Source description
About the role
Position Purpose: The purpose of the position is to help with the security testing activities mentioned in the direct responsibilities. Role & responsibilities To perform Penetration testing (Gray Box and/or Black Box) for Web applications, Mobile, API, and thick client applications. Hands-on mobile penetration tester with strong knowledge and experience in Android and iOS application security testing (both static and dynamic), responsible for discovering, validating and reporting security issues in mobile applications. Perform Static analysis (SAST) and Dynamic analysis (DAST) on Android APKs and iOS IPA to identify insecure storage, hardcoded secrets, insecure configurations, runtime hooking, parameter tampering etc Conduct reverse engineering and protection bypass on mobile applications including decompiling /inspecting binaries, analyzing native libraries (.so/.dylib) and by passing client-side protections (root / jailbreak detection, SSL pinning, obfuscation, tamper checks etc.) using tools like Frida, objection magisk, cydia/selio/zebra and Xposed. Strong research knowledge and should be updated with evolving mobile threats and industry standard (OWASP MASVS/MASTG) Clear understanding of OWASP Top 10 - application security risks Tools/OS: Burp Suite, OWASP ZAP, Kali Linux, mobsf, jadx, dex2jar, adb, xcode, Frida, objection, apktool, putil, otool. Manual Security Testing & Analysis, Security Test Designing Preferred candidate profile Preferrence give to Immediate joiners Maximum 15 Days notice period .
More at BCT CONSULTING INC