Description review
Mobile App Security Engineer
Bjak · Remote · back to the listing
HR standards
51/100
needs work
Title ↔ description
86/100
strong
Reads as
Security Engineer
100% confident
What this role officially is
ICT security administrator — ESCO, the EU occupation classification
ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.
Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator
How others title the same work
Large employers
- Security Risk Management Specialist Canonical Ltd.
- Security Software Engineer Canonical Ltd.
- Senior Security Operations Engineer Canonical Ltd.
- Staff Security Operations Engineer Canonical Ltd.
- Ubuntu Security Engineer Canonical Ltd.
Startups
- Security Engineer (Bangalore, India) AiPrise
- Security & Trust Engineer Alex
- Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
- Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
- Factory | Security Engineer | Onsite in San Francisco | Full-time Factory
What the listing never says
- No section describes what the person would actually do. Scope clarity
- No pay range published. Candidates cannot tell whether applying is worth their time. Pay transparency
The listing, marked up
Nothing in the wording of this listing tripped a check. The scores above still judge how complete and coherent it is.
About BJAK
The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.
Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.
Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.
We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.
If you're this person, we'd love to talk to you.
The Role
Protect BJAK's native iOS and Android applications and their connections to backend services. Work with mobile, backend, and security teams to build mobile security into development and release processes.
What You Will Build
• Assess and review native iOS and Android applications built with Swift and Kotlin.
• Apply OWASP MASVS and MASTG to define mobile security requirements, test coverage, and remediation priorities.
• Assess secure local storage, Keychain and Keystore use, sensitive data handling, sessions, tokens, and data leakage.
• Implement and test transport security, including certificate validation and certificate pinning where appropriate.
• Evaluate tamper detection, jailbreak and root detection, anti-debugging, and runtime protection controls proportionate to risk.
• Work with API and backend teams on authentication, authorization, API exposure, and secure mobile communication.
• Own mobile security controls for SC TRM and BNM RMiT, including testing evidence, vulnerability remediation, release controls, and audit support.
What We Look For
• Degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
• 3+ years in mobile development, mobile security, or mobile penetration testing.
• Experience implementing and owning SC TRM and BNM RMiT controls relevant to mobile applications and secure technology delivery.
• Hands-on native iOS development or review using Swift and Android using Kotlin.
• Practical knowledge of OWASP MASVS and MASTG, mobile threat modeling, and mobile testing tools.
• Experience with secure storage, certificate pinning, jailbreak/root detection, tamper resistance, authentication, and mobile API security.
• Able to work with mobile developers and communicate findings, trade-offs, and remediation steps.
Language
English is our main working language across global teams. Strong English communication is required.
Originally posted on Himalayas
The original mission of BJAK is we believe people deserve smarter ways to plan, save and grow their money. This is the origin of our name.
Started in 2019, we built the first mobile-first, insurance platform, enabling insurance to be accessible online by millions in the region. Today, its the leading insurance platform in Southeast Asia.
Today, we are expanding ways to help people in the region — this includes spending, saving, investing, exchanging, travelling, and more. Our mission is help people get more from their money every day.
We have teams working around the world, with over 20 nationalities from our offices and remotely, who truly enjoys their work. We are looking for the most talented and driven people we can find. We are looking for people who work for their passion, not counting hours. Who loves building great next-generation products, not status quo. Who cares about redefining how everyone around us can get the best financial applications, not for an exclusive few.
If you're this person, we'd love to talk to you.
The Role
Protect BJAK's native iOS and Android applications and their connections to backend services. Work with mobile, backend, and security teams to build mobile security into development and release processes.
What You Will Build
• Assess and review native iOS and Android applications built with Swift and Kotlin.
• Apply OWASP MASVS and MASTG to define mobile security requirements, test coverage, and remediation priorities.
• Assess secure local storage, Keychain and Keystore use, sensitive data handling, sessions, tokens, and data leakage.
• Implement and test transport security, including certificate validation and certificate pinning where appropriate.
• Evaluate tamper detection, jailbreak and root detection, anti-debugging, and runtime protection controls proportionate to risk.
• Work with API and backend teams on authentication, authorization, API exposure, and secure mobile communication.
• Own mobile security controls for SC TRM and BNM RMiT, including testing evidence, vulnerability remediation, release controls, and audit support.
What We Look For
• Degree in Computer Science, Cybersecurity, or related field, or equivalent experience.
• 3+ years in mobile development, mobile security, or mobile penetration testing.
• Experience implementing and owning SC TRM and BNM RMiT controls relevant to mobile applications and secure technology delivery.
• Hands-on native iOS development or review using Swift and Android using Kotlin.
• Practical knowledge of OWASP MASVS and MASTG, mobile threat modeling, and mobile testing tools.
• Experience with secure storage, certificate pinning, jailbreak/root detection, tamper resistance, authentication, and mobile API security.
• Able to work with mobile developers and communicate findings, trade-offs, and remediation steps.
Language
English is our main working language across global teams. Strong English communication is required.
Originally posted on Himalayas