Senior/Staff Mobile Security Engineer
$251k - $325kTools for Humanity
Tools for Humanity (TFH) designs and builds technology behind World. World is building a real human network designed to accelerate people in the age of AI. As bots and autonomous agents reshape the internet, people, institutions, and applications need a trusted way to confirm who is a real human while preserving privacy. The TFH and World tech stacks make this possible: the Orb verifies real, unique people, World ID proves it privately, and World App puts these capabilities, and more, in people’s hands. Together, they add a human layer to an AI-driven internet.
World is already running at a global scale. More than 17 million people across 160 countries have verified with World ID, and more new Orb verifications take place each week. World App is already among the most used wallets globally. Developers are integrating World ID to build safer online experiences and create spaces where real people can participate, earn, and be recognized in ways AI simply can’t replicate.
Founded in 2019, TFH has more than 400 people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI, Tesla, SpaceX, Apple, Google, Stripe, Meta, Coinbase, Palantir and MIT Media Lab. We’re backed by leading investors, including a16z, Khosla Ventures, Bain Capital Crypto, Blockchain Capital, Variant, Tiger Global, and Coinbase Ventures, as well as prominent operators and founders across fintech and AI.
TFH and World have been featured on the cover of [TIME Magazine]( highlighted in [Fast Company’s]( Next 5 in Fintech, and explored in a [Bloomberg deep dive]( [The New York Times]( [Bankless]( and [TechCrunch]( have all recognized our collective progress in identity, cryptography, AI, and global-scale hardware deployment. Our leadership is also named to the [Time AI 100]( Learn more about the newest product launches from our [Liftoff]( event.
About the Team
The Security team at Tools for Humanity operates at a level far beyond a regular company. Our objective is not just to secure an organization, but to build the trusted, foundational infrastructure for the world's largest identity and financial network. We are a team of over 15 seasoned engineers who are central to the success of the [World]( protocol. We tackle a unique and complex threat [landscape]( that spans state-of-the-art hardware security for the Orb, advanced cryptography including new zero-knowledge proofs, and the security of a global, distributed cloud and mobile ecosystem. Our work is critical to enabling the protocol to scale to billions of users while upholding an unwavering commitment to fail-safe security and privacy.
About the Opportunity
As a Mobile Security Engineer, you will own the security and integrity of the mobile applications at the core of the World protocol World App on Android and iOS used by millions of people worldwide to verify their identity, authenticate with biometrics, and manage digital assets. This is not a consultative role; you will be a hands-on builder, designing and implementing the systems that ensure our mobile clients are trustworthy, tamper-resistant, and resistant to adversarial attack at global scale.
Our mobile threat model is uniquely challenging: the World App must perform privacy-preserving biometric operations (iris and face authentication) on-device, hold cryptographic keys for identity proofs, and interact with hardware attestation systems all while operating in environments where adversaries range from casual fraud to nation-state-level identity fabrication at scale. You will be the expert who ensures this stack cannot be subverted.
You will:
- Design, build, and operate mobile device attestation and integrity verification systems across Android and iOS including hardware-backed key attestation (Android KeyStore TEE/StrongBox, Apple App Attest/Secure Enclave), ensuring requests originate from genuine, untampered devices running unmodified app code.
- Engineer anti-tampering, anti-hooking, and runtime integrity protections for the World App, making the app resilient against reverse engineering, instrumentation frameworks (Frida, Xposed), and repackaging attacks.
- Own the mobile hardening strategy end-to-end: certificate pinning, secure storage, obfuscation, jailbreak/root detection, debugger detection, and screen capture protection deciding which protections to build in-house and which to source from vendors.
- Design cryptographic protocols for on-device biometric authentication (Face Auth, selfie verification) that are resistant to replay, relay, and deepfake injection attacks, ensuring the biometric pipeline cannot be manipulated even on a compromised device.
- Build and maintain the server-side attestation verification infrastructure (our Attestation Gateway) that validates Play Integrity tokens, hardware attestation certificate chains, and Apple App Attest assertions, making trust decisions that gate access to sensitive operations.
- Lead threat modeling for mobile-specific attack surfaces: biometric bypass, key extraction, device cloning, session hijacking, overlay attacks, accessibility abuse, and automated bot farms using real devices.
- Embed security into the mobile development lifecycle performing deep code reviews of Android (Kotlin) and iOS (Swift) code, building automated security checks into CI/CD, and establishing secure coding standards for mobile teams.
- Mature our vulnerability management process for mobile, from triaging mobile-specific bug bounty submissions to driving remediation with mobile engineering teams.
- Evaluate, integrate, and manage mobile security tooling and vendor relationships (RASP, SAST for mobile, binary analysis tools).
About You
You are a deeply technical mobile security engineer who has spent years protecting high-value mobile applications against sophisticated adversaries. You have a builder's mindset; you don't just find problems, you ship solutions. You've been responsible for the security of mobile apps where the stakes are real: payments, identity, or financial services at scale.
Required:
- 8+ years of hands-on experience in mobile security engineering, with deep expertise in at least one of Android or iOS (strong in both is ideal).
- Proven experience designing and operating mobile device attestation systems you understand Android Hardware Key Attestation (KeyMint, TEE, StrongBox, attestation certificate chains, Google root CA verification), Google Play Integrity API (Classic and Standard modes), and/or Apple App Attest (DeviceCheck, attestation/assertion flows, Secure Enclave) at a systems level, not just as an API consumer.
- Strong background in mobile application hardening: you have implemented or evaluated anti-tampering, anti-hooking, root/jailbreak detection, debugger detection, certificate pinning, and runtime integrity protection in production apps.
- Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx, apktool), analyze iOS binaries, use Frida/Objection for dynamic analysis, and think like an attacker to validate your defenses.
- Proficiency in Kotlin/Java (Android) and/or Swift (iOS) for security-focused code review and building security libraries.
- Experience securing on-device cryptographic operations: key generation, secure storage (Android KeyStore, iOS Keychain), and protocols that depend on hardware-backed keys.
- Strong understanding of mobile-specific attack vectors: overlay attacks, accessibility service abuse, screen recording, deepfake injection into camera pipelines, biometric bypass, and app cloning.
Nice to have:
- Experience building or operating server-side attestation verification services (decrypting Play Integrity JWE/JWS tokens, validating X.509 attestation certificate chains, managing Apple App Attest key lifecycle in a backend).
- Experience with RASP vendor evaluation and integration (Zimperium, Guardsquare/DexGuard, Promon, Appdome).
- Background in payment security or PCI-compliant mobile applications (SoftPOS, Tap-to-Pay, EMV).
- Familiarity with privacy-preserving systems: zero-knowledge proofs, on-device biometric processing, or differential privacy.
- Experience scaling a Secure SDLC or security champions program for mobile engineering teams.
- Contributions to mobile security research, conference talks, or open-source security tooling.
- Rust, Go, or Python experience for backend security tooling and infrastructure.
What we offer
The reasonably estimated salary for this role at Tools for Humanity ranges from $251,000 - $325,000 plus a competitive long-term incentive package. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Tools for Humanity offers a wide range of best-in-class, comprehensive, and inclusive employee benefits for this role, including healthcare, dental, vision, 401(k) plan and match, life insurance, flexible time off, commuter benefits, professional development stipend, and much more.
By submitting your application, you consent to the processing and internal sharing of your CV within the company, in compliance with the GDPR.
If you don't think you meet all of the criteria but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.
$117.2k - $176.7k
...right place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceThe Product Security team is seeking a Mobile Security Engineer who will own the security posture of Salesforce's mobile application portfolio — spanning many distinct apps...SuggestedFull time$147k - $252k
...that sounds like you, let’s build what’s next.About the teamOur Mobile Team is responsible for the end-to-end development of both our... ...Pay integration for card transactions.What you’ll doAs a Mobile Engineer, you’ll focus on building high-quality, user-friendly native...SeniorTemporary workLocal areaWorldwide$161k - $197k
...iOS and 4.6-star rating from 5,000+ reviews on Android. As a Senior Mobile Engineer, you will own the technical roadmap for our app and... ...direction of the Circle Medical Android app keeping it stable, secure, and aligned with iOS feature parity.Implement, test, and maintain...SeniorFull timeRemote workFlexible hours- ...smarter and more capable. The Role We're looking for a Senior Mobile Engineer to own the mobile experience inside Dispatch. This is a high... ...what we ship. What You'll Do Design and implement secure, scalable, high-performance mobile applications using React...SeniorWork at officeFlexible hours
- ...About the team The Airwallex Information Security Team is a high calibre and highly proactive team that... ...infrastructure, app security, Corporate IT and broader engineering functions. What you’ll do As a Senior Software Engineer in our Security Engineering team...SeniorFull timeWorldwide
$208k - $312k
...that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is... ...to prompt injection and tool misuse.We're looking for a Senior (IC4) software engineer with a strong security background to sit fully embedded inside...SeniorFull timeWork from homeWorldwideFlexible hours- ...that all official communication will only be sent from @Rippling.com addresses.About The RoleWe're looking for a hands-on senior security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security...SeniorWork at officeRelocation3 days per week1 day per week
$181k
About the roleWe are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime’s services, applications, and infrastructure to discover security issues and report them to our internal technology teams. This...SeniorFull timeWork at officeLocal areaRemote work$200k - $225k
...join our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time representative... ...your personal information. If you are viewing this on a mobile device you may want to view the CCPA version on a larger...SeniorFull timeLocal areaImmediate startRemote work$220k
...Venture Partners, and Craft Ventures.The Security Team @ PaveSecurity at Pave protects the... ...that runs on it. The team is small, senior, and AI pilled: everyone builds, everyone... ...across domains. As Pave's Corporate Security Engineer, you'll own the corporate side of that...SeniorWork at officeFlexible hours3 days per week$130k
About the roleWe are looking for a versatile Security Software Engineer to join our team and operate across product security, application security... ...and corporate applicationsPerform security reviews across mobile, backend, cloud, and API systemsConduct penetration testing...SeniorFull timeWork at officeLocal areaRemote work$175k - $220k
About the RoleWe are looking for a highly technical Senior Security Engineer who thrives on building security capabilities from the ground up. This role is ideal for someone who enjoys solving complex security challenges through engineering, automation, and AI rather than...SeniorFull timeWork at office$150k - $220k
...build what’s next.About the teamAirwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems,... ...operate, not treated as a blocker.What You'll doAs a Senior Corporate Security Engineer, you will be a critical...SeniorTemporary workLocal areaWorldwide$112k - $209k
...and your search for important and impactful work lead to the same place.The global law firm of K&L Gates LLP is seeking a Senior Security Engineer to join the firm. The Senior Security Engineer develops, automates, and enhances security capabilities for cloud, on-premises...SeniorFull timeTemporary workWork experience placementLocal areaRemote work$170k - $205k
...be part of a high-performing team that believes in each other, come build with us at Crusoe.About the Role:Crusoe is seeking a Security Engineer to join the Security Engineering team as the primary driver for implementing security defaults and endpoint visibility. This...SeniorTemporary work- ...solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize,... ...empowerment, inclusion, respect, and accountability.Senior Security Engineer, Detection and ResponseRemote Location: Austin TX, Seattle,...SeniorApprenticeshipLocal areaRemote workFlexible hoursShift work
$127k - $249k
We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security controls and services within MongoDB Atlas multi-cloud infrastructure.The team sits within the Site Reliability Engineering...SeniorWork at officeLocal areaRemote workWorldwideFlexible hours$148.5k - $260.1k
...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain the security of using AI tooling securely.In this role,...SeniorFull time- ...A fintech company in San Francisco is looking for a Security-Focused DevOps Engineer for a full-time, in-person position. The role involves securing payment infrastructure, building CI/CD pipelines, and conducting security audits. Candidates should have over 4 years of...SeniorFull time
$200k - $275k
A leading technology firm in San Francisco is seeking a Staff Software Engineer focused on Product Security. This role involves building secure frameworks, resolving security risks, and collaborating with teams to ensure best practices in security. The ideal candidate will...Senior$174.5k - $240k
...people to join us as we power the shop local movement. If you believe in community, come join ours.About the role:As a Senior Enterprise Security Engineer, you will help protect Faire's corporate environment across endpoint, network, identity, and SaaS, and play a key...SeniorWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week- ...Overview We are looking for a seasoned Senior / Staff Network Security Engineer to spearhead our security strategy and defend our fast-growing cloud platform. You will design and deploy advanced safeguards concentrated on the network perimeter, ensuring our edge remains...SeniorFull time
$232k - $290k
...to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence...SeniorFull timeWork at officeLocal area$210k - $230k
...experience requirements vary by role and will be assessed during the interview process.About the Role:We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning the design and operation of our Cloudflare WAF, DDoS...SeniorFull timeWork at officeLocal areaRemote work2 days per week3 days per week$163.2k - $220.8k
...entrepreneurial spirit allow exceptional opportunities for professional achievement and career growth. Wilson Sonsini is looking for a Senior AI Security Engineer to join the Security Operations team. The Senior AI Security Engineer, under the direction of the Director, Security...SeniorFull timeWork experience placementRemote workWorldwideShift work$232k - $290k
...to see your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer, you will be one of Ripple's most senior technical security practitioners, operating at the intersection of application...SeniorFull timeWork at officeLocal area- ...This is a full-time, in-person role. You\'ll be responsible for: Securing our payment infrastructure and protecting customer financial... ...4+ years of experience in DevOps, infrastructure, or security engineering Strong understanding of application security, particularly in...SeniorFull time
$293k - $385k
...that artificial general intelligence benefits all of humanity.The Security organization protects OpenAI’s technology, people, and products... ...and auditability.About the RoleOpenAI is seeking a Security Engineer, Host Assurance to help build the trust foundations for bare-metal...Work at officeLocal areaRelocation packageFlexible hours$175k - $220k
About the RoleWe are looking for a highly technical Senior Security Engineer who is passionate about protecting data across modern SaaS, cloud, endpoint, and analytics environments.This role is ideal for someone who enjoys solving complex data security challenges through...SeniorFull timeWork at office$202k - $230k
...soon For every critical workflow Ready-to-go AI agents for every team Powerful no-code automations Your AI Chief of Staff Senior Software Engineer, Security Development San Francisco We are dedicated to ensuring proactive elimination of entire classes of security risk by...SeniorFull timeWork at officeLocal areaWork from homeWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior/Staff Mobile Security Engineer. Be the first to apply!
- staff security engineer San Francisco, CA
- engineering aide San Francisco, CA
- technology administrator San Francisco, CA
- senior staff engineer San Francisco, CA
- staff engineer San Francisco, CA
- senior staff systems engineer San Francisco, CA
- staff data engineer San Francisco, CA
- assistant engineer San Francisco, CA
- staff design engineer San Francisco, CA
- software engineer staff San Francisco, CA


