Mobile Application Penetration Tester
2 weeks ago
Zimperium is an industry leader in enterprise mobile security, being the first and only company to provide a complete mobile threat defense system that offers real-time, on device world-class protection against both known and unknown next generation of advanced mobile cyberattacks and malware.
Our MTD and award-winning machine learning-based engine protects against device, network, phishing and application attacks for IOS, Android and Windows devices, using a non-intrusive approach to always protect privacy of users.
As part of our fast-growing pace, we are currently looking for an experienced Mobile Application Penetration Tester with deep expertise in security assessments of iOS and Android applications. The role requires advanced skills in runtime analysis, exploit development, and Red Team methodologies. You will be responsible for simulating real-world adversarial attacks, uncovering critical vulnerabilities, and working closely with stakeholders to strengthen the security posture of mobile ecosystems.
Key Responsibilities:
- Conduct end-to-end penetration testing of iOS and Android mobile applications, including static, dynamic, and runtime analysis.
- Assess mobile API integrations, authentication mechanisms, encryption protocols, and data storage security.
- Identify and exploit vulnerabilities such as insecure data storage, weak cryptography, insecure communication, jailbreak/root bypasses, insecure code practices, and business logic flaws.
- Use runtime instrumentation frameworks (Frida, Objection, Xposed) for dynamic testing and bypassing protections.
- Perform certificate pinning bypass, hooking, and traffic interception using advanced proxying techniques.
- Evaluate and attempt evasion of mobile app protections such as root/jailbreak detection, code obfuscation, anti-debugging, and tamper protection.
- Develop custom scripts/exploits (Python, Java, Swift, Kotlin, or C++) for advanced testing scenarios.
- Produce comprehensive penetration test reports, including risk ratings, proof-of-concept exploits, and actionable remediation steps.
- Work closely with development and research security teams to embed secure SDLC practices.
Contribute to Red Team exercises by simulating adversarial attacks against mobile endpoints.
Required Skills & Experience:
- 5+ years of experience in penetration testing, with at least 3 years focused on iOS and Android mobile applications.
Strong knowledge of OWASP Mobile Top 10, and NIST mobile security guidelines.
- Expertise in:
Static & Reverse Engineering: Apktool, JADX, Ghidra, Hopper, IDA Pro, Radare2, JD-GUI.
Dynamic & Runtime Testing: Frida, Objection, Cycript, LLDB, Xposed.
Automation/Frameworks: MobSF, Drozer, Appium (for automation-assisted testing).
Proxying & Interception: Burp Suite Pro, OWASP ZAP, MITM tools
- Solid understanding of mobile OS internals (Android security model, iOS security architecture, Keychain, Secure Enclave, sandboxing).
- Hands-on experience with jailbroken iOS and rooted Android devices for advanced exploitation.
Familiarity with cryptography, secure communications (TLS, cert pinning), and secure data storage techniques.
- Ability to think like an attacker and perform creative exploitation beyond automated tool findings.
Preferred Certifications:
OSCP / OSEP / OSED (Offensive Security)
OSWE / OSMR (Offensive Security Web & Mobile certs)
EWPTX / EWAPT (eLearnSecurity)
CRTP / CRTE (Red Team certs)
CEH / CAP / API Security Testing (good to have, but not mandatory if strong hands-on skills)
Zimperium, Inc. is a global leader in mobile device and app security, offering real-time, on-device protection against both known and unknown threats on Android, iOS and Chromebook endpoints. The company was founded under the premise that the then current state of mobile security was insufficient to solve the growing mobile security problem. At the time, most mobile security was a port from traditional endpoint security technologies.Zimperium recognized mobile devices had unique characteristics needing a completely new approach. The team set to work to reimagine how to protect mobile devices and developed the award winning, patented z9 machine learning-based engine.
Zimperium is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.
-
Penetration Tester
6 days ago
Remote, India IICSEH Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Title: Penetration Tester / Application Security EngineerLocation: RemoteExperience: 1-4 yearsDepartment: CybersecurityRole Overview:We are seeking a highly skilled and passionate Penetration Tester with hands-on experience across multiple domains including Web, Network, Mobile, Cloud, Active Directory, and Red Teaming. The ideal candidate should possess...
-
Penetration Tester
7 days ago
Remote, India ICEH Full time**Job Title: Penetration Tester / Application Security Engineer** **Location**: Remote **Experience**: 1-4 years **Department**: Cybersecurity **Role Overview**: You will be responsible for performing deep technical security assessments, identifying vulnerabilities, and helping clients strengthen their security posture through well-documented findings and...
-
Penetration Tester
1 week ago
Remote, India Goodtech Mind Full time ₹ 13,000 - ₹ 7,62,317 per yearAbout the RoleWe are seeking a skilled Penetration Tester / Vulnerability Assessment & Penetration Testing (VAPT) Specialist to join our cybersecurity team. The role involves identifying security vulnerabilities, simulating cyberattacks, and providing actionable insights to strengthen systems, networks, applications, and infrastructure.Key...
-
Penetration Tester
1 week ago
Remote, India procallisto solutions pvt Full time ₹ 6,00,000 - ₹ 12,00,000 per yearThe Web Application Penetration Tester will be responsible for assessing the security posture of client web applications by simulating real-world cyberattacks. You will identify vulnerabilities, exploit weaknesses where necessary, and provide clear, actionable recommendations to strengthen security controls.Key ResponsibilitiesConduct web application...
-
Vapt Tester-remote
2 weeks ago
Remote, India TeamPlus Staffing Solution Pvt Ltd Full timeThe Penetration tester must have CREST accreditation status in order to qualify for the Project. Penetration tester must hold minimum 2 of the following qualifications or equivalent. Offensive Security Certified Professional (OSCP) Certified Information Systems Security Professional (CISSP) Offensive Security Certified Wireless Professional (OSWP) CREST...
-
Mobile Application Tester
2 days ago
Remote, India Technology Next Full time ₹ 96,00,000 per yearMobile Application TesterLocation: Remote (India)Work Hours: 2:00 PM – 11:00 PM IST (3:00 PM – 12:00 AM IST during daylight saving)Experience: 8+ YearsContract: 6 Months (Extendable)About the Role:We're seeking an experienced Mobile App Automation + Manual Tester with strong hands-on expertise in mobile test automation (Android Espresso / iOS XCUITEST)...
-
Mobile Application Tester
2 days ago
Remote, India Tech Next Full time ₹ 9,60,000 per yearMobile Application TesterLocation: Remote (India)Work Hours: 2:00 PM – 11:00 PM IST (3:00 PM – 12:00 AM IST during daylight saving)Experience: 8+ YearsContract: 6 Months (Extendable)About the Role:We're seeking an experienced Mobile App Automation + Manual Tester with strong hands-on expertise in mobile test automation (Android Espresso / iOS XCUITEST)...
-
Penetration Tester
2 weeks ago
Remote, India Agylex-Sprinx Global Full time**Location**:UAE (Relocation Needed) **Duration**: 12 months + 12 months **Position Overview**: **Key Responsibilities**: - Collaborate closely with interdisciplinary teams to analyze and interpret security assessment outcomes, furnishing actionable recommendations for remediation. - Remain abreast of the latest cybersecurity trends, tools, and...
-
Cyber Security Tester
1 day ago
Remote, India Rigelsoft Technologies Full time**Cyber Security - Penetration Tester** Security roles: - Penetration Testers There are multiple headcounts across different levels for this role. If you are a penetration tester looking for your next penetration testing or just cyber security roles in general, feel free to get in touch for a confidential discussion regarding your next career...
-
Cyber Security Tester
2 weeks ago
Remote, India Rigelsoft Technologies Full time**Cyber Security - Penetration Tester** Security roles: - Penetration Testers There are multiple headcounts across different levels for this role. If you are a penetration tester looking for your next penetration testing or just cyber security roles in general, feel free to get in touch for a confidential discussion regarding your next career...