Назад
2 дня назад

Mobile Application Senior Security Engineer (Fintech)

91 - 116 438GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/Poland/Sweden +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Mobile Application Senior Security Engineer (Fintech): Running offensive security assessments and vulnerability research against iOS and Android applications with an accent on mobile internals, reverse engineering, and OWASP MASVS/MASTG. Focus on stress-testing app-hardening and RASP protections, identifying platform-security weaknesses, and driving actionable fixes with engineering teams.

Location: London, Milan, Stockholm, or Warsaw; most teams meet in the office 2–3 days per week

Salary: £91–£116,438 per year

Company

Klarna is building an everyday finance network serving over 120 million consumers across 26 countries.

What you will do

  • Run penetration tests, red-team exercises, and vulnerability research against iOS and Android applications.
  • Reverse-engineer mobile application binaries to identify sandboxing, permission, and platform-security weaknesses.
  • Assess applications against the OWASP Mobile Application Security Verification Standard and Testing Guide.
  • Evaluate and stress-test app-hardening and RASP protections.
  • Partner with engineering teams to turn findings into fixes and follow remediation through to completion.
  • Document vulnerabilities and recommendations in an actionable format for engineers.

Requirements

  • Hands-on offensive mobile security experience through professional penetration testing, red teaming, bug bounty work, or security research.
  • Experience assessing iOS, Android, or both.
  • Understanding of mobile application sandboxing, permission models, and iOS and Android security architectures.
  • Fluency with Frida, Objection, MobSF, jadx or apktool, Ghidra or Hopper, Burp Suite, and mitmproxy.
  • Practical use of the OWASP MASVS and MASTG as a security assessment framework.
  • Ability to work from one of the listed locations and attend the office 2–3 days per week for most teams.

Nice to have

  • Experience securing fintech, payment, or banking applications.
  • Experience with app-hardening and RASP solutions from offensive and defensive perspectives.
  • Published CVEs, security research, conference talks, or mobile bug bounty achievements.
  • Production mobile development experience.
  • Familiarity with Play Integrity, App Attest, and device-binding schemes.

Culture & Benefits

  • Co-located collaboration is valued, with office attendance varying by team and potentially changing over time.
  • Diverse skills, perspectives, and backgrounds are welcomed.
  • Final compensation depends on qualifications, skills, and experience.
  • Applications should include a CV in English.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →