Senior Security Engineer, Mobile Detection

Tools for HumanitySan Francisco, CA
2d

About The Position

You will work with our App engineering teams to address app and Mini App risks. You will also work with the Device and Device Security teams on securing the Android operating system of the next-generation Orb device. Some travel (10-20% maximum) is expected, especially to our office in Munich, Germany where most of the Orb hardware and software teams are located. 5-8 years experience in offensive and defensive Android security. This is a “purple team” role where you challenge the security of the apps and devices, advise and assist Engineering on implementing controls, develop Detection capabilities for mobile devices, and (when on call) drive incident response for any security incidents (not just mobile). We are building an entirely new automated detection and response system. Right now it needs to protect the 17 million+ verified World ID users processing millions of identity and financial transactions a day, and it will need to rapidly scale to protect billions of users using trusted and untrusted hardware, much of which we will not own. We will publish audit events to the public blockchain for the highest possible transparency and trust of the World ID system, and build decentralized detection & response using those logs. We need to do all this while maintaining the strongest possible privacy protections. This team works closely with the teams building the core technologies, because D&R and Privacy are foundational elements of the World Network. We have a variety of mobile resources that need security controls and detection: apps for users to signup at an Orb and manage their currency wallets, apps for Orb operators to manage their devices and team, and a future Android-based device as a successor to the Orb. Our user app also contains a “Mini App” ecosystem that includes 3rd party developers, and is intimately tied to both the digital identity (WorldID) and blockchain transactions.

Requirements

  • 5-8 years experience in offensive and defensive Android security.
  • Sound knowledge of Security fundamentals.
  • Deep knowledge of mobile attacks and defenses.
  • Some experience developing Android apps (Kotlin).
  • Analyst-level Python coding (building analysis pipelines in an existing environment).
  • Willing to participate in an on call rotation and learn incident handling (or relevant experience)
  • Strong critical thinking, communication, and leadership skills
  • Comfort working cross-functionally with peer teams to negotiate and reach consensus solutions that improve security and privacy
  • Energized by working in a fast-paced, collaborative environment

Nice To Haves

  • Engineer-level coding in Kotlin (implementing security frameworks)
  • Experience hacking or developing iOS apps (Swift)
  • Reported CVEs (especially for mobile apps and Android)
  • Collected Bug Bounty awards
  • Participated in / won CTF (Capture The Flag) competitions

Benefits

  • healthcare
  • dental
  • vision
  • 401(k) plan and match
  • life insurance
  • flexible time off
  • commuter benefits
  • professional development stipend
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service