1

Mobile Security Researcher Jobs (NOW HIRING)

Senior/Staff Mobile Security Engineer

San Francisco, CA · On-site

$134K - $185K/yr

... research, conference talks, or open-source security tooling. • Rust, Go, or Python experience for backend security tooling and infrastructure. Company : World connects users through a privacy ...

We need a hands-on senior Mobile Application Security Engineer with engineering experience to research, craft, and implement capabilities and defenses to secure and protect eBay's critical Mobile ...

MTS 2 Mobile Security Engineer

Austin, TX · On-site

$136K - $228K/yr

We need a hands-on senior Mobile Application Security Engineer with engineering experience to research, craft, and implement capabilities and defenses to secure and protect eBay's critical Mobile ...

next page

Showing results 1-20

Mobile Security Researcher information

See salary details

$30K

$113.1K

$164.5K

How much do mobile security researcher jobs pay per year?

As of Jun 6, 2026, the average yearly pay for mobile security researcher in the United States is $113,102.00, according to ZipRecruiter salary data. Most workers in this role earn between $67,000.00 and $154,000.00 per year, depending on experience, location, and employer.

What are the most common challenges faced by Mobile Security Researchers, and how can they overcome them?

Mobile Security Researchers frequently face the challenge of keeping up with rapidly evolving mobile platforms, proprietary security mechanisms, and increasingly sophisticated attack techniques. They must constantly update their knowledge and adapt to new tools as both Android and iOS release frequent updates that can affect security research methodologies. Collaborating closely with development, QA, and product teams is common, ensuring that discovered vulnerabilities are addressed efficiently. Overcoming these challenges typically involves continuous learning, attending industry conferences, participating in security communities, and maintaining a strong foundational understanding of mobile technologies.

What are the key skills and qualifications needed to thrive in the Mobile Security Researcher position, and why are they important?

To thrive as a Mobile Security Researcher, you need expertise in mobile operating systems (Android and iOS), understanding of security vulnerabilities, programming skills, and often a degree in computer science or cybersecurity. Experience with tools such as reverse engineering frameworks, static and dynamic analysis tools, and certifications like OSCP or GIAC are highly valued. Strong analytical thinking, attention to detail, and effective communication allow individuals to uncover threats and share findings with both technical and non-technical teams. These skills are crucial for proactively identifying and mitigating security risks in an evolving mobile landscape.

What is a Mobile Security Researcher job?

A Mobile Security Researcher is responsible for analyzing and identifying security vulnerabilities in mobile applications, operating systems, and networks. They conduct penetration testing, reverse engineering, and forensic analysis to uncover potential threats. Their role also involves developing security tools, creating reports on findings, and collaborating with developers to enhance mobile security. These professionals help protect users from threats such as malware, data breaches, and unauthorized access. Strong knowledge of mobile platforms like Android and iOS, cryptographic protocols, and exploit techniques is crucial for this role.

More about Mobile Security Researcher jobs
What cities are hiring for Mobile Security Researcher jobs? Cities with the most Mobile Security Researcher job openings:
What are the most commonly searched types of Security Researcher jobs? The most popular types of Security Researcher jobs are:
What states have the most Mobile Security Researcher jobs? States with the most job openings for Mobile Security Researcher jobs include:
What job categories do people searching Mobile Security Researcher jobs look for? The top searched job categories for Mobile Security Researcher jobs are:
Infographic showing various Mobile Security Researcher job openings in the United States as of May 2026, with employment types broken down into 100% Full Time. Highlights an 87% In-person, and 13% Remote job distribution, with an average salary of $113,102 per year, or $54.4 per hour.
Senior/Staff Mobile Security Engineer

Senior/Staff Mobile Security Engineer

World

San Francisco, CA • On-site

$134K - $185K/yr

Full-time

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Job Summary:
World is building a human network designed to accelerate people in the age of AI, focusing on identity verification and privacy. As a Mobile Security Engineer, you will ensure the security and integrity of mobile applications used by millions for identity verification and asset management, tackling complex threats and building robust security systems.
Responsibilities:
• Design, build, and operate mobile device attestation and integrity verification systems across Android and iOS including hardware-backed key attestation (Android KeyStore TEE/StrongBox, Apple App Attest/Secure Enclave), ensuring requests originate from genuine, untampered devices running unmodified app code.
• Engineer anti-tampering, anti-hooking, and runtime integrity protections for the World App, making the app resilient against reverse engineering, instrumentation frameworks (Frida, Xposed), and repackaging attacks.
• Own the mobile hardening strategy end-to-end: certificate pinning, secure storage, obfuscation, jailbreak/root detection, debugger detection, and screen capture protection deciding which protections to build in-house and which to source from vendors.
• Design cryptographic protocols for on-device biometric authentication (Face Auth, selfie verification) that are resistant to replay, relay, and deepfake injection attacks, ensuring the biometric pipeline cannot be manipulated even on a compromised device.
• Build and maintain the server-side attestation verification infrastructure (our Attestation Gateway) that validates Play Integrity tokens, hardware attestation certificate chains, and Apple App Attest assertions, making trust decisions that gate access to sensitive operations.
• Lead threat modeling for mobile-specific attack surfaces: biometric bypass, key extraction, device cloning, session hijacking, overlay attacks, accessibility abuse, and automated bot farms using real devices.
• Embed security into the mobile development lifecycle performing deep code reviews of Android (Kotlin) and iOS (Swift) code, building automated security checks into CI/CD, and establishing secure coding standards for mobile teams.
• Mature our vulnerability management process for mobile, from triaging mobile-specific bug bounty submissions to driving remediation with mobile engineering teams.
• Evaluate, integrate, and manage mobile security tooling and vendor relationships (RASP, SAST for mobile, binary analysis tools).
Qualifications:
Required:
• 8+ years of hands-on experience in mobile security engineering, with deep expertise in at least one of Android or iOS (strong in both is ideal).
• Proven experience designing and operating mobile device attestation systems you understand Android Hardware Key Attestation (KeyMint, TEE, StrongBox, attestation certificate chains, Google root CA verification), Google Play Integrity API (Classic and Standard modes), and/or Apple App Attest (DeviceCheck, attestation/assertion flows, Secure Enclave) at a systems level, not just as an API consumer.
• Strong background in mobile application hardening: you have implemented or evaluated anti-tampering, anti-hooking, root/jailbreak detection, debugger detection, certificate pinning, and runtime integrity protection in production apps.
• Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx, apktool), analyze iOS binaries, use Frida/Objection for dynamic analysis, and think like an attacker to validate your defenses.
• Proficiency in Kotlin/Java (Android) and/or Swift (iOS) for security-focused code review and building security libraries.
• Experience securing on-device cryptographic operations: key generation, secure storage (Android KeyStore, iOS Keychain), and protocols that depend on hardware-backed keys.
• Strong understanding of mobile-specific attack vectors: overlay attacks, accessibility service abuse, screen recording, deepfake injection into camera pipelines, biometric bypass, and app cloning.
Preferred:
• Experience building or operating server-side attestation verification services (decrypting Play Integrity JWE/JWS tokens, validating X.509 attestation certificate chains, managing Apple App Attest key lifecycle in a backend).
• Experience with RASP vendor evaluation and integration (Zimperium, Guardsquare/DexGuard, Promon, Appdome).
• Background in payment security or PCI-compliant mobile applications (SoftPOS, Tap-to-Pay, EMV).
• Familiarity with privacy-preserving systems: zero-knowledge proofs, on-device biometric processing, or differential privacy.
• Experience scaling a Secure SDLC or security champions program for mobile engineering teams.
• Contributions to mobile security research, conference talks, or open-source security tooling.
• Rust, Go, or Python experience for backend security tooling and infrastructure.
Company:
World connects users through a privacy-focused network with secure digital asset management. Founded in 2019, the company is headquartered in San Francisco, USA, with a team of 201-500 employees. The company is currently Growth Stage.