114 Shashwath Solution Jobs
Mobile Application Penetration Tester ( Pentest )
Shashwath Solution
posted 30min ago
Key skills for the job
Job Description:
We are seeking an experienced and highly skilled Penetration Tester with expertise in mobile application security, specifically for both Android and iOS platforms. As a Senior Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in mobile applications, networks, APIs, and other critical systems. Your primary responsibility will be performing thorough security assessments, including reverse engineering, malware analysis, and incident forensics, to ensure the security and resilience of mobile applications and systems.
The ideal candidate should have hands-on experience with penetration testing tools, mobile application testing, and advanced exploitation techniques. You will also be expected to collaborate with various teams, including Red Teams, to develop strategic security initiatives and offer expert-level recommendations for security improvements.
Key Responsibilities:
Mobile Application Penetration Testing: Conduct in-depth security assessments of mobile applications for both Android and iOS platforms, identifying vulnerabilities and recommending remediation strategies.
Red Team Activities: Participate in Red Team exercises to simulate real-world attacks, uncover hidden threats, and assess the effectiveness of security controls.
Security Assessments: Perform penetration testing on applications, networks, mobile platforms, APIs, cloud environments, and critical systems to identify advanced threats and vulnerabilities.
Custom Exploit Development: Develop custom exploit code and scripts to demonstrate potential security risks to stakeholders and stakeholders, providing hands-on demonstrations of vulnerabilities.
Reverse Engineering & Malware Analysis: Use reverse engineering techniques and tools to analyze complex threats, malware, and incidents, providing detailed reports on findings.
Collaboration with Leadership: Collaborate with executive leadership and senior management to develop and execute strategic security initiatives and roadmaps to mitigate security risks.
Security Architecture Guidance: Provide expert-level guidance on secure coding practices, cryptography, architecture design principles, and implementation to mitigate risks effectively.
Tool Development & Automation: Develop custom penetration testing tools and scripts to automate testing processes and enhance capabilities for thorough assessments.
Incident Forensics: Lead efforts to analyze and investigate security incidents, determining the root causes and recommending improvements for better prevention.
Required Skills and Qualifications:
Mobile Pen Testing Expertise: Strong experience in mobile application penetration testing for both Android and iOS platforms.
Penetration Testing Tools: Expertise in tools and frameworks such as Metasploit, Burp Suite, Nessus, NMAP, and custom/open-source tools.
Red Teaming & Advanced Exploitation: Advanced proficiency in red teaming, black box testing, and using advanced exploitation techniques to identify vulnerabilities.
Malware Analysis & Reverse Engineering: Experience in malware analysis and reverse engineering to assess complex threats and incidents.
Cryptography & Secure Coding: In-depth knowledge of cryptography, secure coding practices, and secure architecture design principles.
Custom Tools & Scripting: Hands-on experience in developing custom scripts and tools to automate testing processes and enhance the effectiveness of assessments.
Penetration Testing Methodologies: Expertise in applying penetration testing methodologies, including both network and application-level security assessments.
Certifications (Preferred):
o OSCP (Offensive Security Certified Professional)
o CRTP (Certified Red Team Professional)
o eLearn Security Certified Professional Penetration Tester V2.0
o Any other relevant certifications are a plus.
Required Experience:
Overall Experience: 12+ years in penetration testing, security assessments, and threat analysis.
Relevant Experience: 10 years of hands-on experience specifically in penetration testing for mobile applications (Android & iOS), network security, cloud environments, and APIs.
Experience working in Red Team environments is a plus.
Employment Type: Full Time, Permanent
Read full job description