Mobile Security Analyst (m/f/d) - Bug Bounty, Mobile Device Vulnerability Management, Threat Hunting

Fully-remote from Germany, as soon as possible

ABOUT US:

Common Codes is leading the development of Germany’s EUDI Wallet on behalf of the Federal Ministry for Digital Transformation and Government Modernisation. Our mission is to build secure, privacy-first and trustworthy digital public infrastructure. Together with partners from government, business, research and civil society, we are creating an open and interoperable ecosystem for digital credentials. The EUDI Wallet will enable public authorities and companies to offer new digital services, simplify processes and develop applications based on verifiable digital information. For citizens, it will provide a simple and secure way to identify themselves, store digital credentials and share only the information required in a specific situation. Whether opening a bank account, applying to a university or proving their age, users will remain in control of their personal data. By building this infrastructure, we are laying the foundation for a more accessible, efficient and trustworthy digital society. The EUDI Wallet will reduce bureaucratic barriers, make digital services easier to use and strengthen digital sovereignty in Germany and Europe

YOUR ROLE:

As Mobile Security Analyst (m/f/d), you will support three closely linked security functions: the bug bounty and vulnerability disclosure programs, threat hunting mobile security threats which ultimately will feed into our Mobile Device Vulnerability Management (MDVM) solution.

In the internal bug bounty team, you will support technical triage and in-depth security assessment of vulnerability reports with a strong focus on mobile applications (iOS/Android), however you may also assist the team with technical triage support for some web applications and APIs. These important steps help build a robust and effective MDVM - tracking, assessing and acting on vulnerabilities in the device’s operating system, hardware key stores and wallet app integrity that ensure the security of the German EUDI Wallet.

YOUR RESPONSIBILITIES:

  • Reproduce proof-of-concepts submitted through the bug bounty and the vulnerability disclosure program, and validate whether reported issues are exploitable in the relevant technical context.
  • Assess the severity, help realise the business impact and support the remediation priority of reported vulnerabilities across mobile, web and API surfaces.
  • Support the operational handling of vulnerability reports and take over selected coordination, communication and decision-making responsibilities when needed.
  • Retest remediated findings and verify whether fixes are complete and effective.
  • Monitor and assess vulnerabilities affecting user device operating systems, hardware key stores and wallet instances.
  • Evaluate the attack potential of newly disclosed OS/key store/chip vulnerabilities and contribute to risk-based decisions on device or wallet usage restrictions where integrity cannot be sufficiently verified.
  • Apply reverse engineering skills (static/dynamic analysis, instrumentation, runtime hooking) to independently validate mobile findings and collaborate with threat hunters on specific mobile investigations.
  • Help internal development teams identify the root cause of security issues, particularly in native mobile code, SDKs and third-party libraries.
  • Work with development teams on sustainable remediation measures that address the underlying cause, not only the individual attack path.

WHAT WE’RE LOOKING FOR:

  • Strong hands-on experience in security testing mobile applications.
  • Strong hands-on experience of reverse engineering mobile applications (iOS and Android),
  • Hands-on experience in security testing of web applications and APIs.
  • Practical understanding of mobile platform security mechanisms: secure enclave/hardware-backed keystores, platform attestation (e.g. Android Key Attestation, iOS DeviceCheck/App Attest).
  • Strong knowledge of common vulnerability classes affecting mobile, web and API environments.
  • Good understanding of secure development lifecycle practices and how security findings can be translated into engineering action.
  • Ability to analyze technical findings precisely and explain them clearly to different stakeholders.
  • Strong written and verbal communication skills in English, especially in discussions with development teams and external researchers.
  • Sound judgment and the ability to make risk- and impact-based decisions, including under time pressure.
  • Structured and reliable way of working, including clear documentation and consistent follow-up.

NICE TO HAVE:

  • Direct experience working with bug bounty or vulnerability disclosure programs.
  • Familiarity with common severity rating approaches such as CVSS and with risk-based vulnerability prioritization.
  • Experience supporting remediation in agile or product-oriented engineering environments.
  • Prior exposure to threat hunting methodology or mobile threat intelligence feeds.
  • Experience with digital identity, wallet or credential systems (e.g. OpenID4VCI, mDL/mDoc, eIDAS) and their mobile security implications.
  • Understanding of modern authentication and authorization patterns in API-centric systems.
  • Degree in information security, computer science, cybersecurity or a related field, or equivalent practical experience.
  • Working understanding of the German language.

WHAT WE OFFER:

  • A chance to shape one of Germany’s most important digital public infrastructures
  • A forward-thinking, mission-driven work culture at the intersection of science, administration, and innovation
  • Flexible working hours and remote work from Germany
  • Competitive compensation commensurate with the level of responsibility
  • Access to conferences, team events and a supportive work culture.

We look forward to receiving your application via our application form.

Jetzt bewerben

Please fill out the following form to apply for the advertised position. All fields marked with * are required.

Keine Datei ausgewählt
Please upload a maximum of three documents. Due to server limitations, the upload may take up to 30 seconds.

Disclosure of severe disability


Consent to be contacted again regarding other job openings at SPRIND ("talent pool")

Note: However, we ask that you refrain from providing information such as ethnic origin or union membership as part of your application.


Notes

The declaration of my consent is voluntary. I can refuse it without giving reasons and without having to fear any disadvantages.
My above consent is valid until I revoke it. I can declare this revocation in writing or by e-mail at any later time without giving reasons (personal@sprind.org).
Furthermore, I am entitled to the other rights set out in the Privacy Notice of SPRIND.
The revocation of consent shall not affect the lawfulness of processing based on consent before its revocation. If there is another legal basis for the further processing of my data, SPRIND is authorized to do so. Otherwise, my data will be deleted if I revoke my consent.