Job Opportunities
Find jobs near you, whether onsite, hybrid, or remote.- Similar Jobs to: Staff Product Security Engineer
Senior/Staff Mobile Security Engineer
Tools for HumanityUnited StatesAbout the Company:Tools for Humanity (TFH) designs and builds technology behind World. World is building a real human network designed to accelerate people in the age of AI. As bots and autonomous age
Staff Design Engineer
Aave LabsUnited StatesOur cultureHaving cultivated a thriving, collaborative culture, our team is kind, welcoming and passionate about what we are building. We celebrate differences and seek to develop and retain the most
Staff Backend Engineer
Socure IncUnited StatesWhy Socure?Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the pr
Staff Solutions Engineer
VasionUnited StatesVasion is looking for a Staff Solutions Engineer who serves as the technical authority behind every deal - guiding prospects from program offices and IT leads to agency executives, shaping deal strate
Staff DevOps Engineer
Virtual Vocations IncUnited StatesA company is looking for a Staff DevOps Engineer to work across teams to tackle complex problems and drive platform improvements. Key ResponsibilitiesDesign, develop, and deliver solutions to enhance
Staff Analytics Engineer
NubankUnited StatesStaff Analytics EngineerUSA, Durham; USA, Miami; USA, Palo Alto; USA, Washington DC About UsNu is one of the largest digital financial platforms in the world, with more than 135 million customers acro
Staff Fullstack Engineer
Virtual Vocations IncUnited StatesA company is looking for a Staff Fullstack Engineer to build Data APIs, custom visualizations, and AI products for the hospitality industry. Key ResponsibilitiesBuild and ship full-stack features from
Applications Engineering, Staff Engineer - SPDM
SynopsysUnited StatesApplications Engineering, Staff Engineer - SPDMSynopsys is the leader in engineering solutions from silicon to systems, enabling customers to rapidly innovate AI-powered products. We deliver industry-
Staff Applications Engineer - Engine Systems
GeneracUnited StatesStaff Applications Engineer - Engine SystemsFor more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustaina
Staff Applications Engineer - Engine Systems
Generac Power SystemsUnited StatesWe believe power is a promise - a shared commitment to be there for others when it matters most.For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen busine
Staff Engineer, Machine Learning
SynthesiaUnited StatesAbout the roleYou will own multiple features for our new Interactive Agents product, a two-way conversational video platform to practice conversations and improve team performance, unlocking scalable
Senior/Staff Design Engineer
AlphaSense, Inc.United StatesAbout AlphaSense:The world's most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers ins
Staff Engineer, Design Verification
Samsung SemiconductorUnited StatesPlease Note: To provide the best candidate experience amidst our high application volumes, each candidate is limited to 10 applications across all open jobs within a 6-month period. Advancing the Worl
Backend Staff Software Engineer
VisaUnited StatesAbout Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territ
Staff SW Engineer - Frontend
VisaUnited StatesAbout Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territ
Senior Staff Data Engineer
Virtual Vocations IncUnited StatesTo elevate the systems that power trusted decision-making, the full-time Senior Staff Data Engineer will define platform standards, lead complex cross-domain initiatives, and shape the future of analy
Staff Machine Learning Engineer
PrizePicksUnited StatesAt PrizePicks, we are the fastest-growing sports company in North America, as recognized by Inc. 5000. As the leading platform for Daily Fantasy Sports, we cover a diverse range of sports leagues, inc
Staff Machine Learning Engineer
HeadspaceUnited StatesAbout theStaff Machine Learning Engineerat Headspace:The AI & Machine Learning group at Headspace is a dynamic and innovative group whose mission is to improve the experiences of our members and clini
Staff Engineer, Agentic Backend
Sema4United StatesThe OpportunityAt Sema4.ai, we're building an Enterprise AI Agent platform that fundamentally changes how knowledge work gets done—by enabling people and AI agents to collaborate in durable, trustwort
Systems Engineer (Sr. Member Engineering Staff)
L3Harris TechnologiesCamdenL3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest fo
Staff Machine Learning Engineer, AI
SentryUnited StatesStaff Machine Learning EngineerSoftware runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time fir
Staff Software Engineer - Back End
Capital One UKLondonWhite Collar Factory (95009), United Kingdom, London, LondonStaff Software Engineer - Back EndAbout this roleDo you love shaping the technical landscape and driving innovation across the organisation?
Staff Machine Learning Engineer (Remote)
Home DepotUnited StatesPosition Purpose:The Staff Software Engineer is responsible for leading a team of engineers building and designing a product that our customers and associates love. As a Staff Software Engineer, you w
Staff Verification Design Engineer, DRAM
MicronUnited StatesOur vision is to transform how the world uses information to enrich life forall . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of i
Staff Backend (Python) Engineer, AI Engineering:Duo Chat
GitLabUnited StatesGitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, an
About
Tools for Humanity (TFH) designs and builds technology behind World. World is building a real human network designed to accelerate people in the age of AI. As bots and autonomous agents reshape the internet, people, institutions, and applications need a trusted way to confirm who is a real human while preserving privacy. The TFH and World tech stacks make this possible: the Orb verifies real, unique people, World ID proves it privately, and World App puts these capabilities, and more, in people's hands. Together, they add a human layer to an AI-driven internet.
World is already running at a global scale. More than 17 million people across 160 countries have verified with World ID, and more new Orb verifications take place each week. World App is already among the most used wallets globally. Developers are integrating World ID to build safer online experiences and create spaces where real people can participate, earn, and be recognized in ways AI simply can't replicate.
Founded in 2019, TFH has more than 400 people across hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI, Tesla, SpaceX, Apple, Google, Stripe, Meta, Coinbase, Palantir and MIT Media Lab. We're backed by leading investors, including a16z, Khosla Ventures, Bain Capital Crypto, Blockchain Capital, Variant, Tiger Global, and Coinbase Ventures, as well as prominent operators and founders across fintech and AI.
TFH and World have been featured on the cover of TIME Magazine, highlighted in Fast Company's Next 5 in Fintech, and explored in a Bloomberg deep dive. The New York Times, Bankless and TechCrunch have all recognized our collective progress in identity, cryptography, AI, and global-scale hardware deployment. Our leadership is also named to the Time AI 100. Learn more about the newest product launches from our Liftoff event. About the Team
The Security team at Tools for Humanity operates at a level far beyond a regular company. Our objective is not just to secure an organization, but to build the trusted, foundational infrastructure for the world's largest identity and financial network. We are a team of over 15 seasoned engineers who are central to the success of the World protocol. We tackle a unique and complex threat landscape that spans state-of-the-art hardware security for the Orb, advanced cryptography including new zero-knowledge proofs, and the security of a global, distributed cloud and mobile ecosystem. Our work is critical to enabling the protocol to scale to billions of users while upholding an unwavering commitment to fail-safe security and privacy.
About the Opportunity
As a Mobile Security Engineer, you will own the security and integrity of the mobile applications at the core of the World protocol World App on Android and iOS used by millions of people worldwide to verify their identity, authenticate with biometrics, and manage digital assets. This is not a consultative role; you will be a hands-on builder, designing and implementing the systems that ensure our mobile clients are trustworthy, tamper-resistant, and resistant to adversarial attack at global scale.
Our mobile threat model is uniquely challenging: the World App must perform privacy-preserving biometric operations (iris and face authentication) on-device, hold cryptographic keys for identity proofs, and interact with hardware attestation systems all while operating in environments where adversaries range from casual fraud to nation-state-level identity fabrication at scale. You will be the expert who ensures this stack cannot be subverted.
You will: Design, build, and operate mobile device attestation and integrity verification systems across Android and iOS including hardware-backed key attestation (Android KeyStore TEE/StrongBox, Apple App Attest/Secure Enclave), ensuring requests originate from genuine, untampered devices running unmodified app code. Engineer anti-tampering, anti-hooking, and runtime integrity protections for the World App, making the app resilient against reverse engineering, instrumentation frameworks (Frida, Xposed), and repackaging attacks. Own the mobile hardening strategy end-to-end: certificate pinning, secure storage, obfuscation, jailbreak/root detection, debugger detection, and screen capture protection deciding which protections to build in-house and which to source from vendors. Design cryptographic protocols for on-device biometric authentication (Face Auth, selfie verification) that are resistant to replay, relay, and deepfake injection attacks, ensuring the biometric pipeline cannot be manipulated even on a compromised device. Build and maintain the server-side attestation verification infrastructure (our Attestation Gateway) that validates Play Integrity tokens, hardware attestation certificate chains, and Apple App Attest assertions, making trust decisions that gate access to sensitive operations. Lead threat modeling for mobile-specific attack surfaces: biometric bypass, key extraction, device cloning, session hijacking, overlay attacks, accessibility abuse, and automated bot farms using real devices. Embed security into the mobile development lifecycle performing deep code reviews of Android (Kotlin) and iOS (Swift) code, building automated security checks into CI/CD, and establishing secure coding standards for mobile teams. Mature our vulnerability management process for mobile, from triaging mobile-specific bug bounty submissions to driving remediation with mobile engineering teams. Evaluate, integrate, and manage mobile security tooling and vendor relationships (RASP, SAST for mobile, binary analysis tools). About You
You are a deeply technical mobile security engineer who has spent years protecting high-value mobile applications against sophisticated adversaries. You have a builder's mindset; you don't just find problems, you ship solutions. You've been responsible for the security of mobile apps where the stakes are real: payments, identity, or financial services at scale.
Required: 8+ years of hands-on experience in mobile security engineering, with deep expertise in at least one of Android or iOS (strong in both is ideal). Proven experience designing and operating mobile device attestation systems you understand Android Hardware Key Attestation (KeyMint, TEE, StrongBox, attestation certificate chains, Google root CA verification), Google Play Integrity API (Classic and Standard modes), and/or Apple App Attest (DeviceCheck, attestation/assertion flows, Secure Enclave) at a systems level, not just as an API consumer. Strong background in mobile application hardening: you have implemented or evaluated anti-tampering, anti-hooking, root/jailbreak detection, debugger detection, certificate pinning, and runtime integrity protection in production apps. Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx, apktool), analyze iOS binaries, use Frida/Objection for dynamic analysis, and think like an attacker to validate your defenses. Proficiency in Kotlin/Java (Android) and/or Swift (iOS) for security-focused code review and building security libraries. Experience securing on-device cryptographic operations: key generation, secure storage (Android KeyStore, iOS Keychain), and protocols that depend on hardware-backed keys. Strong understanding of mobile-specific attack vectors: overlay attacks, accessibility service abuse, screen recording, deepfake injection into camera pipelines, biometric bypass, and app cloning. Nice to have:
Experience building or operating server-side attestation verification services (decrypting Play Integrity JWE/JWS tokens, validating X.509 attestation certificate chains, managing Apple App Attest key lifecycle in a backend). Experience with RASP vendor evaluation and integration (Zimperium, Guardsquare/DexGuard, Promon, Appdome). Background in payment security or PCI-compliant mobile applications (SoftPOS, Tap-to-Pay, EMV). Familiarity with privacy-preserving systems: zero-knowledge proofs, on-device biometric processing, or differential privacy. Experience scaling a Secure SDLC or security champions program for mobile engineering teams. Contributions to mobile security research, conference talks, or open-source security tooling. Rust, Go, or Python experience for backend security tooling and infrastructure. What we offer
The reasonably estimated salary for this role at Tools for Humanity ranges from $251,000 - $325,000 plus a competitive long-term incentive package. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Tools for Humanity offers a wide range of best-in-class, comprehensive, and inclusive employee benefits for this role, including healthcare, dental, vision, 401(k) plan and match, life insurance, flexible time off, commuter benefits, professional development stipend, and much more.
By submitting your application, you consent to the processing and internal sharing of your CV within the company, in compliance with the GDPR.
If you don't think you meet all of the criteria but are still interested in the job, please apply. Nobody checks every box, and we're looking for someone excited to join the team.
Languages
- English
This job comes from a TieTalent partner platform. Click "Apply Now" to submit your application directly on their site.