Ditto

Product Security Engineer — Mobile RASP

Ditto Spain

Computer and Network Security · 51-200 employees

Yesterday
Remote security Senior (5-10 yrs) Full-time Spain
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will build and maintain production-grade mobile security capabilities, including RASP shields and code-hardening tools for iOS and Android. Additionally, you will design and operate Python backend services to process threat telemetry and support technical pre-sales activities.

What they look for

Mobile Security RASP Python Swift Objective-C Kotlin Java Cryptography AWS CI/CD Docker Reverse Engineering Binary Hardening API Development Security Research Agile

Requirements

The role requires strong hands-on software engineering experience with mobile SDKs, binary hardening, and applied cryptography. You must also be proficient in Python backend development and comfortable using AI-accelerated coding tools in an Agile environment.

Full description

About Ditto

At Ditto, we're redefining digital trust. Our unified identity platform helps banks, financial institutions, governments and other regulated organisations verify identities, prevent fraud and deliver secure digital experiences through identity verification, authentication, passwordless access and mobile threat defence.

We're a global team with a startup mindset, led by CEO Gonzalo Alonso, on a mission to make digital trust simple, secure and accessible.

The Role

Ditto Protect is our mobile application security (RASP) platform — the runtime layer that keeps high-assurance apps safe while they run, on devices we do not control. We're hiring a Product Security Engineer to own the runtime defences that keep every Ditto Protect app trustworthy. This is a hands-on engineering role first and foremost: you'll write production code, contribute to the delivery pipeline, and ship the features that close gaps in Ditto Protect, working at high velocity with AI as your primary development accelerator.

You'll build our in-house shields and hardening tooling on top of a licensed RASP core — defeating rooting and jailbreaking, hooking and instrumentation, emulators, tampering and repackaging, malware, and network interception including MITM, SSL-pinning bypass, and malicious VPN/proxy. You'll own the applied cryptography beneath secure local storage and app/device attestation, as well as the iOS symbol-obfuscation and binary-hardening tooling that closes native reverse-engineering gaps across Swift, C, C++ and Objective-C.

The product spans both sides of the wire. You'll also build and operate Ditto Protect's Python backend — the services and APIs that ingest threat telemetry from protected apps, drive the operator and companion console, manage configuration and policy, and forward events to SIEM — turning on-device signals into operational visibility. This is a role for an engineer comfortable moving between the mobile client and the server.

Because you build the product, you'll also be well placed to evaluate competing solutions and support the Sales & Solutioning team as a technical pre-sales engineer. These responsibilities matter, but the primary focus is building and delivering software quickly and to a high standard. This is a product, not a project. You'll own capabilities across their lifetime, including ongoing security research, vendor upgrades, and maintenance, to a standard that stands up to regulators across regions and countries. This role directly to the Head of Ditto Protect Engineering. Partners closely with DevOps, QA, and the Sales & Solutioning team.

Where You'll Make an Impact

In this role, you'll:

  • Build and ship production-grade mobile security capabilities that close gaps in Ditto Protect's runtime detection and response coverage.
  • Develop in-house security shields on top of a licensed RASP core, integrating and extending third-party and native SDKs through callback and event APIs.
  • Work around vendor limitations, track defects, and keep the product current through annual platform upgrades.
  • Build code-hardening capabilities including iOS symbol obfuscation and binary hardening across Swift, C, C++ and Objective-C.
  • Own secure local storage, app/device attestation, and the applied cryptography that underpins them.
  • Design, build and operate the Python backend services and APIs that turn on-device threat signals into operational visibility.
  • Work alongside DevOps, who own the delivery pipeline, providing the engineering input required to keep builds, tests, signing and releases reliable.
  • Write tests, collaborate with QA, and close defects directly in the code, owning quality end-to-end.
  • Evaluate competing mobile security solutions and feed technical findings into the product roadmap.
  • Support the Sales & Solutioning team with technical demos, POCs and credible answers for prospects and their security teams.
  • Translate product gaps and requirements into epics and user stories in Jira that the team can build.
  • Use AI coding tools to design, prototype, build, test and document at high speed.
  • Own the capabilities you build throughout their lifecycle, including security research, vendor upgrades and ongoing maintenance.

What You'll Build

  • RASP Coverage - Write production code that closes Ditto Protect's detection and response gaps.
  • In-House Shields on a Licensed Core - Integrate and extend third-party and native SDKs, working with their callback/event APIs, tracking defects, working around vendor limitations, and keeping pace with annual platform upgrades.
  • Code-Hardening Tooling - Build iOS symbol-obfuscation capabilities targeting parity with tools such as iXGuard, together with binary hardening across Swift, C, C++ and Objective-C, closing native naming and reverse-engineering gaps.
  • Secure Storage and Attestation - Build secure data-at-rest encryption and local storage capabilities, together with app/device attestation and the applied cryptography that underpins them.
  • Backend Services - Design, build and operate the Python server-side of Ditto Protect.
  • CI/CD and Delivery - Work alongside DevOps, who own the pipeline, providing the engineering input that keeps builds, tests, signing and releases reliable. Take features from branch to production.
  • AI-Native Development - Use AI coding tools as a standard part of how you work — to design, prototype, build, test and document at speed. AI is a primary development accelerator, not an occasional aid.
  • Quality- Write tests, collaborate with QA, and close defects directly in the code. Own quality end-to-end.
  • Competitive Evaluation - Run hands-on technical evaluations of solutions such as Promon, Bureau, Appdome, Guardsquare, Zimperium and Build38, and feed the findings into the product roadmap.
  • Pre-Sales Support - Back the Sales & Solutioning team with demos, POCs and credible technical answers for prospects and their security teams.
  • Backlog - Translate gaps and requirements into epics and user stories in Jira that the team then builds.

What You'll Work With

On the mobile-security side, you'll work across the RASP and broader mobile threat-and-defence landscape, including:

  • OWASP MASVS / MASTG, Frida, Xposed and Magisk, Emulators,  iOS toolchains — Swift / Objective-C, Android toolchains — Kotlin / Java, Symbol obfuscation and binary hardening, Secure local storage, App/device attestation, Applied cryptography

On the platform and delivery side, you'll work with:

  • Python as the primary backend language, Flask, REST and event-driven APIs, AWS as the primary cloud, Docker, Git, CI/CD pipelines, including GitHub Actions, GitLab CI or Jenkins, Dashboards and consoles, SIEM/log forwarding, Observability, AI coding tools such as Claude Code, Copilot and Cursor

What We're Looking For

You are comfortable moving between mobile security, SDKs, backend services and delivery infrastructure, and you take ownership of the quality and lifecycle of what you build. You'll bring:

  • Strong, current, hands-on software engineering — you code daily and ship to production.
  • Mobile SDK development — experience with iOS (Swift/Objective-C) and/or Android (Kotlin/Java), ideally with a security or SDK focus.
  • SDK integration and extension — experience integrating and extending third-party or native SDKs via callback/event APIs, including working around vendor limitations.
  • Code hardening — applied obfuscation and binary hardening, including symbol obfuscation and anti-reverse-engineering techniques across native mobile toolchains.
  • Applied cryptography fundamentals — practical understanding of secure data-at-rest storage and attestation.
  • Backend development in Python — experience designing and building production Python services and APIs, particularly Flask, with sound testing, packaging and API-design discipline.
  • AI-accelerated development — proven experience building and shipping quickly with AI coding tools such as Claude Code, Copilot or Cursor.
  • CI/CD collaboration — practical experience with delivery pipelines such as GitHub Actions, GitLab CI, Jenkins or similar, and the ability to provide the engineering input those pipelines depend on.
  • Cloud — solid AWS experience; other cloud providers are a plus.
  • Backend and platform engineering — experience with dashboards/consoles, SIEM/log forwarding and observability, together with strong Git and Docker fundamentals.
  • RASP and MTD — hands-on knowledge of RASP and the mobile threat-and-defence landscape in which it operates.
  • Standards — familiarity with OWASP MASVS / MASTG and the mobile attacker toolkit, including Frida, Xposed, Magisk and emulators.
  • Evaluation and pre-sales — ability to evaluate competing security products and support pre-sales when needed.
  • Quality and Agile delivery — experience collaborating with QA, owning quality in your own code, and writing epics and user stories in Jira within an Agile team.
  • Language — written and spoken English to a professional standard.

Strongly Preferred

It would be great if you also have:

  • Fraud management — interest or experience extending mobile security beyond RASP/MTD into fraud — moving from “is the device safe?” to “should we trust this transaction?” This includes on-device behavioural signals such as typing rhythm, navigation and gesture patterns, together with a local pre-scoring signal that fires before any server round-trip.
  • Server-side fraud engine experience — transaction intelligence including velocity, amount spikes, new-payee and cross-channel history; device/identity baselining; and ML-based risk scoring, or close collaboration with data/ML teams, for use cases such as impossible travel, IP reputation, mule-account and anomaly detection.
  • Real-time client↔server scoring — experience defining the signal/risk-score contract between on-device and server layers and orchestrating both scores, for example via REL-ID-SDK, into an adaptive approve / step-up / block / alert response.
  • Anti-fraud signals — familiarity with behavioural biometrics, transaction risk, device intelligence and risk-adaptive (step-up) authentication, and how these complement rather than replace RASP/MTD. This is also useful when evaluating solutions such as Bureau.
  • Live demos and POC environments — experience creating and delivering credible technical demonstrations and proof-of-concept environments.
  • EU regulatory awareness — familiarity with PSD2 SCA, DORA, GDPR, PCI-DSS, and eIDAS 2.0 / EUDI Wallet.
  • Domain background — experience in a security vendor or fintech / banking environment.

Similar roles