SENIOR ANDROID ENGINEER // SECURITY & SDKs // AI AGENTS
I BUILD SECUREANDROID SYSTEMS —AND THE AGENTSTHAT BUILD THEM.
High-stakes Android architecture, application hardening and an end-to-end agentic SDLC — with engineers approving every plan and every merge.
Worked with
- Digidentity
- Ypsomed (via InnoIT)
- Vodafone
- Unisys
- EVO Banco
- Wallbox
Changes what this page puts first. Nothing is hidden for good.
SUMMARY / 00
Who, what and why — in 30 seconds.
At a glance
- ROLE
- Senior Android Engineer · 13+ years
- NOW
- Digidentity — digital identity (2025–present)
- BEFORE
- Lead Android Engineer, Ypsomed medical device (InnoIT) · Vodafone · Unisys
- SECURITY
- PKI, mTLS, certificate pinning, Keystore, digital signatures, passwordless login, DexGuard / R8
- AI / AGENTS
- Designed and runs an agentic SDLC: Claude Code, MCP (Jira, Figma, GitLab), on-device testing, human gates
- LOCATION
- Madrid, Spain · EU citizen — no visa required
- AVAILABILITY
- Open for new opportunities
- LANGUAGES
- Spanish (native) · English (C1)
SYSTEM ARCHITECTURE
Resilient, modular Android apps and SDKs for regulated products — from secure storage and networking to Compose UI.
- Multi-layered modular architecture
- SDK development and lifecycles (Android + iOS)
- Performance profiling and optimization
Visualizing the stack
SECURITY PIPELINE
DEFENSE IN DEPTH FOR ANDROID
01_IDENTITY
PKI / mTLS
Mutual trust between client and server, proven with certificates.
02_STORAGE
ANDROID KEYSTORE
Hardware-backed protection for keys that never leave the device.
03_CODE
DEXGUARD / R8
Obfuscation and hardening that raise the cost of reverse engineering.
04_RELEASE
SIGNED RELEASE
Cryptographically verified production builds.
In production: a PKI and mTLS channel to a medical device (Ypsomed), and X.509 signatures with DexGuard hardening for digital identity (Digidentity).
AGENTIC SDLC
The pipeline I designed and run at Digidentity: a Jira ticket goes in, a reviewed merge request comes out. Tested on emulators and physical devices.
Agents: Claude Code
Connected to Jira, Figma and GitLab through MCP servers.
Human gates: 2
Engineers approve the plan before coding and the merge before it lands.
- JIRA TICKET
- REFINEMENT
- HUMAN APPROVAL
- DEVELOPMENT
- TESTING
- REVIEW
- HUMAN APPROVAL
- MERGE REQUEST
$ agent run "Add biometric authentication to sign-in"
Press Run to replay a pipeline run.
EXPERIENCE_LOG
JAN 2025 – PRESENT
SENIOR ANDROID ENGINEER · Digidentity
- Designed and run an AI-agentic development and testing system on a server with Android emulators and physical devices.
- Agents built on Claude Code, connected to Jira, Figma and GitLab through MCP servers.
JUN 2022 – DEC 2024
LEAD ANDROID ENGINEER · InnoIT — Ypsomed project
- Led the Android and iOS SDKs for an EU medical self-injection device.
- Encrypted communication channel between the Android device and the medical device, authenticated with PKI and certificate-based mTLS.
SEP 2019 – JUN 2022
ANDROID ENGINEER · Vodafone
- Core features for Vodafone's e-commerce mobile app, improving UX and stability.
FEB 2019 – SEP 2019
ANDROID ENGINEER · Unisys
- ENIRE airport operations app: Java, Clean Architecture, MDM, unit tests.
PRINCIPLES / 05
Engineering principles
01
Security is architecture
Security is not a final checklist. It defines identity, trust boundaries and system design.
02
Automation should create leverage
Agents should remove repetitive engineering work while preserving human judgment.
03
Every agent needs boundaries
Tools, permissions, context and execution must be explicitly constrained.
04
Ship with evidence
Tests, traces and production behaviour matter more than claims.
05
Humans own the system
AI can accelerate engineering. Accountability remains human.
06
Defense in depth
mTLS, authentication, secure storage, obfuscation and hardening each solve a different part of the problem.
WORK / 06
Selected work
Digidentity · 2026
An agentic SDLC for Android
- Constraints
- Regulated identity product: every change needs human accountability and real-device validation.
- Architecture
- Six stages — refinement, approval, development, testing, review, approval — with Claude Code agents connected to Jira, Figma and GitLab via MCP.
- Decisions
- Two human gates: one before code is written, one before merge.
- Implementation
- Runs on a dedicated server with Android emulators and physical devices.
InnoIT — Ypsomed · 2022–2024
Secure channel to a medical device
- Constraints
- EU medical device: high reliability and secure communication between phone and device.
- Architecture
- Android and iOS SDKs with an encrypted channel authenticated by PKI and certificate-based mTLS.
- Implementation
- TDD, Coroutines, XP practices and CI/CD pipelines.
Digidentity · 2025
Identity SDK and wallet
- Architecture
- Android SDK and decentralized identity wallet.
- Implementation
- Identity verification, onboarding, secure authentication, passwordless login and certificate-based digital signatures.
- Security
- App hardened with DexGuard.