Staff Mobile & Product Security Engineer
MrBeast · San Francisco Bay Area
📍 San Mateo, CA💰 $170,000 to $250,000via greenhousePosted 2026-09-15
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to MrBeast.
About Us
Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson, popularly known as MrBeast, the most watched person in the world. Renowned for revolutionizing digital content creation, Beast Industries encompasses a diverse portfolio of ventures that extend far beyond its origins on YouTube. With a mission to entertain, inspire, and create significant social impact, Beast Industries operates across various domains including digital media, philanthropy, consumer products, and innovative business initiatives. At Beast Industries, we believe in the transformative power of digital media and its potential to entertain, educate, and effect positive change. Our commitment to innovation, creativity, and philanthropy drives us to explore new frontiers, create unforgettable experiences, and build a legacy that inspires future generations.
Staff Embedded Mobile & Product Security Engineer
Primary: Bay Area (San Francisco/Peninsula) | Secondary: NYC
Reports to: Director of Engineering Team: Security
About Us
Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson, popularly known as MrBeast, the most watched person in the world. Renowned for revolutionizing digital content creation, Beast Industries encompasses a diverse portfolio of ventures that extend far beyond its origins on YouTube. With a mission to entertain, inspire, and create significant social impact, Beast Industries operates across various domains including digital media, philanthropy, consumer products, and innovative business initiatives. At Beast Industries, we believe in the transformative power of digital media and its potential to entertain, educate, and effect positive change. Our commitment to innovation, creativity, and philanthropy drives us to explore new frontiers, create unforgettable experiences, and build a legacy that inspires future generations.
The Opportunity
We are building a first-of-its-kind consumer membership ecosystem from the ground up — and when you're serving 100M+ users across iOS, Android, and web, security has to be built in from day one, not bolted on later. As our Staff Embedded Mobile & Product Security Engineer , you will be the foundational security hire on the Security team, embedded directly with product and mobile squads to ship features that are secure by design rather than secured after the fact.
This is a hands-on, build-with-the-team role. You'll own mobile and product application security, run the pen testing program (with deep focus on mobile attack surface), and architect the controls that meet partner security requirements so the business can close deals and ship with confidence.
The Product
You will be the security anchor underneath a membership ecosystem anchored around the MrBeast audience, spanning native mobile apps, web clients, and backend platform services. Your surface area spans every product squad and every partnership:
Mobile Security: iOS and Android app security — secure storage, certificate/key pinning, jailbreak/root and tamper detection, secure IPC, mobile authN/authZ flows, and hardening of the mobile SDK and build/release pipeline.
Product & Application Security: Threat modeling, secure-by-default patterns, code review, and developer-facing tooling across the membership app, creator marketplace, and platform services.
Offensive Testing: A pen testing program you own end-to-end — internal red-team exercises (including mobile-specific testing: static/dynamic analysis, reverse engineering, API abuse), coordinated external engagements, and continuous validation against real attacker behavior.
Security Architecture: The control framework that lets us meet partner security requirements — and the architecture decisions that keep our mobile and product surfaces ready for the next partner, not scrambling for them.
What You'll Do
Embed directly with mobile and product squads — membership app (iOS/Android), marketplace, data & identity — to threat-model, review, and harden features before they ship.
Own the mobile application security program end-to-end: secure mobile SDLC, mobile-specific code review (Swift/Kotlin/React Native, as applicable), dependency and supply-chain controls, and developer-facing security tooling.
Own the broader product application security program: secure-by-default patterns, API and backend security review, and paved-road tooling for engineering teams.
Run the pen testing program — hands-on offensive work spanning mobile (static/dynamic analysis, binary/reverse engineering, on-device attack surface) and web/API, plus coordination of external engagements — and turn findings into fixed issues, not tickets in a backlog.
Architect the security controls and documentation that meet partner security requirements, so partnership deals close on our schedule.
Set the security baseline for a zero-to-one, AI-native stack: coding agents, model and prompt security, mobile AI features, and the new attack surface that comes with AI-native products.
Write the playbook — mobile and product security standards, guardrails, and the "paved road" — so as the org scales, secure is the easy path.
Who You Are
Embedded Builder: You've been the security engineer on a product or mobile team, not just a reviewer at the gate. You write code, file PRs, and ship fixes yourself when it's the fastest path.
Mobile Security Depth: You've secured native iOS and/or Android applications at consumer scale — you understand mobile-specific threats (reverse engineering, tampering, insecure storage, insecure IPC, mobile API abuse) and how to design against them.
AppSec at Consumer Scale: You've run or heavily contributed to an application security program inside a consumer product used by millions — you know the real tradeoffs between coverage, velocity, and risk.
Offensive Hands-On: You can pen test mobile and web applications, not just read pen test reports. You've
More San Francisco Bay Area jobs
San Francisco Bay Area jobs · Browse all locations