> Markdown version of [/jobs/ext/1442320-android-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1442320-android-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Android Penetration Tester - **Company:** The Fountain Group - **Location:** Mountain View, CA, United States - **Salary:** $135,200.0 - $145,600.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Android Software Development, Software System Penetration Testing, Cyber Security, Firmware, White-Box Testing, Information Security Management, Python (Programming Language), Cloud Services, Phishing, Reverse Engineering, Web Applications, Malware, Cyber Threat Analysis, Vulnerability Analysis, Web Api, Programming Languages - **Published:** July 25, 2026 - **Apply:** https://www.thefountaingroup.com/job/10957/android_penetration_tester#apply-now-header ## About the Role * 5+ years' experience in Penetration testing, including 2+ year experience in Android and 1+ year experience in Web Application. * Degree in Cyber Security or Security relevant disciplines is a plus. * Certifications in offensive security: OSCP or OSWA or OSWE or CRTO or BSCP or similar is a plus. * Comprehensive knowledge in Information Security practices on malware, phishing attacks, attack vectors and methods to protect against threats. * Knowledge in Java, python or any relevant programming language. * Malware development or reverse engineering experience is a plus. ## Description * This role is focused on Pen Testing for Mobile Application + Android APK Level. Previous interviews have been too focused on web applications and missing the Android piece. * Hybrid role - 3 days onsite. * Should be able to read and understand Java & Python, as Java is the native language of Android. Responsibilites * Develop expertise in our product solutions, deep diving into design/architecture, & execute white box and black box penetration scenarios. * Plan, scope and conduct vulnerability assessment/ Penetration test on internal / external facing public assets such as Web application, Android platform, Android Apps, Backend APIs, and Cloud services. * Research & and conduct adversary simulation for known security threats and identify Client attack vectors to test a system's relative security readiness. * Conduct Threat modelling, Threat Intelligence and scoping with stakeholders. * Assist in creating and maintaining internal penetration testing and practice within QA team, managing vulnerabilities and tracking until closure. * Build Test harness & required Automation suites and validate attack vectors in Threat Lab. * Co-ordinate with program management, security architects at Internal & offshore sites. * Stays up to date on current tools, technologies, and vulnerabilities to incorporate into testing practices. * Research and developing exploits for zero-day vulnerabilities. * Conduct penetration test on IOT and Firmware Devices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [93 Java Interview Questions You Should Prepare For](https://www.wearedevelopers.com/magazine/14-93-java-interview-questions-you-should-prepare-for)