03 Aug
|
D ASPIRE
|
India
Job Description – Security Engineer (Mobile VAPT, Source Code Review & Web Application Security)
Job Title: Security Engineer – Mobile VAPT, Source Code Review & Web Application Security
Experience: 1+ Years (Hands-on Experience Required)
Employment Type: Full-Time
Location: (As per company requirement)
About the Role
We are seeking a highly skilled and execution-focused Security Engineer with expertise in Mobile Application VAPT (Android/iOS), Web & API Security Testing, and Secure Source Code Review. The ideal candidate should have strong hands-on penetration testing skills, the ability to identify and exploit real-world vulnerabilities, and deliver consulting-quality security assessment reports.
Key Responsibilities
- Perform Mobile Application VAPT (Android & iOS) using industry-standard methodologies.
- Conduct Web Application & API Security Assessments, including business logic testing.
- Perform Secure Source Code Reviews for Java, Kotlin, Swift, and Objective-C applications.
- Identify vulnerabilities based on OWASP Mobile Top 10 and OWASP Top 10 standards.
- Execute advanced security testing including:
- Reverse Engineering
- SSL Pinning Bypass
- Runtime Manipulation (Frida)
- Authentication & Authorization Testing
- IDOR, SSRF & Injection Vulnerabilities
- Business Logic Testing
- Identification of insecure coding practices and hardcoded secrets
- API exploitation and security bypass techniques
- APK/IPA decompilation and code analysis
- App Sandboxing, Keychain Security, Entitlements & Plist Configuration Review
- Prepare professional, audit-ready VAPT reports including:
- Proof of Concept (PoC)
- CVSS Risk Rating
- Detailed Remediation Recommendations
- Participate in peer reviews and internal quality assurance processes.
- Support clients during vulnerability walkthroughs and remediation validation.
- Deliver end-to-end VAPT engagements independently while maintaining consulting-quality standards.
Required Qualifications
- Bachelor's Degree in Computer Science, Information Security, Cyber Security, IT, or a related field.
- Minimum 1+ year of hands-on VAPT experience (Internships will not be considered).
- Strong understanding of Android & iOS security architecture.
- Practical experience in Web Application & API Security Testing.
- Hands-on experience in manual penetration testing and real-world exploitation techniques.
- Experience conducting Secure Source Code Reviews.
- Excellent analytical, troubleshooting, and reporting skills.
Technical Skills
- Mobile Application Penetration Testing (Android & iOS)
- Web Application & API Security Testing
- Secure Source Code Review
- OWASP Mobile Top 10
- OWASP Top 10
- Business Logic Testing
- Reverse Engineering
- Runtime Instrumentation
- SSL Pinning Bypass
- Vulnerability Assessment & Penetration Testing (VAPT)
- CVSS Risk Assessment
- Security Documentation & Reporting
Preferred Skills
- Hands-on experience with:
- Burp Suite
- MobSF
- Frida
- JADX
- APKTool
- Experience bypassing modern application security controls.
- Exposure to client-facing cybersecurity consulting engagements.
- Relevant cybersecurity certifications (CEH, eJPT, OSCP, Mobile Security, etc.) are an added advantage.
What We Expect
- High-quality, consulting-level security assessments.
- Ability to independently execute complete VAPT engagements.
- Solid focus on technical accuracy and reproducible findings.
- Excellent communication and documentation skills.
- Professional attitude and commitment to continuous learning.
Pay: ₹20,000.00 - ₹25,000.00 per month
Benefits:
- Flexible schedule
Work Location: In person
📌 Security Engineer (Mobile VAPT, Source Code Review & Web Application Security) (India)
🏢 D ASPIRE
📍 India