Mobile Application Senior Security Engineer

8 ore fa

Varese, Lombardia, Italia Klarna Tempo pieno
Overview

In this role you will lead offensive security testing for Klarna’s mobile apps, focusing on iOS and Android; you’ll work with engineering teams to turn findings into fixes and improve app hardening. You’ll apply MASVS/MASTG guidelines to drive concrete security improvements, not just produce reports. The role combines hands-on testing, reverse engineering, and collaboration to reduce risk in a fintech mobile ecosystem. This is a hands-on position in a fast-moving security team with real impact on product security.

Responsabilità
  • Run offensive security assessments (penetration tests, red-team exercises, vulnerability discovery) on Klarna’s mobile apps (iOS/Android)
  • Reverse‑engineer app binaries to uncover sandboxing, permission, and core security weaknesses
  • Test against OWASP MASVS/MASTG and translate results into actionable fixes with engineering teams
  • Evaluate and stress‑test app-hardening and RASP protections
  • Document findings in actionable formats and ensure fixes are implemented in production
Requisiti fondamentali
  • Hands-on offensive mobile security experience (pentesting, red teaming, bug bounty, or security research) against iOS/Android
  • Strong understanding of mobile internals: sandboxing, permissions, security architectures of iOS and Android
  • Fluent with mobile security tooling (Frida, Objection, MobSF, jadx/apktool, Ghidra/Hopper, Burp Suite, mitmproxy)
  • Familiarity with OWASP MASVS/MASTG as primary framework for security assessments
  • Experience with app-hardening and RASP; fintech/payments app security a plus
  • Published CVEs, talks, or track record in mobile security or bug bounty (bonus)
  • Experience shipping production mobile code or similar
  • Familiarity with Play Integrity/App Attest and device-binding schemes (bonus)
  • Collaborative mindset
  • Strong written and verbal communication with engineers
  • Curiosity and meticulous attention to detail
  • OWASP MASVS/MASTG
  • Frida
  • Objection