Security Analyst - Mobile
Key Responsibilities
The Senior Security Consultant – Mobile Application Security Testing will be responsible for leading and executing advanced security assessments of Android, iOS, and hybrid mobile applications. The role requires strong hands-on experience in mobile application penetration testing, mobile platform security, API security, and secure mobile application architecture reviews.
The consultant will conduct comprehensive manual security testing, identify security vulnerabilities, assess business impact, provide remediation guidance, and mentor junior team members.
- Lead and execute advanced Android and iOS application security assessments.
- Perform black-box, gray-box, and white-box mobile application penetration testing.
- Conduct static and dynamic security assessments of mobile applications.
- Perform reverse engineering and binary analysis of mobile applications.
- Assess mobile application APIs and backend services.
- Evaluate authentication, authorization, session management, cryptographic controls, and data protection mechanisms.
- Identify vulnerabilities, validate exploitability, and assess business impact.
- Assess mobile applications against OWASP Mobile Top 10 and MASVS requirements.
- Analyze application communication channels and API interactions.
- Review application architecture and mobile security controls.
- Conduct secure code review for mobile applications where required.
- Validate remediation activities and perform retesting.
- Prepare detailed technical reports and executive summaries.
- Present findings and recommendations to technical and management stakeholders.
- Mentor junior consultants and conduct peer reviews of assessment reports.
- Contribute to mobile security research, testing methodologies, and tool development.
Key Skills
- Strong experience testing both Android and iOS applications.
- Extensive knowledge of
o OWASP Mobile Top 10
o OWASP MASVS
o OWASP MSTG
o Mobile threat modeling concepts
- Experience identifying vulnerabilities including
o Insecure Data Storage
o Weak Authentication
o Broken Authorization
o Insecure Communication
o Improper Certificate Validation
o SSL Pinning Bypass
o Reverse Engineering Weaknesses
o Code Tampering Risks
o Cryptographic Weaknesses
o Runtime Manipulation Risks
o API Security Vulnerabilities
Key Competencies
Accountability
Communications - Oral & Written
Analysis Skills
Passion
Adaptability
Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →