19 ago
|
Socium - Teams Done Differently
|
Galicia
19 ago
Socium - Teams Done Differently
Galicia
Product Security Engineer — Mobile RASP
This is a Fully Remote role, but the individual needs to be based in Spain.
Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run — on devices the company doesnt control. Theyre hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.
This is a genuine builder role, not a policy or governance one. Youll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.
What youll be building
Youll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) — built on top of a licensed RASP core. Youll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.
The product spans both sides of the wire, so youll also build and operate the platforms Python (Flask) backend — the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.
Because youre building the product, youll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38) and support the Sales & Solutioning team as a technical pre-sales engineer when needed.
What were looking for
Strong, current,
hands-on software engineering — you code daily and ship to production
Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused
Experience integrating and extending third-party SDKs via callback/event APIs
Code-hardening experience — obfuscation and binary hardening across native mobile toolchains
Applied cryptography fundamentals (secure data-at-rest storage, attestation)
Backend development in Python (Flask), with solid testing and API-design discipline
Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)
Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals
Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)
Professional-standard English
Strongly preferred: Spanish (spoken and written), given the companys Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.
Location: Fully remote, based in Spain or London.
If you want to own real runtime security defences end-to-end — mobile client through to backend — and ship at speed with AI as your co-pilot, wed love to hear from you. Company details shared on application.
#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec
📌 Senior Product Security Engineer (Galicia)
🏢 Socium - Teams Done Differently
📍 Galicia