Staff Mobile & Product Security Engineer
MrBeast - San Francisco, CA
Hiring: Staff Mobile & Product Security Engineer Company: MrBeast Location: San Francisco, CA Job Posted Time: 2026-09-16 11:48:48 Target Skills & Keywords : Android, Embedded Systems, Kotlin, Pen Testing, React Native, SOC 2, Swift, iOS About the job Required Skills: •, you will be the foundational security hire on the Security team, embedded directly with product and mobile squads to ship features that are secure by design rather than secured after the fact. •This is a hands-on, build-with-the-team role. You'll own mobile and product application security, run the pen testing program (with deep focus on mobile attack surface), and architect the controls that meet partner security requirements so the business can close deals and ship with confidence. •IOS and Android app security — secure storage, certificate/key pinning, jailbreak/root and tamper detection, secure IPC, mobile authN/authZ flows, and hardening of the mobile SDK and build/release pipeline. •Threat modeling, secure-by-default patterns, code review, and developer-facing tooling across the membership app, creator marketplace, and platform services. •A pen testing program you own end-to-end — internal red-team exercises (including mobile-specific testing: static/dynamic analysis, reverse engineering, API abuse), coordinated external engagements, and continuous validation against real attacker behavior. •The control framework that lets us meet partner security requirements — and the architecture decisions that keep our mobile and product surfaces ready for the next partner, not scrambling for them. •Embed directly with mobile and product squads — membership app (iOS/Android), marketplace, data & identity — to threat-model, review, and harden features before they ship. •Own the mobile application security program end-to-end: secure mobile SDLC, mobile-specific code review (Swift/Kotlin/React Native, as applicable), dependency and supply-chain controls, and developer-facing security tooling. Qualifications: •You've been the security engineer on a product or mobile team, not just a reviewer at the gate. You write code, file PRs, and ship fixes yourself when it's the fastest path. •You've secured native iOS and/or Android applications at consumer scale — you understand mobile-specific threats (reverse engineering, tampering, insecure storage, insecure IPC, mobile API abuse) and how to design against them. •You've run or heavily contributed to an application security program inside a consumer product used by millions — you know the real tradeoffs between coverage, velocity, and risk. •You can pen test mobile and web applications, not just read pen test reports. You've found real bugs in real systems — including on-device and API-level mobile vulnerabilities — and shepherded them through to fix. •You've architected against partner security frameworks (or equivalents — SOC 2, PCI, vendor security reviews, mobile app store security requirements) and know how to translate requirements into real controls without theater. •You aren't just curious about AI; you are burning through tokens, using coding agents daily, and thinking about how AI changes both how we build and what we have to defend — including on-device and mobile AI features. •You have the startup experience to build from zero with a nimble team, plus the big-tech exposure to know what breaks when a product hits massive scale. •You thrive in ambiguity and prefer shipping controls over writing policy. You'd rather land a fix than run a meeting. Compensation: •$170,000 - $250,000 / year •Competitive benefits and rewards package •The target total compensation ranges from $170,000 to $250,000, an employee equity plan grant, bonus, plus comprehensive benefits Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!