> Markdown version of [/jobs/ext/1571795-security-applications-engineer](https://www.wearedevelopers.com/jobs/ext/1571795-security-applications-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Applications Engineer - **Company:** Revenuecat - **Location:** Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Code Review, Mobile Application Software, Python (Programming Language), Large Language Models, Software Security, Backend, Static Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://es.trabajo.org/oferta-5354-772abda666522a66331e5ef9b14904d3 ## About the Role Since graduating from YC's S18 batch we've grown into the default monetization platform for mobile: we're in 40% of newly shipped subscription apps, we process $10B+ in annual purchase volume, and we help everyone from a solo dev in Brazil to the OpenAI mobile team understand and grow their revenue. We're a remote-first crew of 120+, spread across 25 countries, and guided by values we actually practice: Customer Obsession, Always Be Shipping, Own It, and Balance. We are looking for a Senior, proactive Application Security Engineer to work closely with engineering teams, PMs and external parties to ensure that RevenueCat's products are secure. Your mission is to help to keep security at that speed, invest in automatic tooling to prevent certain kinds of security issues, identify common patterns and create frameworks that make building secure applications the default, so frictionless that adoption is natural and enthusiastic. As such it needs to implement novel methods to prevent tampering and keep security high. Participate in security code and system reviews, threat modeling and risk assessments. Collaborate closely with infra security to level up our security posture. You see that the best way to ensure that security and best practices are followed is to make something so easy and joyful to use that nobody wants to use anything else. You are AI-Curious: You understand how LLMs and AI coding tools are changing engineering, you want to embrace and use them effectively to keep security level up. You are agile: Deep understanding of common security flaws and ways to address them, both in web and mobile app environments. Experience identifying security issues through code review. Experience with common security tools and services, like SAST tools, proxies… You are familiar with new AI security risks regarding MCPs, prompt injection and others. Experience securing mobile SDKs (iOS/Android) and backend services (Python) is highly valued Familiarize yourself with SDK and backend, how they interact. Ship your first project. Participate in code reviews, security design reviews. Understand deeply risks and threats on SDK, how SDK and backend interact and the backend application. Actively contribute to improve security, pushing and introducing frameworks, tools or services that have measurable impact. Collaborate closely with other teams, creating ties, trust relationships, providing security guidance. Be the go-to expert for application security issues, seek for security reviews, threat assessments. Have your own initiatives for improving application security. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)