Senior/Staff Mobile Security Engineer
$251k - $325kWorld Coin
About the Company:
World is building a real human network designed to accelerate people in the age of AI. As bots and autonomous agents reshape the internet, people, institutions, and applications need a trusted way to confirm who is a real human while preserving privacy. Our products make this possible: the Orb verifies real people, World ID proves it privately, and World App enables and distributes the new applications made possible by this technology. Together, they form a new layer for AI internet.
We’re one of the fastest-growing networks in tech. More than 17 million people across 160 countries have verified with World ID, and we complete over 350,000 verifications each week. World App is already among the most used wallets globally. Developers are integrating World ID to build safer online experiences and create spaces where real people can participate, earn, and be recognized in ways AI simply can’t replicate.
World was founded in 2019 and launched globally in 2023. We are more than 400 people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI, Tesla, SpaceX, Apple, Google, Stripe, Meta, Coinbase, Palantir and MIT Media Lab. We’re backed by leading investors, including a16z, Khosla Ventures, Bain Capital Crypto, Blockchain Capital, Variant, Tiger Global, and Coinbase Ventures, as well as prominent operators and founders across fintech and AI.
World has been featured on the cover of TIME Magazine, highlighted in Fast Company’s Next 5 in Fintech, and explored in a Bloomberg deep dive. The New York Times, Bankless and TechCrunch have all recognized our progress in identity, cryptography, AI, and global-scale hardware deployment. Our leadership is also named to the Time AI 100. Learn more about the newest product launches from our Unwrapped event.
About the Team
The Security team at Tools for Humanity operates at a level far beyond a regular company. Our objective is not just to secure an organization, but to build the trusted, foundational infrastructure for the world's largest identity and financial network. We are a team of over 15 seasoned engineers who are central to the success of the World protocol. We tackle a unique and complex threat landscape that spans state-of-the-art hardware security for the Orb, advanced cryptography including new zero-knowledge proofs, and the security of a global, distributed cloud and mobile ecosystem. Our work is critical to enabling the protocol to scale to billions of users while upholding an unwavering commitment to fail-safe security and privacy.
About the Opportunity
As a Mobile Security Engineer, you will own the security and integrity of the mobile applications at the core of the World protocol World App on Android and iOS used by millions of people worldwide to verify their identity, authenticate with biometrics, and manage digital assets. This is not a consultative role; you will be a hands-on builder, designing and implementing the systems that ensure our mobile clients are trustworthy, tamper-resistant, and resistant to adversarial attack at global scale.
Our mobile threat model is uniquely challenging: the World App must perform privacy-preserving biometric operations (iris and face authentication) on-device, hold cryptographic keys for identity proofs, and interact with hardware attestation systems all while operating in environments where adversaries range from casual fraud to nation-state-level identity fabrication at scale. You will be the expert who ensures this stack cannot be subverted.
You will:
- Design, build, and operate mobile device attestation and integrity verification systems across Android and iOS including hardware-backed key attestation (Android KeyStore TEE/StrongBox, Apple App Attest/Secure Enclave), ensuring requests originate from genuine, untampered devices running unmodified app code.
- Engineer anti-tampering, anti-hooking, and runtime integrity protections for the World App, making the app resilient against reverse engineering, instrumentation frameworks (Frida, Xposed), and repackaging attacks.
- Own the mobile hardening strategy end-to-end: certificate pinning, secure storage, obfuscation, jailbreak/root detection, debugger detection, and screen capture protection deciding which protections to build in-house and which to source from vendors.
- Design cryptographic protocols for on-device biometric authentication (Face Auth, selfie verification) that are resistant to replay, relay, and deepfake injection attacks, ensuring the biometric pipeline cannot be manipulated even on a compromised device.
- Build and maintain the server-side attestation verification infrastructure (our Attestation Gateway) that validates Play Integrity tokens, hardware attestation certificate chains, and Apple App Attest assertions, making trust decisions that gate access to sensitive operations.
- Lead threat modeling for mobile-specific attack surfaces: biometric bypass, key extraction, device cloning, session hijacking, overlay attacks, accessibility abuse, and automated bot farms using real devices.
- Embed security into the mobile development lifecycle performing deep code reviews of Android (Kotlin) and iOS (Swift) code, building automated security checks into CI/CD, and establishing secure coding standards for mobile teams.
- Mature our vulnerability management process for mobile, from triaging mobile-specific bug bounty submissions to driving remediation with mobile engineering teams.
- Evaluate, integrate, and manage mobile security tooling and vendor relationships (RASP, SAST for mobile, binary analysis tools).
About You
You are a deeply technical mobile security engineer who has spent years protecting high-value mobile applications against sophisticated adversaries. You have a builder's mindset; you don't just find problems, you ship solutions. You've been responsible for the security of mobile apps where the stakes are real: payments, identity, or financial services at scale.
Required:
- 8+ years of hands-on experience in mobile security engineering, with deep expertise in at least one of Android or iOS (strong in both is ideal).
- Proven experience designing and operating mobile device attestation systems you understand Android Hardware Key Attestation (KeyMint, TEE, StrongBox, attestation certificate chains, Google root CA verification), Google Play Integrity API (Classic and Standard modes), and/or Apple App Attest (DeviceCheck, attestation/assertion flows, Secure Enclave) at a systems level, not just as an API consumer.
- Strong background in mobile application hardening: you have implemented or evaluated anti-tampering, anti-hooking, root/jailbreak detection, debugger detection, certificate pinning, and runtime integrity protection in production apps.
- Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx, apktool), analyze iOS binaries, use Frida/Objection for dynamic analysis, and think like an attacker to validate your defenses.
- Proficiency in Kotlin/Java (Android) and/or Swift (iOS) for security-focused code review and building security libraries.
- Experience securing on-device cryptographic operations: key generation, secure storage (Android KeyStore, iOS Keychain), and protocols that depend on hardware-backed keys.
- Strong understanding of mobile-specific attack vectors: overlay attacks, accessibility service abuse, screen recording, deepfake injection into camera pipelines, biometric bypass, and app cloning.
Nice to have:
- Experience building or operating server-side attestation verification services (decrypting Play Integrity JWE/JWS tokens, validating X.509 attestation certificate chains, managing Apple App Attest key lifecycle in a backend).
- Experience with RASP vendor evaluation and integration (Zimperium, Guardsquare/DexGuard, Promon, Appdome).
- Background in payment security or PCI-compliant mobile applications (SoftPOS, Tap-to-Pay, EMV).
- Familiarity with privacy-preserving systems: zero-knowledge proofs, on-device biometric processing, or differential privacy.
- Experience scaling a Secure SDLC or security champions program for mobile engineering teams.
- Contributions to mobile security research, conference talks, or open-source security tooling.
- Rust, Go, or Python experience for backend security tooling and infrastructure.
What we offer
The reasonably estimated salary for this role at Tools for Humanity ranges from $251,000 - $325,000 plus a competitive long-term incentive package. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Tools for Humanity offers a wide range of best-in-class, comprehensive, and inclusive employee benefits for this role, including healthcare, dental, vision, 401(k) plan and match, life insurance, flexible time off, commuter benefits, professional development stipend, and much more.
By submitting your application, you consent to the processing and internal sharing of your CV within the company, in compliance with the GDPR.
If you don't think you meet all of the criteria but are still interested in the job, please apply. Nobody checks every box, and we’re looking for someone excited to join the team.
#J-18808-Ljbffr$251k - $325k
...than 400 people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI, Tesla,... ...launches from our [Liftoff]( event. About the Team The Security team at Tools for Humanity operates at a level far beyond a...SeniorCasual workWorldwideFlexible hours$320k - $405k
...Staff / Senior Physical Security Systems Engineer Remote-Friendly (Travel Required) | San Francisco, CA About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for...SeniorRemote jobFor contractorsWork at officeVisa sponsorshipFlexible hours- ...whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the role Data Center Security Engineering (DCSE) secures Anthropic's data center footprint; this...SeniorFull time
$147k - $252k
...Read ouroperating principles to see it in full.About the teamOur Mobile Team is responsible for the end-to-end development of both our... ...integration for card transactions.What you’ll doAs a Mobile Engineer, you’ll focus on building high-quality, user-friendly native mobile...SeniorTemporary workLocal area- ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security...SeniorWork at officeRelocation3 days per week1 day per week
$232k - $290k
...to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence...SeniorFull timeWork at officeLocal area$150k - $240k
...and collaborates.We’re assembling a diverse, world-class team—engineers, designers, researchers, and product minds—focused on creating... ...everywhere can do their best work.About The RoleAs an Offensive Security Engineer within HP IQ’s Product Security team, you will...SeniorFull timeTemporary workLocal areaFlexible hours- ...Senior Security Engineer, Enterprise Security CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI...SeniorFor contractorsRemote work
- ...official communication will only be sent from @Rippling.com addresses.About The RoleWe are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Rippling's security program forward. This role offers the opportunity to...SeniorFull timeWork at officeRelocation3 days per week1 day per week
$141.6k - $212.4k
...life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny.Klaviyo is looking for a Senior Security Engineer to add to our growing Detection and Response (D&R) Team. This is a hands-on technical role that involves building and...Senior$174.5k - $240k
...keep Faire's AI adoption moving fast, safely:The Enterprise Security team at Faire owns the tools and policies that keep our... ...threat detection, compliance training, and AI governance.As our Senior Security Engineer focusing on Enterprise AI, you will own the AI platforms...SeniorWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week- ...Serve as a subject matter expert in network security, focusing on firewalls, VPNs, and routing/switching technologies within cloud-native AI infrastructure. Manage and update firewall configurations across the enterprise network to align with security needs. Deploy...Senior
$172k - $215k
...ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Security Engineer on the Security Operations team, you will help Ripple detect, investigate, and respond to security threats across our...SeniorFull timeWork at officeLocal area$175k - $220k
Location: New York City or San Francisco - 4 days in officeAbout the RoleWe are looking for a highly technical Senior Security Engineer who thrives on building security capabilities from the ground up. This role is ideal for someone who enjoys solving complex security...SeniorFull timeWork at office$10 per hour
...you'll doThere is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager rotation so...SeniorWork at officeLocal areaImmediate startRelocationRelocation packageFlexible hours$170k - $205k
...be part of a high-performing team that believes in each other, come build with us at Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This...SeniorTemporary work$213k
About the roleWe are looking for a Sr. Full Stack Application Security Engineer with deep expertise in mobile application security to join our Product Security team. This role is hands-on and impact driven. You will work directly with mobile, backend, and platform engineering...SeniorFull timeWork at officeLocal areaRemote work- ...HP IQ in San Francisco is seeking an Offensive Security Engineer to partner with engineering teams to identify, validate, and mitigate security risks across the product lifecycle. You will influence design decisions, embed security into development workflows, and continuously...Senior
- ...Escalation Point of Contact: Serve as the primary Level 3 escalation point for resolving complex network infrastructure, routing, and security configuration issues across both on-premise Data Centers and AWS environments. Maintain Multi-Vendor Security & Perimeter...Senior
- ...Ventura Solutions LLC (WonderSee Labs) is seeking a versatile Software Engineer to lead mobile app development for a medical device startup. The role combines software, hardware, and firmware awareness, with a focus on BLE data flow, on‑device analytics, and cross‑platform...SeniorRemote job
- ...team and help support some of the most important innovation happening in healthcare today! The Role We’re looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our...SeniorFlexible hours
$130k - $225k
...About the Role As the first full-time security engineer at an early-stage AI infrastructure company, you will build and operate the security program from the ground up. You will work across product, infrastructure, compliance, and incident response to protect AI systems...SeniorFull timeVisa sponsorshipRelocation package- ...Overview We are looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security strategy and defend our fast-growing cloud platform. You will design and deploy advanced safeguards concentrated on the network perimeter, ensuring our edge remains...SeniorFull time
$200k - $330k
...About the Role This is a senior individual contributor role owning application security for a rapidly scaling, multi-tenant AI agent platform that serves enterprise... .... You will sit at the intersection of product engineering and security, embedding secure practices across...Senior- ...Discord is seeking a Senior Software Engineer for the Application Security team to protect user accounts. You will design and implement full‑stack security solutions, strengthen session security, and own authentication services for hundreds of millions of users. With...SeniorRemote job
- ...behalf of our client. Establish and run a security and privacy function from the ground up... ...with outside assessors and keeping staff aligned with internal policies. Define... ...startup or at a company known for a demanding engineering bar. ~ Hands-on exposure to SOC 2 Type...SeniorFull timeWork at officeFlexible hours3 days per week
$214k - $280k
...Security Engineer OpportunityApollo Research works with most frontier AI companies to test their models before deployment and collaborate on... ...provided for all employees on workdaysPaid work trips, including staff retreats, business trips, and relevant conferencesA yearly $1...SeniorWork at officeWork from homeVisa sponsorshipFlexible hours$164k
About the RoleAs a mobile platform engineer, you'll help shape the future of Chime's React Native app, building the infrastructure and tooling that make development faster, safer, and more scalable for hundreds of engineers working alongside AI.You'll thrive in this role...SeniorFull timeWork at officeLocal areaRemote work- ...compliances, Plaud is committed to the highest standards of data security and privacy protection. To learn more about Plaud, please... ...Standing Privileges via JIT/CIEM. SIEM Build & Detection Engineering - Deploy the SIEM platform and author 30+ MITRE ATT&CK-mapped...SeniorWorldwide
$166k - $185k
...our founding vision and unlock world-class medicine through world-class operations. About The Role We're looking for a Security Engineer to own the design and buildout of Qventus' cloud and data security tooling. This role will be responsible for driving engineering...SeniorLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior/Staff Mobile Security Engineer. Be the first to apply!
- assistant engineer San Francisco, CA
- senior staff systems engineer San Francisco, CA
- technology administrator San Francisco, CA
- engineering aide San Francisco, CA
- senior staff engineer San Francisco, CA
- staff design engineer San Francisco, CA
- assistant electrical engineer San Francisco, CA
- staff data engineer San Francisco, CA
- software engineer staff San Francisco, CA
- staff engineer San Francisco, CA


