Senior Android Engineer – VPN/Networking
Fusemachines29 days ago
Remote, WorldwideSenior
Responsibilities
- Build and manage Android VPN tunnels with routing, DNS handling, per-app VPN, and always-on VPN behavior.
- Implement packet capture and forwarding through TUN interfaces while handling MTU, TCP/UDP behavior, latency, and packet loss.
- Support WireGuard, OpenVPN, IKEv2/IPsec, and potentially Shadowsocks or custom tunneling protocols.
- Integrate and ship native VPN libraries across arm64-v8a and armeabi-v7a ABIs using NDK/JNI, C/C++, Gradle, and CMake.
- Harden releases with R8 and ProGuard, crash and ANR monitoring, and Google Play Console workflows.
- Apply Android Keystore, secure storage, encryption, certificate handling or pinning, threat modeling, least-privilege design, and privacy-first telemetry.
- Contribute optionally to backend APIs, secrets management, rate limiting, Linux networking, infrastructure-as-code, CI/CD, monitoring, centralized logging, and operational runbooks.
- Deliver stable connections with minimal battery impact and no DNS or IP leaks in standard test suites.
Requirements
- Strong Android Kotlin experience with coroutines/Flow and modern Android architecture.
- Experience building and managing VPN tunnels with Android VpnService, routing, DNS, per-app VPN, and always-on VPN behavior.
- Understanding of TUN interfaces, packet capture and forwarding, MTU, TCP/UDP, TLS, DNS, HTTP(S), proxies, NAT, latency, and packet loss handling.
- Experience with WireGuard keypairs, allowed IPs, handshakes, and keepalive behavior; OpenVPN TLS, configuration formats, cipher suites, and connection stability; and IKEv2/IPsec authentication and mobility features.
- NDK/JNI and C/C++ experience for integrating VPN cores is strongly preferred.
- Experience with R8/ProGuard, crash and ANR monitoring, Google Play Console, multi-ABI native libraries, Gradle, and CMake.
- Knowledge of Android Keystore, secure storage, encryption, certificate handling or pinning, threat modeling, least-privilege design, and privacy-first telemetry.
- Prior consumer or enterprise VPN product experience and experience with Google Play policies for VPN applications are preferred.
- Experience building a core VPN SDK with an application shell is preferred.
- Optional experience includes Go, Java, Node.js, or Python; PostgreSQL; secure API design; KMS or Vault; rate limiting; Linux networking; iptables or nftables; sysctl tuning; infrastructure-as-code; CI/CD; Prometheus; Grafana; and centralized logging.
Benefits
- Full-time remote work arrangement.
- Six-month contractual engagement with possibility of extension.