Назад
Company hidden
3 дня назад

Security Consultant II (Mobile Application Penetration Tester)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Consultant II (Mobile Application Penetration Tester) (Mobile Security/Android/iOS): Conducting penetration tests of mobile applications and underlying APIs, identifying vulnerabilities, and delivering actionable client reports with an accent on insecure data storage, communications, cryptography, and application protections. Focus on developing Frida tools, researching offensive testing techniques, analyzing mobile operating systems, and performing ARM reverse engineering.

Location: Remote - US; occasional travel of 5–10% required.

Company

hirify.global provides penetration testing as a service, attack surface management, and vulnerability prioritization supported by security professionals, AI, and automation.

What you will do

  • Conduct penetration testing engagements for mobile applications and underlying APIs.
  • Identify insecure data storage, communications, cryptography, and application protections.
  • Create, deliver, and collaborate on penetration testing reports across diverse client environments.
  • Research and develop testing techniques, tools, and methodologies.
  • Complete administrative tasks supporting consulting engagements and business operations.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Math, or IT, or equivalent experience.
  • 2–3 years of experience in mobile application penetration testing.
  • Experience with tools such as Kali Linux, Burp Suite, Frida, Drozer, Objection, and Ghidra.
  • Experience developing Frida tools to bypass application protections or exploit vulnerabilities.
  • Knowledge of Android and iOS, mobile application security, communications, sandboxes, OWASP Top 10, and security frameworks.
  • Ability to work independently and collaboratively during an 8-hour workday, with occasional evenings or weekends for project deadlines or critical needs.

Nice to have

  • Experience mentoring team members or sharing knowledge through blogs, webinars, or conferences.
  • Experience with Ruby, Python, Perl, C, C++, Java, or C#.
  • Offensive cybersecurity certifications such as GXPN, GPEN, OSCP, CISSP, or GWAPT.
  • Experience in ARM reverse engineering.

Culture & Benefits

  • Collaborative, innovative, and customer-focused working environment.
  • Work supporting clients across diverse security assessment environments.
  • Remote work arrangement within the United States.
  • Opportunities to contribute to security best practices and innovative testing methodologies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →