Jobs Companies Payjoy Senior Mobile Security Engineer

About this Senior Mobile Security Engineer role at Payjoy

Payjoy · Hybrid · Mexico City, CDMX
About PayJoy
 
PayJoy, a Public Benefit Corporation, is a mission-first credit provider dedicated to helping under-served customers in emerging markets to achieve financial stability and success.  Our patented technology for secured credit provides an on-ramp for new customers to enter the credit system.  Through PayJoy’s point-of-sale financing and card offerings, customers gain access to a modern quality of life.  PayJoy’s credit also allows our customers to seize opportunities as micro-entrepreneurs, and acts as insurance for tough times. Through our cutting-edge machine learning, data science, and anti-fraud AI, we have served over 18 million customers as of 2025 while achieving solid profitability for sustainable growth.
 
This role

The success of PayJoy depends on the strength of its locking technology against various evolving bypass mechanisms. As an experienced Android security analyst and team lead, you will be responsible for both testing and strengthening PayJoy's lock strength directly, and for leading a distributed team of three Lock Product Analysts across Brazil, South Africa, and the Philippines.

We are seeking a highly skilled and tenacious senior analyst with a specialized focus on Android device security. In this critical senior role, you will independently define and lead PayJoy's testing strategy against device lock bypass methods and tools, while also managing and coordinating a distributed team of three Lock Product Analysts across Brazil, South Africa, and the Philippines. Given the problem space — ensuring lock integrity across OS OTA updates, lock technology changes, and evolving in-market bypass tools — you will explore and evaluate your own approaches, propose solutions, and drive them to completion. You will own the vulnerability discovery roadmap, lead the response to what your team finds, and develop the people doing the work.

This position requires 10–25% travel to investigate vulnerabilities and techniques across  several  markets.

Responsibilities

Team Management

  • Lead, mentor, and develop a team of three Lock Product Analysts based in Brazil, South Africa, and the Philippines — setting clear expectations, reviewing their work, and supporting their growth.

  • Coordinate testing coverage across markets, ensuring the team's efforts are prioritized against the highest-risk devices and vulnerabilities globally.

  • Serve as the escalation point for complex or ambiguous findings surfaced by the team, and make the call on severity, prioritization, and next steps.

  • Build team rituals and shared processes (e.g., testing standards, vulnerability documentation, cross-market knowledge sharing) that improve quality and consistency as the team scales.

  • Bypass Testing & Vulnerability Identification

  • Independently design and drive the approach to testing PayJoy's device locking mechanism across a diverse range of Android devices and OS versions following every OTA update.

  • Define and lead comprehensive periodic testing of the lock after every update to PayJoy lock technology, proactively identifying gaps before they become exploits.

  • Research, identify, and evaluate existing and emerging lock-breaking tools, software, hardware techniques, and methodologies (e.g., factory reset exploits, bootloader vulnerabilities, ADB exploits, custom ROM flashing, FRP bypass tools) — proposing which attack vectors to prioritize and why.

  • Test Strategy & Execution

  • Independently design, own, and continuously evolve the test strategy, test cases, and test scenarios for lock security, bypass attempts, and anti-tampering features.

  • Evaluate the solution space for testing approaches, identify trade-offs, and lead execution of the chosen path.

  • Document all testing activities, methodologies, findings, discovered vulnerabilities, and precise reproduction steps in a clear, concise, and actionable manner in our bug tracking system (e.g., Jira).

  • Collaboration & Reporting

  • Lead the vulnerability lifecycle end-to-end: from discovery through root cause analysis, mitigation proposal, and fix verification — partnering closely with Android developers, security engineers, and product managers.

  • Drive alignment across teams on prioritization and remediation, and own the reporting of lock security posture to stakeholders.
  • Research & Intelligence

  • Proactively identify and evaluate new Android security vulnerabilities, platform changes, rooting techniques, bootloader unlocking methods, custom firmware, and bypass tools — translating findings into concrete actions for the team.

  • Own and evolve the lab environment, tooling, and device coverage strategy to stay ahead of the threat landscape.

  • Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or related field, OR equivalent practical experience; 4+ years in QA or security testing, with 2+ years in Android mobile testing.

  • Prior experience managing or leading a small team — setting direction, reviewing work, and developing people while still contributing individually.

  • Strong understanding of Android OS architecture (bootloader, recovery mode, ADB, fastboot, system partitions, security features) and hands-on experience attempting to bypass software-based locks, with a track record of proposing and validating mitigations.

  • Demonstrated ability to independently scope and own a testing strategy, including familiarity with rooting techniques, custom ROMs, device modification tools (e.g., Magisk, Xposed), and standard Android debugging tools (Android Studio, Logcat, Wireshark/tcpdump).

  • Meticulous attention to detail with strong analytical, problem-solving, and communication skills; comfortable working with ambiguity and owning outcomes in a fast-paced environment.

  •  

    Preferred Skills & Qualifications

  • Direct experience with lock-breaking, forensic, or mobile security assessment tools, or a background in dedicated security/penetration testing.

  • Knowledge of MDM or kiosk mode solutions and their vulnerabilities, plus understanding of common mobile security principles (e.g., OWASP Mobile Top 10).

  • Basic scripting skills (Python, Shell) for test automation or custom tooling.

  • Familiarity with emerging market Android devices and firmware; relevant certifications (e.g., eMAPT, GMOB, OSCP) are a plus.

  • Benefits

  • 100% Company-funded Health and dental and vision discount plan for employees and immediate family members.
  • Life insurance.
  • Phone finance, Headphone, home office equipment and wellness perks.
  • 30 days of Christmas bonus
  • 20 days paid Vacation
  • 50% Vacation premium 
  • 13% Saving funds 
  • $2,000 MXN monthly grocery coupons
  • $2,000 USD annual Co-working Travel perk
  • $2,000 USD annual Professional Development perk
  • Catered lunches

  • PayJoy is proud to be an Equal Employment Opportunity employer and we welcome and encourage people of all backgrounds. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
     
     
    Finance for the next billion * Ownership * Break Through Walls * Live Communication * Transparency & Directness * Focus on Scale * Work-Life Balance * Embrace Diversity * Speed * Active Listening
    Ready to apply to Payjoy?
    Apply to Payjoy

    Similar jobs

    Sign up for suggestions tailored to the jobs you open and the searches you save.

    More jobs at Payjoy

    See all jobs at Payjoy →

    Apply now
    🤖

    Whoa — hold up

    JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

    Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

    Catch your next role the second it’s posted.

    Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

    Create free account

    Free forever · takes 30 seconds · already have one?

    Get an edge on your job hunt.

    Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

    Join the channel — it's free