3 дня назад
Security Consultant II (Mobile Application Penetration Tester)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Consultant II (Mobile Application Penetration Tester) (Mobile Security/Android/iOS): Conducting penetration tests of mobile applications and underlying APIs, identifying vulnerabilities, and delivering actionable client reports with an accent on insecure data storage, communications, cryptography, and application protections. Focus on developing Frida tools, researching offensive testing techniques, analyzing mobile operating systems, and performing ARM reverse engineering.
Location: Remote - US; occasional travel of 5–10% required.
Company
provides penetration testing as a service, attack surface management, and vulnerability prioritization supported by security professionals, AI, and automation.
What you will do
- Conduct penetration testing engagements for mobile applications and underlying APIs.
- Identify insecure data storage, communications, cryptography, and application protections.
- Create, deliver, and collaborate on penetration testing reports across diverse client environments.
- Research and develop testing techniques, tools, and methodologies.
- Complete administrative tasks supporting consulting engagements and business operations.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Math, or IT, or equivalent experience.
- 2–3 years of experience in mobile application penetration testing.
- Experience with tools such as Kali Linux, Burp Suite, Frida, Drozer, Objection, and Ghidra.
- Experience developing Frida tools to bypass application protections or exploit vulnerabilities.
- Knowledge of Android and iOS, mobile application security, communications, sandboxes, OWASP Top 10, and security frameworks.
- Ability to work independently and collaboratively during an 8-hour workday, with occasional evenings or weekends for project deadlines or critical needs.
Nice to have
- Experience mentoring team members or sharing knowledge through blogs, webinars, or conferences.
- Experience with Ruby, Python, Perl, C, C++, Java, or C#.
- Offensive cybersecurity certifications such as GXPN, GPEN, OSCP, CISSP, or GWAPT.
- Experience in ARM reverse engineering.
Culture & Benefits
- Collaborative, innovative, and customer-focused working environment.
- Work supporting clients across diverse security assessment environments.
- Remote work arrangement within the United States.
- Opportunities to contribute to security best practices and innovative testing methodologies.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Penetration Tester (iGaming)
5 дней назад
Senior Application Security Engineer (Red Team) (Fintech)
200 000 - 240 000$
4 дня назад
Senior Application Security Engineer (Red Team)
170 000 - 225 000$
CrowdStrike
10 дней назад
Red Team Services Consultant (Cybersecurity)
95 000 - 140 000$
4 дня назад
Summer Associate Internship (Penetration Testing)
26 - 44$
Системная безопасность
4 дня назад
Эксперт по анализу защищенности компьютерных систем и сетей (руководитель группы анализа защищенности)
230 000₽