About this Senior Mobile Security Engineer role at Payjoy
The success of PayJoy depends on the strength of its locking technology against various evolving bypass mechanisms. As an experienced Android security analyst and team lead, you will be responsible for both testing and strengthening PayJoy's lock strength directly, and for leading a distributed team of three Lock Product Analysts across Brazil, South Africa, and the Philippines.
We are seeking a highly skilled and tenacious senior analyst with a specialized focus on Android device security. In this critical senior role, you will independently define and lead PayJoy's testing strategy against device lock bypass methods and tools, while also managing and coordinating a distributed team of three Lock Product Analysts across Brazil, South Africa, and the Philippines. Given the problem space — ensuring lock integrity across OS OTA updates, lock technology changes, and evolving in-market bypass tools — you will explore and evaluate your own approaches, propose solutions, and drive them to completion. You will own the vulnerability discovery roadmap, lead the response to what your team finds, and develop the people doing the work.
This position requires 10–25% travel to investigate vulnerabilities and techniques across several markets.
Responsibilities
Team Management
Lead, mentor, and develop a team of three Lock Product Analysts based in Brazil, South Africa, and the Philippines — setting clear expectations, reviewing their work, and supporting their growth.
Coordinate testing coverage across markets, ensuring the team's efforts are prioritized against the highest-risk devices and vulnerabilities globally.
Serve as the escalation point for complex or ambiguous findings surfaced by the team, and make the call on severity, prioritization, and next steps.
Build team rituals and shared processes (e.g., testing standards, vulnerability documentation, cross-market knowledge sharing) that improve quality and consistency as the team scales.
Bypass Testing & Vulnerability Identification
Independently design and drive the approach to testing PayJoy's device locking mechanism across a diverse range of Android devices and OS versions following every OTA update.
Define and lead comprehensive periodic testing of the lock after every update to PayJoy lock technology, proactively identifying gaps before they become exploits.
Research, identify, and evaluate existing and emerging lock-breaking tools, software, hardware techniques, and methodologies (e.g., factory reset exploits, bootloader vulnerabilities, ADB exploits, custom ROM flashing, FRP bypass tools) — proposing which attack vectors to prioritize and why.
Test Strategy & Execution
Independently design, own, and continuously evolve the test strategy, test cases, and test scenarios for lock security, bypass attempts, and anti-tampering features.
Evaluate the solution space for testing approaches, identify trade-offs, and lead execution of the chosen path.
Document all testing activities, methodologies, findings, discovered vulnerabilities, and precise reproduction steps in a clear, concise, and actionable manner in our bug tracking system (e.g., Jira).
Collaboration & Reporting
Lead the vulnerability lifecycle end-to-end: from discovery through root cause analysis, mitigation proposal, and fix verification — partnering closely with Android developers, security engineers, and product managers.
Research & Intelligence
Proactively identify and evaluate new Android security vulnerabilities, platform changes, rooting techniques, bootloader unlocking methods, custom firmware, and bypass tools — translating findings into concrete actions for the team.
Own and evolve the lab environment, tooling, and device coverage strategy to stay ahead of the threat landscape.
Requirements
Bachelor's degree in Computer Science, Cybersecurity, or related field, OR equivalent practical experience; 4+ years in QA or security testing, with 2+ years in Android mobile testing.
Prior experience managing or leading a small team — setting direction, reviewing work, and developing people while still contributing individually.
Strong understanding of Android OS architecture (bootloader, recovery mode, ADB, fastboot, system partitions, security features) and hands-on experience attempting to bypass software-based locks, with a track record of proposing and validating mitigations.
Demonstrated ability to independently scope and own a testing strategy, including familiarity with rooting techniques, custom ROMs, device modification tools (e.g., Magisk, Xposed), and standard Android debugging tools (Android Studio, Logcat, Wireshark/tcpdump).
Meticulous attention to detail with strong analytical, problem-solving, and communication skills; comfortable working with ambiguity and owning outcomes in a fast-paced environment.
Preferred Skills & Qualifications
Direct experience with lock-breaking, forensic, or mobile security assessment tools, or a background in dedicated security/penetration testing.
Knowledge of MDM or kiosk mode solutions and their vulnerabilities, plus understanding of common mobile security principles (e.g., OWASP Mobile Top 10).
Basic scripting skills (Python, Shell) for test automation or custom tooling.
Familiarity with emerging market Android devices and firmware; relevant certifications (e.g., eMAPT, GMOB, OSCP) are a plus.