Posted on: 16/09/2026
The Role :
We're hiring a Native Android / iOS Developer to build and own the SDKs that sit at the heart of OTPless - embedded directly inside the apps of India's top banks, fintechs, and fast-scaling startups.
This is not a typical app-development role. Our SDK runs inside some of the most security-sensitive, heavily scrutinized mobile apps in the country. Every release has to be lightweight, rock-solid across a brutal device/OS matrix, and hardened against attackers who actively try to reverse-engineer, hook, and tamper with it.
You'll own the device-security layer of the SDK - root/jailbreak detection, device fingerprinting for fraud signals, and RASP (Runtime Application Self-Protection) - working closely with our Security and ML teams, since the signals you capture feed directly into OTPless's fraud detection engine.
Your code will run on hundreds of millions of devices, inside banking apps that cannot afford to be wrong. That's the bar.
What You'll Do :
SDK Engineering :
- Build and maintain native Android (Kotlin/Java) and iOS (Swift/Objective-C) SDKs used by bank, fintech, and startup apps.
- Own SDK architecture, versioning, and backward compatibility across partner and OS versions.
- Optimise SDK size, cold-start latency, and memory footprint.
- Write integration docs, sample apps, and support tooling for partner teams.
Device Security & Anti-Fraud :
- Build and harden root/jailbreak, emulator, debugger, and hooking-framework detection (Frida, Xposed, Cydia Substrate).
- Build device fingerprinting for fraud and risk signals.
- Implement RASP - obfuscation, tamper detection, integrity checks, anti-repackaging.
- Track emerging bypass techniques and patch proactively.
- Feed device signals into the fraud detection engine with Security and ML.
Platform & Ecosystem :
- Work fluently across Android (Kotlin, NDK where relevant) and iOS (Swift, Objective-C).
- Integrate biometrics, Android Keystore, iOS Keychain/Secure Enclave, Play Integrity API, App Attest.
- Define secure SDK-to-server protocols - token exchange, certificate pinning, replay protection.
- Support partner integration, testing, and certification directly.
Quality, Release & Support :
- Test across a wide matrix of real devices, OS versions, and manufacturers.
- Own crash-free rate, ANR rate, and SDK stability in production.
- Build and maintain CI/CD for SDK builds, testing, and staged rollouts.
- Provide L2/L3 support for partner integration issues.
What We're Looking For :
Must-Have :
- 2 - 6 years of hands-on native mobile development experience (Android and/or iOS); strong depth on one platform with working knowledge of the other is fine.
- Proven experience building and shipping SDKs (not just apps) consumed by external partners - you understand versioning, backward compatibility, and public API design.
- Solid understanding of device security fundamentals - root/jailbreak detection, anti-tampering, code obfuscation.
- Working knowledge of device fingerprinting techniques and privacy-conscious identity signal generation.
- Familiarity with RASP concepts and implementation - runtime integrity checks, hooking/injection detection.
- Strong grasp of platform security primitives - Android Keystore / Play Integrity API, iOS Keychain / Secure Enclave / App Attest.
- Comfort working across Kotlin/Java (Android) and/or Swift/Objective-C (iOS).
- Experience debugging across a wide range of real devices and OS versions, not just emulators.
Good to Have :
- Experience with obfuscation/protection tooling (ProGuard/R8, DexGuard, iXGuard, or similar).
- Familiarity with the reverse-engineering tools attackers use (Frida, Xposed, Cydia Substrate, jadx, Hopper) - understanding offence sharpens defence.
- Experience integrating with banking or fintech apps, or working under RBI/PCI-DSS-adjacent constraints.
- NDK/C++ experience on Android, or low-level iOS security work.
- Experience with certificate pinning, mutual TLS, or other secure-transport hardening.
- Contribution to a published SDK/library with real external developer adoption.
Did you find something suspicious?
Posted by
Posted in
Mobile Applications
Functional Area
Mobile Development - Hybrid/Native
Job Code
1671818