🇪🇸 Spain · 15h ago
Product Security Engineer — Mobile RASP
Ditto
LinkedInseniorEnglish-friendly
About DittoAt Ditto, we're redefining digital trust. Our unified identity platform helps banks, financial institutions, governments and other regulated organisations verify identities, prevent fraud and deliver secure digital experiences through identity verification, authentication, passwordless access and mobile threat defence.We're a global team with a startup mindset, led by CEO Gonzalo Alonso, on a mission to make digital trust simple, secure and accessible.The RoleDitto Protect is our mobile application security (RASP) platform — the runtime layer that keeps high-assurance apps safe while they run, on devices we do not control. We're hiring a Product Security Engineer to own the runtime defences that keep every Ditto Protect app trustworthy. This is a hands-on engineering role first and foremost: you'll write production code, contribute to the delivery pipeline, and ship the features that close gaps in Ditto Protect, working at high velocity with AI as your primary development accelerator.You'll build our in-house shields and hardening tooling on top of a licensed RASP core — defeating rooting and jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception including MITM, SSL-pinning bypass, and malicious VPN/proxy. You'll own the applied cryptography beneath secure local storage and app/device attestation, as well as the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.The product spans both sides of the wire. You'll also build and operate Ditto Protect's Python backend — the services and APIs that ingest threat telemetry from protected apps, drive the operator and companion console, manage configuration and policy, and forward events to SIEM — turning on-device signals into operational visibility. This is a role for an engineer comfortable moving between the mobile client and the server.Because you build the product, you'll also be well placed to evaluate competing solutions and support the Sales & Solutioning team as a technical pre-sales engineer. These responsibilities matter, but the primary focus is building and delivering software quickly and to a high standard. This is a product, not a project. You'll own capabilities across their lifetime, including ongoing security research, vendor upgrades, and maintenance, to a standard that stands up to regulators across regions and countries. This role directly to the Head of Ditto Protect Engineering. Partners closely with DevOps, QA, and the Sales & Solutioning team.Where You'll Make an ImpactIn This Role, You'llBuild and ship production-grade mobile security capabilities that close gaps in Ditto Protect's runtime detection and response coverage.Develop in-house security shields on top of a licensed RASP core, integrating and extending third-party and native SDKs through callback and event APIs.Work around vendor limitations, track defects, and keep the product current through annual platform upgrades.Build code-hardening capabilities including iOS symbol obfuscation and binary hardening across Swift, C, C++ and Objective-C.Own secure local storage, app/device attestation, and the applied cryptography that underpins them.Design, build and operate the Python backend services and APIs that turn on-device threat signals into operational visibility.Work alongside DevOps, who own the delivery pipeline, providing the engineering input required to keep builds, tests, signing and releases reliable.Write tests, collaborate with QA, and close defects directly in the code, owning quality end-to-end.Evaluate competing mobile security solutions and feed technical findings into the product roadmap.Support the Sales & Solutioning team with technical demos, POCs and credible answers for prospects and their security teams.Translate product gaps and requirements into epics and user stories in Jira that the team can build.Use AI coding tools to design, prototype, build, test and document at high speed.Own the capabilities you build throughout their lifecycle, including security research, vendor upgrades and ongoing maintenance.What You'll BuildRASP Coverage - Write production code that closes Ditto Protect's detection and response gaps.In-House Shields on a Licensed Core - Integrate and extend third-party and native SDKs, working with their callback/event APIs, tracking defects, working around vendor limitations, and keeping pace with annual platform upgrades.Code-Hardening Tooling - Build iOS symbol-obfuscation capabilities targeting parity with tools such as iXGuard, together with binary hardening across Swift, C, C++ and Objective-C, closing native naming and reverse-engineering gaps.Secure Storage and Attestation - Build secure data-at-rest encryption and local storage capabilities, together with app/device attestation and the applied cryptography that underpins them.Backend Services - Design, build and operate the Python server-side of Ditto Protect.CI/CD and Delivery - Work alongside DevOps, who own the pipeline, providing the engineering input that keeps builds, tests, signing and releases reliable. Take features from branch to production.AI-Native Development - Use AI coding tools as a standard part of how you work — to design, prototype, build, test and document at speed. AI is a primary development accelerator, not an occasional aid.Quality- Write tests, collaborate with QA, and close defects directly in the code. Own quality end-to-end.Competitive Evaluation - Run hands-on technical evaluations of solutions such as Promon, Bureau, Appdome, Guardsquare, Zimperium and Build38, and feed the findings into the product roadmap.Pre-Sales Support - Back the Sales & Solutioning team with demos, POCs and credible technical answers for prospects and their security teams.Backlog - Translate gaps and requirements into epics and user stories in Jira that the team then builds.What You'll Work WithOn the mobile-security side, you'll work across the RASP and broader mobile threat-and-defence landscape, including:OWASP MASVS / MASTG, Frida, Xposed and Magisk, Emulators, iOS toolchains — Swift / Objective-C, Android toolchains — Kotlin / Java, Symbol obfuscation and binary hardening, Secure local storage, App/device attestation, Applied cryptographyOn The Platform And Delivery Side, You'll Work WithPython as the primary backend language, Flask, REST and event-driven APIs, AWS as the primary cloud, Docker, Git, CI/CD pipelines, including GitHub Actions, GitLab CI or Jenkins, Dashboards and consoles, SIEM/log forwarding, Observability, AI coding tools such as Claude Code, Copilot and CursorWhat We're Looking ForYou are comfortable moving between mobile security, SDKs, backend services and delivery infrastructure, and you take ownership of the quality and lifecycle of what you build. You'll bring:Strong, current, hands-on software engineering — you code daily and ship to production.Mobile SDK development — experience with iOS (Swift/Objective-C) and/or Android (Kotlin/Java), ideally with a security or SDK focus.SDK integration and extension — experience integrating and extending third-party or native SDKs via callback/event APIs, including working around vendor limitations.Code hardening — applied obfuscation and binary hardening, including symbol obfuscation and anti-reverse-engineering techniques across native mobile toolchains.Applied cryptography fundamentals — practical understanding of secure data-at-rest storage and attestation.Backend development in Python — experience designing and building production Python services and APIs, particularly Flask, with sound testing, packaging and API-design discipline.AI-accelerated development — proven experience building and shipping quickly with AI coding tools such as Claude Code, Copilot or Cursor.CI/CD collaboration — practical experience with delivery pipelines such as GitHub Actions, GitLab CI, Jenkins or similar, and the ability to prSourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.