Android Penetration Tester

The Fountain Group
Mountain View, CA, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$135,200.0 - $145,600.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Android Software Development Software System Penetration Testing Cyber Security Firmware White-Box Testing Information Security Management Python (Programming Language) Cloud Services Phishing Reverse Engineering Web Applications
+5 more
Malware Cyber Threat Analysis Vulnerability Analysis Web Api Programming Languages

Job description

  • This role is focused on Pen Testing for Mobile Application + Android APK Level. Previous interviews have been too focused on web applications and missing the Android piece.
  • Hybrid role - 3 days onsite.
  • Should be able to read and understand Java & Python, as Java is the native language of Android.

Responsibilites

  • Develop expertise in our product solutions, deep diving into design/architecture, & execute white box and black box penetration scenarios.
  • Plan, scope and conduct vulnerability assessment/ Penetration test on internal / external facing public assets such as Web application, Android platform, Android Apps, Backend APIs, and Cloud services.
  • Research & and conduct adversary simulation for known security threats and identify Client attack vectors to test a system’s relative security readiness.
  • Conduct Threat modelling, Threat Intelligence and scoping with stakeholders.
  • Assist in creating and maintaining internal penetration testing and practice within QA team, managing vulnerabilities and tracking until closure.
  • Build Test harness & required Automation suites and validate attack vectors in Threat Lab.
  • Co-ordinate with program management, security architects at Internal & offshore sites.
  • Stays up to date on current tools, technologies, and vulnerabilities to incorporate into testing practices.
  • Research and developing exploits for zero-day vulnerabilities.
  • Conduct penetration test on IOT and Firmware Devices.

Requirements

  • 5+ years’ experience in Penetration testing, including 2+ year experience in Android and 1+ year experience in Web Application.
  • Degree in Cyber Security or Security relevant disciplines is a plus.
  • Certifications in offensive security: OSCP or OSWA or OSWE or CRTO or BSCP or similar is a plus.
  • Comprehensive knowledge in Information Security practices on malware, phishing attacks, attack vectors and methods to protect against threats.
  • Knowledge in Java, python or any relevant programming language.
  • Malware development or reverse engineering experience is a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thefountaingroup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

9:56 min

Expanding browser capabilities with modern web APIs

Ire Aderinokun · JS Congress

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

4:15 min

Scaling DevSecOps and researching mobile application security standards

Moataz Nabil Moataz Nabil · LIVE

7:44 min

Bootstrapping a test-driven asp.net web api

Alex Banul · LIVE

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

Videos

See all

Related articles

See all