Remote job
Staff Mobile & Product Security Engineer
Job details
About this role
Role overview
A consumer membership platform serving 100M+ users across iOS, Android, and web is hiring its foundational mobile and product security engineer. This is a hands-on, build-with-the-team role embedded directly with product and mobile squads, with ownership of mobile security, application security, offensive testing, and the partner-facing security architecture for a zero-to-one stack that includes AI-native features.
Responsibilities
- Embed with mobile and product squads (membership app for iOS and Android, marketplace, data and identity) to threat-model features, review designs, and harden code before it ships. - Own the mobile application security program end-to-end, including secure mobile SDLC, code review across Swift, Kotlin, and React Native, supply-chain and dependency controls, and developer-facing security tooling. - Run the broader product application security program, covering secure-by-default patterns, API and backend security review, and paved-road tooling for the engineering organization. - Run the pen testing program, performing hands-on mobile and web offensive work (static and dynamic analysis, reverse engineering, on-device attack surface) and coordinating external engagements; turn findings into shipped fixes. - Architect the controls and documentation needed to satisfy partner security requirements so partnership deals can close on schedule. - Set the security baseline for an AI-native product stack, including coding agents, model and prompt security, mobile AI features, and related attack surfaces. - Author mobile and product security standards, guardrails, and the paved-road playbook so that security scales with the organization.
Requirements
- Background as the security engineer embedded inside a product or mobile team, with a track record of shipping code and fixes directly rather than only reviewing at the gate. - Deep experience securing native iOS and/or Android apps at consumer scale, including secure storage, certificate and key pinning, jailbreak/root and tamper detection, secure IPC, and mobile authentication flows. - Experience running or significantly contributing to an application security program inside a consumer product used by millions, with pragmatic judgment about coverage, velocity, and risk tradeoffs. - Hands-on offensive skills against mobile and web targets, including discovery and remediation of real-world on-device and API-level mobile vulnerabilities. - Familiarity with partner security frameworks and equivalents such as SOC 2, PCI, vendor security reviews, and mobile app store security requirements, with the ability to translate requirements into substantive controls. - Comfort working in ambiguity on a fast-moving, scaling product, with a bias toward shipping controls over writing policy.
Nice to have
- Daily use of AI coding agents and applied thinking about how AI changes both product development and the defensive surface area, including on-device and mobile AI features. - A blend of scrappy early-stage startup experience and exposure to large-scale consumer platforms.
Benefits and work setup
- Base salary range of $178,000 to $268,000, plus bonus and equity. - Medical, dental, and vision coverage through Blue Cross Blue Shield, plus company-paid life insurance. - Health Savings Account contributions, 401(k) plan with safe-harbor company matching, and a flexible vacation policy with paid company holidays. - Company-provided technology package. - Relocation assistance where applicable, including travel and company-provided housing for the first 90 days. - On-site, embedded collaboration with mobile and product engineering teams.