
Applied cryptography fundamentals (secure data-at-rest storage, attestation)
Backend development in Python (Flask), with solid testing and API-design discipline
Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)
Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals
Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)
Professional-standard English
Strongly preferred
Spanish (spoken and written), given the company's Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.
Location
Fully remote, based in Spain or London. xugodme
If you want to own real runtime security defences end-to-end — mobile client through to backend — and ship at speed with AI as your co-pilot, we'd love to hear from you. Company details shared on application.
#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec
📌 Senior Product Security Engineer (Madrid)
🏢 Socium - Teams Done Differently
📍 Madrid