Mobile Security Tester - Remote
Capgemini • Romania
**Role & seniority: ** Mobile Security Tester (offensive/mobile security engineering, senior; min 5 years experience)
**Location & work type: ** Remote
**Stack / tools: **
-
Reverse engineering: IDA Pro, Ghidra, JADX, JEB
-
Binary formats/architectures: Mach-O, DEX, ELF
-
Dynamic instrumentation: Frida (JS injection), Objection
-
Threat/model & security standards: OWASP MASVS / MASTG
-
App attestation / bypass targets: Android Play Integrity API, iOS App Attest
-
Top 3 responsibilities:
-
Reverse engineer binaries (decompile/disassemble) to analyze logic and security controls
-
Use dynamic instrumentation (Frida/Objection) including runtime hooking and security control bypasses
-
Perform manual penetration testing & threat modeling of REST/GraphQL APIs (beyond automated compliance scanning)
-
-
Must-have skills:
-
Deep experience in mobile offensive security/pen testing (baseline 5+ years)
-
Advanced platform architecture knowledge (Android/iOS internals)
-
Ability to bypass SSL/TLS pinning
-
Experience bypassing anti-root/jailbreak controls
-
Proven ability to bypass hardware-backed attestation (Play Integrity, App Attest)
-
Strong alignment to OWASP MASVS/MASTG
-
-
Nice-to-haves:
- Prior work in highly secure industries (e.g., fintech, banking, identity ecosystems)
Full Description
MOBILE SECURITY TESTER – REMOTE
Summary of the Job Description Structure
Role Overview: Focuses on full-spectrum security engineering rather than standard automated compliance checklist scanning.
Core Responsibilities: Includes deep binary decompiling/disassembling, dynamic runtime hooking, manual penetration testing of REST/GraphQL APIs, and threat modeling.
Your role
Reverse Engineering: Specifying IDA Pro, Ghidra, Jadx, JEB, and understanding structures like Mach-O, DEX, and ELF.
Dynamic Instrumentation: Focuses on Frida (JavaScript injection), Objection, and bypassing hardware-backed attestation (Play Integrity, App Attest).
Standards: Full alignment with the industry-benchmark OWASP MASVS / MASTG framework.
Your profile
Professional Experience: Specifically highlights a baseline requirement of minimum 5 years of dedicated mobile offensive security/pen testing experience, with emphasis on highly secure industries (Fintech, Banking, Identity ecosystems).
Platform-Specific Architecture Mastery: Adds explicit parameters for deep platform knowledge.
Defensive Bypass Techniques: Demands proof of experience bypassing SSL/TLS Pinning, anti-root/jailbreak mechanisms, and hardware-level attestation systems (Android Play Integrity API and iOS App Attest).