Posted today · be early
Mobile App Security Engineer
Bjak
WorldwideremotePosted today
Skill Required
Mobile-Security-EngineerMobile-DevSecOps-EngineerMobile-Security-EngineeringMobile-Security-ArchitectApplication-Security-EngineerApp-Security-SpecialistAppSec-EngineerSoftware-Security-EngineerSecurity-EngineerSecurity EngineersecurityPenetration Testingrelated fieldCybersecuritydebuggingbuildingAndroidTestNGKotlinSwiftOWASPiOSandFulltime
Key highlights
- 3+ years in mobile development, mobile security, or mobile penetration testing
- Required experience with SC TRM and BNM RMiT controls
- Required native iOS (Swift) and Android (Kotlin) expertise
- Strong English communication required
Role overview
BJAK is a leading mobile-first insurance platform in Southeast Asia, founded in 2019 with a mission to provide smarter ways for people to plan, save, and grow their money. The company is expanding into spending, saving, investing, exchanging, and traveling, employing a global team of over 20 nationalities. The role involves protecting BJAK's native iOS and Android applications and their connections to backend services, working closely with mobile, backend, and security teams to integrate mobile security into development and release processes.
Responsibilities
- Assess and review native iOS and Android applications built with Swift and Kotlin.
- Apply OWASP MASVS and MASTG to define mobile security requirements, test coverage, and remediation priorities.
- Assess secure local storage, Keychain and Keystore use, sensitive data handling, sessions, tokens, and data leakage.
- Implement and test transport security, including certificate validation and certificate pinning where appropriate.
- Evaluate tamper detection, jailbreak and root detection, anti-debugging, and runtime protection controls proportionate to risk.
- Work with API and backend teams on authentication, authorization, API exposure, and secure mobile communication.
- Own mobile security controls for SC TRM and BNM RMiT, including testing evidence, vulnerability remediation, release controls, and audit support.
Requirements
- Degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
- 3+ years in mobile development, mobile security, or mobile penetration testing.
- Experience implementing and owning SC TRM and BNM RMiT controls relevant to mobile applications and secure technology delivery.
- Hands-on native iOS development or review using Swift and Android using Kotlin.
- Practical knowledge of OWASP MASVS and MASTG, mobile threat modeling, and mobile testing tools.
- Experience with secure storage, certificate pinning, jailbreak/root detection, tamper resistance, authentication, and mobile API security.
- Able to work with mobile developers and communicate findings, trade-offs, and remediation steps.
- Strong English communication is required.
Additional details
- English is our main working language across global teams.
- Originally posted on Himalayas