# Senior/Staff Mobile Security Engineer at Worldcoin

- Company: Worldcoin
- What the company does: World ensures that every human benefits from the age of AI. Join millions of real humans in 160 countries with World ID and World App. Backed by a16z.
- Company website: https://world.org
- Type: Startups
- Level: Senior
- Location: San Francisco
- Work setup: On-site
- Pay: $251K to $325K base salary per year (USD)
- Posted: 2026-04-15
- Apply by: 2026-10-08
- Apply: https://jobs.ashbyhq.com/Tools%20for%20Humanity/11e5ab54-e01c-4196-8194-646155c7235f
- Page: https://www.1752.vc/careers/jobs/worldcoin-senior-staff-mobile-security-engineer/

## About the role

As a Mobile Security Engineer, you will own the security and integrity of the mobile applications at the core of the World protocol World App on Android and iOS used by millions of people worldwide to verify their identity, authenticate with biometrics, and manage digital assets. This is not a consultative role; you will be a hands-on builder, designing and implementing the systems that ensure our mobile clients are trustworthy, tamper-resistant, and resistant to adversarial attack at global scale.

## What they're looking for

- 8+ years of hands-on experience in mobile security engineering, with deep expertise in at least one of Android or iOS (strong in both is ideal)
- Strong background in mobile application hardening: you have implemented or evaluated anti-tampering, anti-hooking, root/jailbreak detection, debugger detection, certificate pinning, and runtime integrity protection in production apps
- Experience with mobile reverse engineering and offensive security: you can decompile APKs (jadx, apktool), analyze iOS binaries, use Frida/Objection for dynamic analysis, and think like an attacker to validate your defenses
- Proficiency in Kotlin/Java (Android) and/or Swift (iOS) for security-focused code review and building security libraries
- Experience securing on-device cryptographic operations: key generation, secure storage (Android KeyStore, iOS Keychain), and protocols that depend on hardware-backed keys
- Strong understanding of mobile-specific attack vectors: overlay attacks, accessibility service abuse, screen recording, deepfake injection into camera pipelines, biometric bypass, and app cloning

Tags: Engineering
