Security SDK Engineer
Job description
About the role
Security SDK Engineer Opportunity at AppsFlyer
AppsFlyer builds technology at massive scale, powering measurement, analytics, and fraud prevention across billions of mobile events every day. The organization seeks engineers for the Security SDK Team, a group dedicated to protecting the integrity and authenticity of mobile SDKs across Android and iOS. This team focuses on securing SDK communication, enhancing SDK resilience, and developing trusted solutions that operate on billions of devices globally. The role suits engineers passionate about mobile development and interested in security, low-level systems, and reverse engineering. Work involves Android and iOS platforms, native components written in C/C++, and cloud-based infrastructure. The environment emphasizes continuous learning, technical growth, and hands-on research.
This position is based in Kyiv. The engagement centers on mobile SDK security for Android and iOS. The compensation offered is 35000 USD per year.
What you will do
You will design and ship protection for mobile SDKs owned by you. You analyze complex mobile runtime conditions to define security boundaries for AppsFlyer SDK components. You implement defensive mechanisms that operate reliably on hostile devices without disrupting legitimate usage patterns. You architect hardened Android defenses while advancing iOS resilience layers through iterative experimentation. You instrument tamper detection and runtime controls that actively monitor the integrity of mobile components. You coordinate with product managers and backend engineers on trust boundaries and data protection strategies. You investigate obscure mobile threats through debugging sessions and controlled experiments in sandbox environments. You explore instruction flows via native tooling and reverse engineering practices to uncover potential vulnerabilities. You synchronize delivery rhythms inside mobile, backend, and product Agile teams to align security milestones. You validate build toolchains and deployment pipelines for security correctness and compliance with internal standards.
Requirements
You must hold a B.Sc. in Computer Science or comparable real-world background. One to two years of software development experience is required, with a leaning toward Android platforms. Candidates should have built mobile applications or SDKs that reach production devices. A strong understanding of Android internals, application structure, and binary interfaces is necessary. Sharp debugging instincts and systematic problem-solving skills are mandatory. Curiosity for security concepts and low-level system mechanisms must be demonstrated. Clear English communication skills, used with precision and care, are essential. An ownership mindset and the drive to learn while mentoring peers are required. You must be located in Kyiv for this role. You must commit to the engagement model outlined in the official listing. You must adhere to timelines and quality standards expected for security-sensitive work.
Nice to have qualifications
Hands-on work with Kotlin, Java, or Android SDK creation is valued. Familiarity with C/C++ and native mobile development workflows is beneficial. Interest in mobile security, reverse engineering, and runtime internals is encouraged. Comfort with tools such as Frida, Ghidra, or IDA for analysis and exploration tasks is advantageous. Experience using Gradle, CMake, or CI/CD systems in mobile contexts is helpful. Knowledge of AWS or other backend service integration patterns is noted. Exposure to LLVM, Clang, or intricate build toolchain configurations is considered a bonus.
Skills and tools
The role requires proficiency with Android, iOS, C/C++, Kotlin, Java, Gradle, CMake, Frida, Ghidra, IDA, and AWS. You should feel comfortable switching context between high-level application logic and low-level native codebases. You must be able to read and interpret disassembled code to support debugging and threat analysis. You should understand networking protocols and data serialization formats used in mobile communication. You are expected to write clean, testable code that integrates with existing security controls. You should be able to document technical decisions to support knowledge sharing across the team.
What you'll do
AppsFlyer unifies measurement, deep linking, data collaboration, and AI across mobile, web, CTV, console, and other environments. The platform helps teams make more informed decisions, optimize each channel, and clearly demonstrate impact.
You work on instrumentation, event streaming, and modeling that support global customers. The role involves close collaboration with product, engineering, and data teams to refine tracking, improve data quality, and strengthen the product.