Job Description:
We are looking for a seasoned Mobile Application Penetration Tester to join our offensive security team as a Lead Cybersecurity Engineer. The ideal candidate will have deep expertise in iOS and Android application security, strong knowledge of mobile platforms, and hands-on experience with both static and dynamic testing techniques.
Experience Level: 5+ years.
Key Responsibilities:
-
Lead and conduct manual penetration testing of mobile applications (Android/iOS), including client-side, API, and backend integrations.
-
Perform static analysis (SAST) and dynamic analysis (DAST) to uncover security weaknesses, insecure data storage, authentication flaws, and reverse engineering vulnerabilities.
-
Analyze mobile apps for vulnerabilities such as insecure communication, improper platform usage, insecure storage, code tampering, and authentication bypass.
-
Develop and use custom scripts, tools, and techniques to simulate real-world mobile threats.
-
Assess and exploit mobile apps using tools like MobSF, Burp Suite, Frida, Objection, Jadx, Ghidra, Xcode, Android Studio, ADB, Mitmproxy, etc.
-
Reverse engineer APKs and IPAs to find hardcoded secrets or weak crypto implementations.
-
Evaluate mobile API endpoints for common OWASP API vulnerabilities.
-
Collaborate with development and security teams to explain findings, recommend mitigations, and re-test fixes.
-
Stay current on emerging mobile threats, CVEs, and evolving mobile app frameworks and security practices.
Required Skills and Experience:
-
5+ years of experience in cybersecurity with 3+ years in mobile application penetration testing.
-
Strong understanding of OWASP MASVS, OWASP Mobile Top 10, and OWASP API Top 10.
-
Deep understanding of Android internals (APK, Smali, Java/Kotlin) and iOS internals (IPA, Objective-C/Swift).
-
Proficient in static code analysis, certificate pinning bypass, root/jailbreak detection bypass, and runtime manipulation.
-
Experience with Jailbroken iOS and Rooted Android environments.
-
Strong scripting skills in Python, JavaScript, Bash, or PowerShell.
-
Knowledge of CI/CD pipelines and how to integrate mobile app security testing.
To apply for this job email your details to vijay@opencops.com