Senior Mobile Security Engineer (Android/iOS)
at Encora10
- Seniority
- Senior
- Location
- Kuala Lumpur
- Posted
- 5d ago
at Encora10
<p>Key Responsibilities: <br>● App Hardening: Implement and maintain RASP (Runtime Application Self-Protection), <br>Code Obfuscation (ProGuard/DexGuard), and Root/Jailbreak detection mechanisms. <br>● Secure Connectivity: Enforce Certificate Pinning and secure TLS configurations to <br>prevent Man-in-the-Middle (MitM) attacks. <br>● Data Protection: Ensure no sensitive data (PII, Keys) is leaked in logs, cache, or <br>snapshots. Secure usage of Android Keystore and iOS Keychain. <br>● Mobile Design Components: Deliver new security design patterns and components <br>for Mobile security. Create reusable libraries for biometric login, secure storage, and <br>device attestation that feature teams can easily drop into their code. <br>● Pentesting: Regularly decompile and attack our own binaries to verify defenses. </p> <p>Technical Requirements: <br>● Deep knowledge of Android (Kotlin/Java) and iOS (Swift/Obj-C) internals. <br>● Experience with mobile security frameworks (OWASP MASVS). <br>● Hands-on experience with reverse engineering tools (Frida, Ghidra, MobSF). <br>● Understanding of Biometric authentication flows (FaceID/TouchID implementation). </p>