Capgemini logo

Mobile Security Tester - Remote

Capgemini Romania

remote
Posted Sep 23, 2026

**Role & seniority: ** Mobile Security Tester (offensive/mobile security engineering, senior; min 5 years experience)

**Location & work type: ** Remote

**Stack / tools: **

  • Reverse engineering: IDA Pro, Ghidra, JADX, JEB

  • Binary formats/architectures: Mach-O, DEX, ELF

  • Dynamic instrumentation: Frida (JS injection), Objection

  • Threat/model & security standards: OWASP MASVS / MASTG

  • App attestation / bypass targets: Android Play Integrity API, iOS App Attest

  • Top 3 responsibilities:

    1. Reverse engineer binaries (decompile/disassemble) to analyze logic and security controls

    2. Use dynamic instrumentation (Frida/Objection) including runtime hooking and security control bypasses

    3. Perform manual penetration testing & threat modeling of REST/GraphQL APIs (beyond automated compliance scanning)

  • Must-have skills:

    • Deep experience in mobile offensive security/pen testing (baseline 5+ years)

    • Advanced platform architecture knowledge (Android/iOS internals)

    • Ability to bypass SSL/TLS pinning

    • Experience bypassing anti-root/jailbreak controls

    • Proven ability to bypass hardware-backed attestation (Play Integrity, App Attest)

    • Strong alignment to OWASP MASVS/MASTG

  • Nice-to-haves:

    • Prior work in highly secure industries (e.g., fintech, banking, identity ecosystems)

Full Description

MOBILE SECURITY TESTER – REMOTE

Summary of the Job Description Structure

Role Overview: Focuses on full-spectrum security engineering rather than standard automated compliance checklist scanning.

Core Responsibilities: Includes deep binary decompiling/disassembling, dynamic runtime hooking, manual penetration testing of REST/GraphQL APIs, and threat modeling.

Your role

Reverse Engineering: Specifying IDA Pro, Ghidra, Jadx, JEB, and understanding structures like Mach-O, DEX, and ELF.

Dynamic Instrumentation: Focuses on Frida (JavaScript injection), Objection, and bypassing hardware-backed attestation (Play Integrity, App Attest).

Standards: Full alignment with the industry-benchmark OWASP MASVS / MASTG framework.

Your profile

Professional Experience: Specifically highlights a baseline requirement of minimum 5 years of dedicated mobile offensive security/pen testing experience, with emphasis on highly secure industries (Fintech, Banking, Identity ecosystems).

Platform-Specific Architecture Mastery: Adds explicit parameters for deep platform knowledge.

Defensive Bypass Techniques: Demands proof of experience bypassing SSL/TLS Pinning, anti-root/jailbreak mechanisms, and hardware-level attestation systems (Android Play Integrity API and iOS App Attest).

Mobile Security TestingReverse EngineeringBinary DecompilationDynamic InstrumentationFridaObjectionManual Penetration TestingREST API Security TestingGraphQL API Security TestingThreat ModelingSSL/TLS Pinning BypassRoot and Jailbreak Detection BypassHardware-Backed Attestation BypassAndroid SecurityiOS SecurityOWASP MASVS/MASTG

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.