30 Sep
|
Confidential
|
Mumbai
30 Sep
Confidential
Mumbai
About the Role We are looking for an experienced
Mobile Security Engineer
to design, implement, and strengthen security mechanisms for enterprise Android applications and
mobile device management
(MDM) environments. The role will focus on
Android application security, cryptography, secure communications, device identity, PKI, authentication, data protection, and application hardening .
Key Responsibilities Design and implement security mechanisms for Android applications and MDM environments. Apply
cryptographic techniques
for encryption, digital signatures, key exchange, hashing, and secure key management. Design and maintain
PKI and certificate lifecycle management , including certificate issuance, renewal, rotation, and revocation. Implement secure device-to-server communication using
TLS, mutual TLS, certificates, and secure authentication . Work with
Android Keystore, KeyMint, StrongBox, hardware-backed keys, and Key Attestation . Secure sensitive data, credentials, tokens, encryption keys, and device information. Secure Android application components, IPC/Binder, permissions, Services, Broadcast Receivers, Content Providers, and exported components. Implement application hardening, including
tamper detection, anti-debugging, certificate pinning, obfuscation, and secure configuration . Secure MDM device enrollment, provisioning, registration, authentication, and device lifecycle processes. Conduct security reviews, threat modelling, vulnerability assessments, and penetration-testing support. Review APIs and communication mechanisms between Android clients, MDM platforms, and backend services. Identify and remediate mobile application and device-security vulnerabilities.
Work closely with Android, backend, DevOps, QA, and security teams to implement secure development practices. Define security standards and guidelines for Android and MDM development.
Required Skills 8+ years of experience in
mobile security, Android security, application security, cybersecurity, or related fields . Strong hands-on experience with
Android application security and Android security architecture . Strong understanding of
cryptography , including AES, RSA, ECC/ECDSA/ECDH, SHA-2/SHA-3, HMAC, digital signatures, and key management. Strong knowledge of
PKI, X.509 certificates, certificate chains, CRL/OCSP, TLS, and mutual TLS . Hands-on experience with
Android Keystore / KeyMint / StrongBox / Key Attestation . Experience with
Android Enterprise, Device Owner, Profile Owner, Work Profile, or MDM/UEM/EMM platforms . Robust understanding of Android permissions, IPC/Binder, Services, Broadcast Receivers, Content Providers, and application components. Experience with mobile application hardening, reverse engineering, vulnerability assessment, or penetration testing. Good knowledge of
secure boot, Verified Boot, TEE, and hardware-backed security . Experience with Java/Kotlin and Android SDK.
Preferred Skills: Experience with
OWASP MASVS / MSTG . Experience with
MobSF, Frida, Burp Suite, JADX, Ghidra, or ADB . Experience with HSMs or hardware security modules. Knowledge of FIPS 140-3 or Common Criteria. C/C++ and native Android security experience. Experience securing APIs and cloud-based services.
Education Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, Computer Engineering, or a related field.
📌 Mobile Security Engineer (Mumbai)
🏢 Confidential
📍 Mumbai