Bjak
Mobile App Security Engineer
About this role
Protect BJAK's iOS and Android applications by assessing native mobile security, implementing OWASP standards, and collaborating with development teams to embed security into release processes. You'll own mobile security controls, evaluate tamper detection and transport security, and ensure compliance with regional financial regulations.
What you'll do
- Review and assess native iOS (Swift) and Android (Kotlin) applications for security vulnerabilities
- Apply OWASP MASVS and MASTG standards to define security requirements, testing coverage, and remediation priorities
- Evaluate secure storage, Keychain/Keystore, authentication, and data leakage in mobile applications
- Implement and test transport security including certificate validation and certificate pinning
- Own mobile security controls for SC TRM and BNM RMiT compliance, including testing and audit support
- Collaborate with mobile, backend, and API teams on authentication, authorization, and secure mobile communication
What they're looking for
- Mobile security testing and penetration testing
- Native iOS development and code review (Swift)
- Native Android development and code review (Kotlin)
- OWASP MASVS and MASTG frameworks
- Certificate pinning and transport layer security
- Jailbreak/root detection and tamper resistance
- Mobile threat modeling
- API and backend security assessment
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Bjak
Bjak is a Southeast Asian fintech super app offering insurance, payments, savings, wallets, and investment products through a unified platform. The company is hiring full stack engineers, backend engineers, iOS developers, and Android engineers to build scalable features and reliable systems across mobile and web products.
- Website
- bjak.com
Likely interview questions
- Walk us through your approach to assessing a native iOS or Android application for security vulnerabilities using OWASP MASVS.
- Describe your experience implementing certificate pinning in mobile applications and the trade-offs you've encountered.