> Markdown version of [/jobs/ext/2131721-senior-product-security-engineer-girona](https://www.wearedevelopers.com/jobs/ext/2131721-senior-product-security-engineer-girona). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Security Engineer - Girona - **Company:** Socium - Teams Done Differently - **Location:** Oña, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Apple IOS, Biometrics, C++ (Programming Language), Continuous Integration, Data Security, Cursor (Graphical User Interface Elements), Emulators, Fraud Prevention and Detection, Github, Virtual Private Networks (VPN), Mobile Application Software, Python (Programming Language), Open Web Application Security, PCI Data Security Standards, Reverse Engineering, Security Information and Event Management, Software Engineering, Systems Integration, Web Services, Transport Layer Security, Flask (Web Framework), Software Security, Malware, Backend, Git, Kotlin, Gitlab-ci, Production Code, Api Design, Objective C++, Docker, Jenkins - **Published:** August 19, 2026 - **Apply:** https://www.buscojobs.com.es/senior-product-security-engineer-girona-en-ona-ID-367908473 ## About the Role Strong, current, hands-on software engineering - you code daily and ship to production Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused Experience integrating and extending third-party SDKs via callback/event APIs Code-hardening experience - obfuscation and binary hardening across native mobile toolchains Applied cryptography fundamentals (secure data-at-rest storage, attestation) Backend development in Python (Flask), with solid testing and API-design discipline Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar) Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators) Professional-standard English Strongly preferred:Spanish (spoken and written), given the company's Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment. Location:Fully remote, based in Spain or London. If you want to own real runtime security defences end-to-end - mobile client through to backend - and ship at speed with AI as your co-pilot, we'd love to hear from you. Company details shared on application. #ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec ## Description ?Product Security Engineer - Mobile RASPThis is a Fully Remote role, but the individual needs to be based in Spain.Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run - on devices the company doesn't control.They're hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.This is a genuine builder role, not a policy or governance one.You'll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.What you'll be building:You'll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) - built on top of a licensed RASP core.You'll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.The product spans both sides of the wire, so you'll also build and operate the platform's Python (Flask) backend - the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.Because you're building the product, you'll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38) and support the Sales & Solutioning team as a technical pre-sales engineer when needed.What we're looking for:Strong, current, hands-on software engineering - you code daily and ship to productionMobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focusedExperience integrating and extending third-party SDKs via callback/event APIsCode-hardening experience - obfuscation and binary hardening across native mobile toolchainsApplied cryptography fundamentals (secure data-at-rest storage, attestation)Backend development in Python (Flask), with solid testing and API-design disciplineProven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentalsFamiliarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)Professional-standard EnglishStrongly preferred:Spanish (spoken and written), given the company's Spanish-speaking European and LATAM customer and supplier base.Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.Location:Fully remote, based in Spain or London.If you want to own real runtime security defences end-to-end - mobile client through to backend - and ship at speed with AI as your co-pilot, we'd love to hear from you.Company details shared on application.#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Migrating half a million users to a new payment service provider](https://www.wearedevelopers.com/videos/730-migrating-half-a-million-users-to-a-new-payment-service-provider) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)