Senior Mobile Security Engineer (Android/iOS)
Encora
| Company | Encora |
| Category | Engineering |
| Location | Kuala Lumpur |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 22 Jun 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Key Responsibilities: ● App Hardening: Implement and maintain RASP (Runtime Application Self-Protection), Code Obfuscation (ProGuard/DexGuard), and Root/Jailbreak detection mechanisms. ● Secure Connectivity: Enforce Certificate Pinning and secure TLS configurations to prevent Man-in-the-Middle (MitM) attacks. ● Data Protection: Ensure no sensitive data (PII, Keys) is leaked in logs, cache, or snapshots. Secure usage of Android Keystore and iOS Keychain. ● Mobile Design Components: Deliver new security design patterns and components for Mobile security. Create reusable libraries for biometric login, secure storage, and device attestation that feature teams can easily drop into their code. ● Pentesting: Regularly decompile and attack our own binaries to verify defenses.
Technical Requirements: ● Deep knowledge of Android (Kotlin/Java) and iOS (Swift/Obj-C) internals. ● Experience with mobile security frameworks (OWASP MASVS). ● Hands-on experience with reverse engineering tools (Frida, Ghidra, MobSF). ● Understanding of Biometric authentication flows (FaceID/TouchID implementation).