Mobile Application Penetration Tester

4 days ago


India Zimperium Full time US$ 90,000 - US$ 1,20,000 per year

Zimperium is an industry leader in enterprise mobile security, being the first and only company to provide a complete mobile threat defense system that offers real-time, on device world-class protection against both known and unknown next generation of advanced mobile cyberattacks and malware.

Our MTD and award-winning machine learning-based engine protects against device, network, phishing and application attacks for IOS, Android and Windows devices, using a non-intrusive approach to always protect privacy of users.

As part of our fast-growing pace, we are currently looking for an experienced Mobile Application Penetration Tester with deep expertise in security assessments of iOS and Android applications. The role requires advanced skills in runtime analysis, exploit development, and Red Team methodologies. You will be responsible for simulating real-world adversarial attacks, uncovering critical vulnerabilities, and working closely with stakeholders to strengthen the security posture of mobile ecosystems.

Key Responsibilities:

- Conduct end-to-end penetration testing of iOS and Android mobile applications, including static, dynamic, and runtime analysis.

- Assess mobile API integrations, authentication mechanisms, encryption protocols, and data storage security.

- Identify and exploit vulnerabilities such as insecure data storage, weak cryptography, insecure communication, jailbreak/root bypasses, insecure code practices, and business logic flaws.

- Use runtime instrumentation frameworks (Frida, Objection, Xposed) for dynamic testing and bypassing protections.

- Perform certificate pinning bypass, hooking, and traffic interception using advanced proxying techniques.

- Evaluate and attempt evasion of mobile app protections such as root/jailbreak detection, code obfuscation, anti-debugging, and tamper protection.

- Develop custom scripts/exploits (Python, Java, Swift, Kotlin, or C ) for advanced testing scenarios.

- Produce comprehensive penetration test reports, including risk ratings, proof-of-concept exploits, and actionable remediation steps.

- Work closely with development and research security teams to embed secure SDLC practices.

Contribute to Red Team exercises by simulating adversarial attacks against mobile endpoints.

Required Skills & Experience:

- 5 years of experience in penetration testing, with at least 3 years focused on iOS and Android mobile applications.

Strong knowledge of OWASP Mobile Top 10, and NIST mobile security guidelines.

- Expertise in:

Static & Reverse Engineering: Apktool, JADX, Ghidra, Hopper, IDA Pro, Radare2, JD-GUI.

Dynamic & Runtime Testing: Frida, Objection, Cycript, LLDB, Xposed.

Automation/Frameworks: MobSF, Drozer, Appium (for automation-assisted testing).

Proxying & Interception: Burp Suite Pro, OWASP ZAP, MITM tools

- Solid understanding of mobile OS internals (Android security model, iOS security architecture, Keychain, Secure Enclave, sandboxing).

- Hands-on experience with jailbroken iOS and rooted Android devices for advanced exploitation.

Familiarity with cryptography, secure communications (TLS, cert pinning), and secure data storage techniques.

- Ability to think like an attacker and perform creative exploitation beyond automated tool findings.

Preferred Certifications:

OSCP / OSEP / OSED (Offensive Security)

OSWE / OSMR (Offensive Security Web & Mobile certs)

EWPTX / EWAPT (eLearnSecurity)

CRTP / CRTE (Red Team certs)

CEH / CAP / API Security Testing (good to have, but not mandatory if strong hands-on skills)

Zimperium, Inc. is a global leader in mobile device and app security, offering real-time, on-device protection against both known and unknown threats on Android, iOS and Chromebook endpoints. The company was founded under the premise that the then current state of mobile security was insufficient to solve the growing mobile security problem. At the time, most mobile security was a port from traditional endpoint security technologies.Zimperium recognized mobile devices had unique characteristics needing a completely new approach. The team set to work to reimagine how to protect mobile devices and developed the award winning, patented z9 machine learning-based engine.

Zimperium is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.


  • Penetration Tester

    1 week ago


    India CIEL HR Full time

    Job Summary **ROLE**:.penetration tester **Experience**: 3 - 7 Years **Location**: Chennai Work Location - DLF, Chennai - Work from Office Alternative saturday working **Security Test Engineer**: Understand the non-functional requirements from business. Experience in Analyzing and identifying the vulnerabilities manually. Experience in Web Application...


  • India Delta System & Software, Inc. Full time

    Job Title: Lead Penetration Tester Location: India (Remote - Travel to Office Once a Month) Job Type: Full-Time Industry: Cybersecurity / Information Technology Work Hours: Standard IST hours Travel: Once a month to client/office location (as required) About the Role: We are seeking an experienced and highly skilled Lead Penetration...


  • India Delta System & Software, Inc. Full time

    Job Title: Lead Penetration Tester Location: India (Remote - Travel to Office Once a Month) Job Type: Full-Time Industry: Cybersecurity / Information Technology Work Hours: Standard IST hours Travel: Once a month to client/office location (as required) About the Role: We are seeking an experienced and highly skilled Lead Penetration...


  • India WTW Full time

    202501122 - India - Taguig, Metro Manila, Philippines - Bevorzugt **Description**: The Role Please enter the responsibilities of the role - Responsibility: - Security Analysis: Analyzing the results of penetration tests to assess the severity of identified vulnerabilities, their potential impact on the system and the business, and the likelihood of...


  • India Delta System & Software, Inc. Full time

    Job Title: Lead Penetration TesterLocation: India (Remote - Travel to Office Once a Month)Job Type: Full-TimeIndustry: Cybersecurity / Information TechnologyWork Hours: Standard IST hoursTravel: Once a month to client/office location (as required)About the Role:We are seeking an experienced and highly skilled Lead Penetration Tester to lead security...


  • Remote, India Rackspace Technology Full time

    Job Description- Cyber Vulnerability Analyst & Penetration Tester III - IN- Night shift ( Mon -Friday)Experience - 5+ yrs into Pen TestingLocation - Gurgaon Hybrid or India RemotePS - OSCP certification is Mandatory for this role.Job Profile SummaryResponsible for conducting vulnerability assessment scans, assisting with penetration testing, exposing...


  • India Rackspace Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Role - Cyber Vulnerability Analyst & Penetration Tester III - IN Shift - Night shift ( Mon -Friday Experience - 5 yrs into Pen Testing Location - Gurgaon Hybrid or India Remote PS - OSCP certification is Mandatory for this role Job Profile Summary Responsible for conducting vulnerability assessment scans, assisting with penetration testing, exposing...

  • Penetration Tester

    2 weeks ago


    India The Hackett Group Full time

    **Responsibilities** - Conduct Penetration Tests: Perform comprehensive penetration testing on AI models, APIs, cloud infrastructures, and associated systems to uncover security weaknesses. - AI-Specific Threat Analysis: Identify and assess vulnerabilities unique to AI systems, including model inversion, data poisoning, and adversarial attacks. - Tool...


  • India Pivot DevOps Full time

    We're looking for enthusiastic User-driven Beta Testers to join us in shaping an exciting travel-tech product. We're offering a unique Internship for a new travel-tech app aimed at solving a major pain point for millions of Indian railway passengers. This is your chance to work directly with the product team, test features and contribute ideas that will...

  • Security Tester

    8 hours ago


    India ControlCase Full time

    As a Security Engineer, you will perform authorized penetration tests on computer systems in order to expose weaknesses in their security that could be exploited by criminals. You can choose to specialize in manipulating a particular type of system, such as: - Network and infrastructures - Windows, Linux and Mac operating systems - APIs and Web Services,...