Senior Penetration Tester – Mobile Apps (Android/iOS) and POS
Key Responsibilities:
- Conduct high-quality, non-disruptive penetration testing on mobile applications (Android/iOS) and POS software/devices.
- Design attack scenarios, execute security tests, and assess API/web service security.
- Identify, document, and rank vulnerabilities; provide actionable remediation guidance.
- Compile clear, concise technical reports and communicate findings to developers and management.
- Collaborate with SDLC security initiatives; contribute to secure coding practices and security controls.
- Perform retesting after remediation to verify closure.
- Stay current with evolving threats, tools, and techniques in mobile security.
- Integrate threat intelligence and threat modeling practices into assessment work to enhance risk understanding.
- Align testing approaches with MITRE ATTACK framework for mobile and POS contexts.
Must-Have Skills and Experience:
- 5+ years of hands-on penetration testing and security assessment experience.
- Deep expertise in mobile app security (Android/iOS): Java/Kotlin, Swift/Objective-C; secure coding concepts and mobile threat modeling.
- Proficiency with mobile testing tools (e.g., MobSF, Burp Suite, OWASP ZAP, Frida, Xposed).
- Experience testing POS/payments devices and related architectures; knowledge of payment protocols and PCI considerations.
- Strong API/security concepts: JWT/OAuth, encryption, key management, threat modeling.
- Excellent reporting skills; ability to communicate risk and remediation to both technical and non-technical stakeholders.
- English proficiency for reading documentation and presenting findings.
- Relevant certifications (e.g., CISSP, OSCP/OSWP, CEH) or equivalent practical experience.
Saturday to Wednesday, 8:00 to 17:00
Social Security Insurance and supplementary
city center