Posted:
2/26/2026, 8:13:51 PM
Location(s):
Staines-upon-Thames, England, United Kingdom ⋅ England, United Kingdom
Experience Level(s):
Junior ⋅ Mid Level ⋅ Senior
Field(s):
IT & Security ⋅ Software Engineering
Position Summary
We have an opportunity available for Security Engineer to join us on a 12 month contract basis here at Samsung Research UK.Role and Responsibilities
Producing security assessments and generating evidence reports for Samsung Galaxy applications as per acceptance requirements set by the government agencies. The security assessment task includes testing applications in line with well-known industry standards including: OWASP MASVS testing, threat modelling, tool relating to data flow analysis within the device and to the network; static and dynamic testing using tools such as MobSF, Frida, Jadx, cve-gin-tool and others for application risk assessment. These tasks may also require development of necessary tools for testing and hence development experience with programming languages such as Python is essential.
Support Samsung partners and customers to build solutions based on Samsung Knox platform and Knox service infrastructure. This task includes development experience with front-end and back-end and web services using the latest IDE and tool chains.
Depending upon needs, support Android and smartcard applications and mobile platform framework development tasks, in particular being responsible for functional specifications, requirements, design documentation along with supporting implementation and deployment, as necessary.
Development of tools to enable solution installation, provisioning and approval.
Creation of necessary documentation as per requirements to support approval of the solution including solution design and deployment guide documents.
Coordination between internal and external stakeholders throughout the process and to support the product roadmap and strategy.
Create necessary process documents to share with business stakeholders.
Create necessary documents to describe issues encountered in an effective manner to get the right support from development teams.
Travel as required, including to attend meetings with customers and partners.
Timely provision of written progress reports to management and others, as required.
All work is to be of a professional standard, paying due regard to safety, efficiency, cost effectiveness, time scales and the needs of the company.
Skills and Qualifications
Essential:
A degree in Computing and Communications or any related discipline (an equivalent period of industrial experience may be substituted).
Experience with application testing using various methods and tools including OWASP MASVS, MobfSF, Frida and tools to conduct static and dynamic testing.
Knowledge of various device security attack vectors including apps, browsers, connectivity, device management, networking, local storage. etc.
Knowledge of C, C++ and Java programming languages (at least 3 years’ experience). This experience is necessary to understand existing code and write test code to verify security requirements.
Experience in development of Java Cryptography Extension (JCE) provider for Android KeyStore.
Familiarity with PKI, certificate enrolment, Public Key Cryptography Standards (PKCS #)
Documentation skills required for creating high quality technical, process and day-to-day documents including use of MS Word and PowerPoint.
A high degree of self-motivation, and a proactive approach to problem resolution.
A good level of inter-personal and communication skills.
Desirable:
Experience with
Global Platform Card Specification 2.3 and amendments A, C, D, E, F, ISO 7816 smart card standard, NFC and ETSI 102 705 APIs.
Experience with the development of smart card-based Android applications including the necessary SDK. Hands-on experience with Javacard API, crypto engines and crypto libraries.
Front-end and back-end and Web Services development and hence experience with Javascript, Python and the latest IDE and toolchain is desirable.
Defining security concepts, requirements and security architecture.
Applying security-by-design principles.
Secure mobile platform development.
Mobile device security features including device lock and data encryption.
Common criteria certification of security-critical software including CC, FIPS, VS-NfD, etc.
Samsung has a strict policy on trade secrets. In applying to Samsung and progressing through the recruitment process, you must not disclose any trade secrets of a previous employer.
* Please visit Samsung membership to see Privacy Policy, which defaults according to your location, at: https://account.samsung.com/membership/policy/privacy. You can change Country/Language at the bottom of the page. If you are European Economic Resident, please click here: https://europe-samsung.com/ghrp/PrivacyNoticeforEU.html
Website: https://www.samsung.com/
Headquarter Location: Suwon, Ch'ungch'ong-namdo, South Korea
Employee Count: 10001+
Year Founded: 1973
IPO Status: Private
Industries: Automotive ⋅ Electronics ⋅ Manufacturing