Senior Product Security Engineer - Alacant

Socium - Teams Done Differently
Alicante (Alacant), Spain
15 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, Spanish

Tech stack

C (Programming Language) Java (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Apple IOS Biometrics C++ (Programming Language) Continuous Integration Data Security Cursor (Graphical User Interface Elements) Emulators
+25 more
Fraud Prevention and Detection Github Virtual Private Networks (VPN) Mobile Application Software Python (Programming Language) Open Web Application Security PCI Data Security Standards Reverse Engineering Security Information and Event Management Software Engineering Systems Integration Web Services Transport Layer Security Flask (Web Framework) Software Security Malware Backend Git Kotlin Gitlab-ci Production Code Api Design Objective C++ Docker Jenkins

Job description

?Product Security Engineer - Mobile RASPThis is a Fully Remote role, but the individual needs to be based in Spain.Our client is a mobile identity and security company whose platform protects high-assurance apps from attack while they run - on devices the company doesn’t control.They’re hiring a hands-on Product Security Engineer to help build out their mobile application security (RASP) platform.This is a genuine builder role, not a policy or governance one.You’ll write production code across mobile and backend, working at high velocity with AI as your primary development accelerator.What you’ll be building:You’ll ship the in-house shields that defeat rooting/jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception (MITM, SSL-pinning bypass, malicious VPN/proxy) - built on top of a licensed RASP core.You’ll own the applied cryptography behind secure local storage and app/device attestation, plus the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.The product spans both sides of the wire, so you’ll also build and operate the platform’s Python (Flask) backend - the APIs and services that ingest threat telemetry, drive the operator console, manage configuration and policy, and forward events to SIEM.Because you’re building the product, you’ll also run hands-on competitive evaluations (against the likes of Promon, Appdome, Guardsquare, Zimperium and Build38) and support the Sales & Solutioning team as a technical pre-sales engineer when needed.What we’re looking for:Strong, current, hands-on software engineering - you code daily and ship to productionMobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focusedExperience integrating and extending third-party SDKs via callback/event APIsCode-hardening experience - obfuscation and binary hardening across native mobile toolchainsApplied cryptography fundamentals (secure data-at-rest storage, attestation)Backend development in Python (Flask), with solid testing and API-design disciplineProven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar)Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentalsFamiliarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators)Professional-standard EnglishStrongly preferred:Spanish (spoken and written), given the company’s Spanish-speaking European and LATAM customer and supplier base.Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment.Location:Fully remote, based in Spain or London.If you want to own real runtime security defences end-to-end - mobile client through to backend - and ship at speed with AI as your co-pilot, we’d love to hear from you.Company details shared on application.#ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec

Requirements

Strong, current, hands-on software engineering - you code daily and ship to production Mobile SDK development in iOS (Swift/Obj-C) and/or Android (Kotlin/Java), ideally security- or SDK-focused Experience integrating and extending third-party SDKs via callback/event APIs Code-hardening experience - obfuscation and binary hardening across native mobile toolchains Applied cryptography fundamentals (secure data-at-rest storage, attestation) Backend development in Python (Flask), with solid testing and API-design discipline Proven experience building and shipping quickly with AI coding tools (Claude Code, Copilot, Cursor, or similar) Practical CI/CD experience (GitHub Actions, GitLab CI or Jenkins) and solid AWS, Git and Docker fundamentals Familiarity with RASP/MTD, OWASP MASVS/MASTG, and the mobile attacker toolkit (Frida, Xposed, Magisk, emulators) Professional-standard English Strongly preferred:Spanish (spoken and written), given the company’s Spanish-speaking European and LATAM customer and supplier base. Experience or interest in fraud management (behavioural biometrics, transaction risk scoring, device intelligence) and EU regulatory frameworks (PSD2 SCA, DORA, GDPR, PCI-DSS, eIDAS 2.0) is a plus, as is a background in a security vendor or fintech/banking environment. Location:Fully remote, based in Spain or London. If you want to own real runtime security defences end-to-end - mobile client through to backend - and ship at speed with AI as your co-pilot, we’d love to hear from you. Company details shared on application. #ProductSecurity #MobileSecurity #RASP #Cybersecurity #Hiring #RemoteWork #iOS #Android #Python #AppSec

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:09 min

Understanding Kotlin Multiplatform and its compiler targets

Petar Marijanović · LIVE

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all