
Staff Mobile & Product Security Engineer
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United States.
• Collaborate with mobile and product teams within the membership app, marketplace, data, and identity to conduct threat modeling, review, and enhance features prior to launch.
• Oversee the mobile application security program, encompassing secure mobile SDLC, mobile code review, dependency and supply-chain controls, as well as security tools for developers.
• Lead the broader application security initiative for products, which includes secure-by-default patterns, API and backend security assessments, and paved-road tooling.
• Manage the comprehensive penetration testing program across mobile, web, and APIs; coordinate external engagements and facilitate remediation efforts.
• Design security controls and documentation to fulfill partner security requirements.
• Establish the security baseline for a zero-to-one AI-native stack, which includes coding agents, model and prompt security, and mobile AI features.
• Develop mobile and product security standards, guidelines, and paved-road practices to scale organizationally.
• Create secure membership ecosystem products that encompass native mobile applications, web clients, and backend platform services for over 100 million users.
• Proven experience as a security engineer integrated into a product or mobile team.
• Proficient in coding, submitting pull requests, and implementing fixes.
• Experience in securing native iOS and/or Android applications at a consumer scale.
• Knowledge of reverse engineering, tampering, insecure storage, insecure IPC, and mobile API exploitation.
• Experience leading or significantly contributing to an application security program for a consumer product used by millions.
• Capability to conduct penetration tests on mobile and web applications, including on-device and API-level mobile vulnerabilities.
• Familiarity with designing against partner security frameworks or similar standards, such as SOC 2, PCI, vendor security assessments, or mobile app store security criteria.
• Experience with coding agents, model and prompt security, and on-device/mobile AI capabilities.
• Background in startups building from the ground up within an agile team, alongside exposure to large-scale tech environments.
• Mobile-specific code review expertise in Swift, Kotlin, and/or React Native.
• Knowledge of static/dynamic analysis, binary/reverse engineering, API abuse, threat modeling, secure SDLC, dependency and supply-chain controls, API/backend security assessments, and security tooling.
• Competitive Salary
• Comprehensive Medical (Blue Cross Blue Shield), Dental, Vision, and company-paid Life Insurance
• Company contributions to employee Health Savings Accounts (HSA)
• 401k Plan with Safe Harbor company-matching
• Flexible vacation policy and paid company holidays
• Company-provided technology package
• Relocation assistance where applicable, including travel and company-provided housing for the initial 90 days
• Bonus
• Equity
AbbVie
Biogen
RunPod
LRQA
Get handpicked remote jobs straight to your inbox weekly.