• Full Time
  • Anywhere

Job Description:

We are looking for a seasoned Mobile Application Penetration Tester to join our offensive security team as a Lead Cybersecurity Engineer. The ideal candidate will have deep expertise in iOS and Android application security, strong knowledge of mobile platforms, and hands-on experience with both static and dynamic testing techniques.

Experience Level: 5+ years.

Key Responsibilities:

  • Lead and conduct manual penetration testing of mobile applications (Android/iOS), including client-side, API, and backend integrations.

  • Perform static analysis (SAST) and dynamic analysis (DAST) to uncover security weaknesses, insecure data storage, authentication flaws, and reverse engineering vulnerabilities.

  • Analyze mobile apps for vulnerabilities such as insecure communication, improper platform usage, insecure storage, code tampering, and authentication bypass.

  • Develop and use custom scripts, tools, and techniques to simulate real-world mobile threats.

  • Assess and exploit mobile apps using tools like MobSF, Burp Suite, Frida, Objection, Jadx, Ghidra, Xcode, Android Studio, ADB, Mitmproxy, etc.

  • Reverse engineer APKs and IPAs to find hardcoded secrets or weak crypto implementations.

  • Evaluate mobile API endpoints for common OWASP API vulnerabilities.

  • Collaborate with development and security teams to explain findings, recommend mitigations, and re-test fixes.

  • Stay current on emerging mobile threats, CVEs, and evolving mobile app frameworks and security practices.

Required Skills and Experience:

  • 5+ years of experience in cybersecurity with 3+ years in mobile application penetration testing.

  • Strong understanding of OWASP MASVS, OWASP Mobile Top 10, and OWASP API Top 10.

  • Deep understanding of Android internals (APK, Smali, Java/Kotlin) and iOS internals (IPA, Objective-C/Swift).

  • Proficient in static code analysis, certificate pinning bypass, root/jailbreak detection bypass, and runtime manipulation.

  • Experience with Jailbroken iOS and Rooted Android environments.

  • Strong scripting skills in Python, JavaScript, Bash, or PowerShell.

  • Knowledge of CI/CD pipelines and how to integrate mobile app security testing.

To apply for this job email your details to vijay@opencops.com