Mobile Security Analyst (m/f/d) - Bug Bounty, Mobile Device Vulnerability Management, Threat Hunting
Fully-remote from Germany, as soon as possible
ABOUT US:
Common Codes is leading the development of Germany’s EUDI Wallet on behalf of the Federal Ministry for Digital Transformation and Government Modernisation. Our mission is to build secure, privacy-first and trustworthy digital public infrastructure. Together with partners from government, business, research and civil society, we are creating an open and interoperable ecosystem for digital credentials. The EUDI Wallet will enable public authorities and companies to offer new digital services, simplify processes and develop applications based on verifiable digital information. For citizens, it will provide a simple and secure way to identify themselves, store digital credentials and share only the information required in a specific situation. Whether opening a bank account, applying to a university or proving their age, users will remain in control of their personal data. By building this infrastructure, we are laying the foundation for a more accessible, efficient and trustworthy digital society. The EUDI Wallet will reduce bureaucratic barriers, make digital services easier to use and strengthen digital sovereignty in Germany and Europe
YOUR ROLE:
As Mobile Security Analyst (m/f/d), you will support three closely linked security functions: the bug bounty and vulnerability disclosure programs, threat hunting mobile security threats which ultimately will feed into our Mobile Device Vulnerability Management (MDVM) solution.
In the internal bug bounty team, you will support technical triage and in-depth security assessment of vulnerability reports with a strong focus on mobile applications (iOS/Android), however you may also assist the team with technical triage support for some web applications and APIs. These important steps help build a robust and effective MDVM - tracking, assessing and acting on vulnerabilities in the device’s operating system, hardware key stores and wallet app integrity that ensure the security of the German EUDI Wallet.
YOUR RESPONSIBILITIES:
- Reproduce proof-of-concepts submitted through the bug bounty and the vulnerability disclosure program, and validate whether reported issues are exploitable in the relevant technical context.
- Assess the severity, help realise the business impact and support the remediation priority of reported vulnerabilities across mobile, web and API surfaces.
- Support the operational handling of vulnerability reports and take over selected coordination, communication and decision-making responsibilities when needed.
- Retest remediated findings and verify whether fixes are complete and effective.
- Monitor and assess vulnerabilities affecting user device operating systems, hardware key stores and wallet instances.
- Evaluate the attack potential of newly disclosed OS/key store/chip vulnerabilities and contribute to risk-based decisions on device or wallet usage restrictions where integrity cannot be sufficiently verified.
- Apply reverse engineering skills (static/dynamic analysis, instrumentation, runtime hooking) to independently validate mobile findings and collaborate with threat hunters on specific mobile investigations.
- Help internal development teams identify the root cause of security issues, particularly in native mobile code, SDKs and third-party libraries.
- Work with development teams on sustainable remediation measures that address the underlying cause, not only the individual attack path.
WHAT WE’RE LOOKING FOR:
- Strong hands-on experience in security testing mobile applications.
- Strong hands-on experience of reverse engineering mobile applications (iOS and Android),
- Hands-on experience in security testing of web applications and APIs.
- Practical understanding of mobile platform security mechanisms: secure enclave/hardware-backed keystores, platform attestation (e.g. Android Key Attestation, iOS DeviceCheck/App Attest).
- Strong knowledge of common vulnerability classes affecting mobile, web and API environments.
- Good understanding of secure development lifecycle practices and how security findings can be translated into engineering action.
- Ability to analyze technical findings precisely and explain them clearly to different stakeholders.
- Strong written and verbal communication skills in English, especially in discussions with development teams and external researchers.
- Sound judgment and the ability to make risk- and impact-based decisions, including under time pressure.
- Structured and reliable way of working, including clear documentation and consistent follow-up.
NICE TO HAVE:
- Direct experience working with bug bounty or vulnerability disclosure programs.
- Familiarity with common severity rating approaches such as CVSS and with risk-based vulnerability prioritization.
- Experience supporting remediation in agile or product-oriented engineering environments.
- Prior exposure to threat hunting methodology or mobile threat intelligence feeds.
- Experience with digital identity, wallet or credential systems (e.g. OpenID4VCI, mDL/mDoc, eIDAS) and their mobile security implications.
- Understanding of modern authentication and authorization patterns in API-centric systems.
- Degree in information security, computer science, cybersecurity or a related field, or equivalent practical experience.
- Working understanding of the German language.
WHAT WE OFFER:
- A chance to shape one of Germany’s most important digital public infrastructures
- A forward-thinking, mission-driven work culture at the intersection of science, administration, and innovation
- Flexible working hours and remote work from Germany
- Competitive compensation commensurate with the level of responsibility
- Access to conferences, team events and a supportive work culture.
We look forward to receiving your application via our application form.
Jetzt bewerben
Please fill out the following form to apply for the advertised position. All fields marked with * are required.