Mobile Application Security Expert

1 month ago


Bengaluru, India NETSACH GLOBAL Full time

Greetings from Netsach.


We are looking for Mobile Application Security Expert for Dubai location as listed below.


Job Title - Mobile Application Security Expert

Exp- 4-5yrs

Job Type- Full-time

No of Openings - 2

Location - Dubai


Interested candidates can share their resume at emily@netsach.co.in.


Requirements:


Mobile Application Security Expert on platforms Android, iOS, tablet devices etc. with good knowledge about microservice architecture, security code review and pipeline driven security (Kubernetes, openshift and PaaS environment).


Key Skills Web & Mobile Application Security, Security Code review and API security.


Primary/General Job Purpose:

  • Encourage Shift Left Mindset - Proactively embed security requirements, by influencing implementation of security & privacy patterns from the start of the development cycle by reviewing user stories and create evil patterns. The candidate should also have an experience in working in an Agile environment.


  • Implement via Influence - Influence stakeholders such as Product Owners, Solution Architects, Developers, Testers, Engineers & others to include security patterns into features, epics and stories in order to build secure, innovative & superior digital products for customers and employees.


  • Assessments Perform security assessment, create evil stories, and perform gap analysis to provide appropriate remediations to the teams for implementing the fixes.


  • Tools and Technologies Burp Suite, Postman, Tenable Nessus, Checkmarx SAST, GitHub, CodeQL and good knowledge about microservice architecture and pipeline driven security.


Primary/General Job Purpose:

  • Encourage Shift Left Mindset - Proactively embed security requirements, by influencing implementation of security & privacy patterns from the start of the development cycle by reviewing user stories and create evil patterns. The candidate should also have an experience in working in an Agile environment.
  • Implement via Influence - Influence stakeholders such as Product Owners, Solution Architects, Developers, Testers, Engineers & others to include security patterns into features, epics and stories in order to build secure, innovative & superior digital products for customers and employees


Technical Skillsets :



Domain Knowledge


Technical Skillsets

Thin Client Application Security (Web based)

  1. Should have in depth exploitation knowledge and hands on OWASP top 10 and SANS 25
  2. Knowledge of CVSS scorings
  3. CVEs and evaluation of CVE and exploitation of CVE vulnerabilities
  4. Business logic bypasses, payment gateway tampering.
  5. Able to test Thick Client version of the web application.

Mobile Application Security (Android, iOS)

  1. Should have in depth exploitation knowledge and hands on OWASP top 10 and SANS 25
  2. Should be able to Bypass complex SSL Pinning on Mobile applications
  3. Hands on expertise on complex Root detection bypass techniques
  4. Hands on expertise in Jailbreaking and Rooting of N-1 devices.
  5. Tampering - decompiling and recompiling apk and ipa files.
  6. Review of manifest and plist files
  7. Bypasses of MAM / MDM controls and other business Logic scenarios.

Secure Code Review (+ review of open-source packages)

  1. Should have in depth knowledge and review the code manually as well as through automated code review for most tech stacks java, reactjs, node, asp, C#, python, ruby etc. wrt OWASP top 10 and SANS 25 secure coding standards.
  2. Find critical vulnerabilities with web application and mobile applications by reviewing source code.
  3. Should be aware about providing Code level mitigations for vulnerabilities.
  4. Sound knowledge on reviews for open-source packages and third-party libraries used in code
  5. To understand and prepare root cause analysis for vulnerabilities and

exploit.

Network component, Server & other devices (VA Compliance & Config review)

  1. Vulnerability assessment and Penetration testing using nmap, tenable , kali linux, msf etc.
  2. Strong knowledge on cryptographic algorithms, Digital signatures and PKI.
  3. Config reviews as per NIST / CIS benchmarks.
  4. Server hardening reviews.

Additional Platform Knowledge

(Optional but has Additional Advantage)

Devsecops, Container / K8s Security API Security

Elastic Search, ELK Cloud - Azure, AWS

Analytics / Machine Learning - Python

Data platform knowledge of Hadoop / Hive / SAP Hana



Thank You

Emily

emily@netsach.co.in




  • Bengaluru, India BCITS PVT LTD Full time

    Position: Application and Mobile Security Audit ExpertExperience: 1-4 yearsLocation: BangaloreSkills Sets:- Should have 1-4 years of experience in Application and Mobile Security Audit- proven experience in conducting security audits and penetration testing for web applications, mobile applications, and backend systems.- Strong understanding of web...


  • Bengaluru, India BCITS PVT LTD Full time

    Position: Application and Mobile Security Audit ExpertExperience: 1-4 yearsLocation: BangaloreSkills Sets: Should have 1-4 years of experience in Application and Mobile Security Auditproven experience in conducting security audits and penetration testing for web applications, mobile applications, and backend systems.Strong understanding of web application...


  • Bengaluru, India BCITS PVT LTD Full time

    Position: Application and Mobile Security Audit Expert Experience: 1-4 years Location: Bangalore Skills Sets:   Should have 1-4 years of experience in Application and Mobile Security Audit proven experience in conducting security audits and penetration testing for web applications, mobile applications, and backend systems. Strong understanding of web...


  • Bengaluru, India BCITS PVT LTD Full time

    Position: Application and Mobile Security Audit ExpertExperience: 1-4 yearsLocation: BangaloreSkills Sets: Should have 1-4 years of experience in Application and Mobile Security Auditproven experience in conducting security audits and penetration testing for web applications, mobile applications, and backend systems.Strong understanding of web application...

  • Senior Engineer

    3 days ago


    Bengaluru, India SHIELD Full time

    SHIELD is a device-first risk AI platform that helps digital businesses worldwide eliminate fake accounts and stop all fraudulent activities. SHIELD identifies the root of fraud with the global standard for device identification (SHIELD Device ID) and actionable risk intelligence, empowering businesses to stay ahead of new and unknown fraud threats. We are...

  • Senior Engineer

    1 week ago


    Bengaluru, India SHIELD Full time

    SHIELD is a device-first risk AI platform that helps digital businesses worldwide eliminate fake accounts and stop all fraudulent activities. SHIELD identifies the root of fraud with the global standard for device identification (SHIELD Device ID) and actionable risk intelligence, empowering businesses to stay ahead of new and unknown fraud threats. We are...


  • Bengaluru, India Capgemini Full time

    Strong understanding of vulnerability assessment and triage - 5+ year experience on Mobile Application Security and related security scanning tools such as Kryptowire. **Primary Skills**: Mobile Application Security Testing Security Scanning Tools - Onboarding, Vulnerability review, False positive **Responsibilities**: Certified Mobile Application Security


  • Bengaluru, India Mobile Programming Full time

    Responsibilities:- Lead the design, development, and implementation of Xamarin-based mobile applications for iOS and Android platforms.- Collaborate with stakeholders to gather requirements, analyze user needs, and define technical specifications for mobile applications.- Architect mobile solutions using Xamarin.Forms and Xamarin Native, ensuring...


  • Bengaluru, India Getinz Techno Services Full time

    Hiring Senior Mobile Application Security Engineer for a product company in the mobile-first risk intelligence platform (Fraud Detection Software) domain.Experience Range: 4 - 8 yrsLocation: Koramangala, BengaluruWork from officeRequirementsBachelor's degree in Computer Science, Cybersecurity, or a related fieldMinimum of 4 years of experience within mobile...


  • Bengaluru, India Getinz Techno Services Full time

    Hiring Senior Mobile Application Security Engineer for a product company in the mobile-first risk intelligence platform (Fraud Detection Software) domain.Experience Range: 4 - 8 yrsLocation: Koramangala, BengaluruWork from officeRequirementsBachelor's degree in Computer Science, Cybersecurity, or a related fieldMinimum of 4 years of experience within mobile...


  • Bengaluru, India athmâ Full time

    About Narayana Health:Narayana Health is headquartered in Bengaluru, India, and operates a network of hospitals in India and Overseas. Our mission is to deliver high-quality, affordable healthcare services to the broader population. Narayana Health Group is India’s leading healthcare provider and one of the largest hospital groups in the country with a...


  • Bengaluru, India Mobile Programming Full time

    Salary : 12 - 24 LPAJob Description : Vulnerability management Engineer : - Emphasis on the importance of being able to assess the risk of these CVEs contextualized for your environment being able to prioritize these CVEs. Triage Vulnerability mgmt life cycle. - Responsible for the Application Security and Vulnerability Management Product (SAST, DAST,...


  • Bengaluru, India athmâ Full time

    About Narayana Health:Narayana Health is headquartered in Bengaluru, India, and operates a network of hospitals in India and Overseas. Our mission is to deliver high-quality, affordable healthcare services to the broader population. Narayana Health Group is India’s leading healthcare provider and one of the largest hospital groups in the country with a...

  • Application Security

    3 weeks ago


    Bengaluru, India Nityo Infotech Full time

    Integration , Microsoft Office , Testing , A , Achieve , Activities , Aid , Android , Application , Application Infrastructure , Application Security , Authentication , Automation , Bangalore , Burp Suite , CEH , Certifications , Code , Command , Common , Communications , Communications Writing , Company , Construction , Continuous Delivery , Continuous...


  • Bengaluru, India athmâ Full time

    About Narayana Health: Narayana Health is headquartered in Bengaluru, India, and operates a network of hospitals in India and Overseas. Our mission is to deliver high-quality, affordable healthcare services to the broader population. Narayana Health Group is India’s leading healthcare provider and one of the largest hospital groups in the country with a...

  • Application Security

    1 month ago


    Bengaluru, India Nityo Infotech Full time

    Integration , Microsoft Office , Testing , A , Achieve , Activities , Aid , Android , Application , Application Infrastructure , Application Security , Authentication , Automation , Bangalore , Burp Suite , CEH , Certifications , Code , Command , Common , Communications , Communications Writing , Company , Construction , Continuous Delivery , Continuous...


  • Bengaluru, India Kratikal Full time

    Responsibilities Application Security Testing/Penetration Testing (Web-based, Thick client, web services, Mobile Android & IOS, Network PT) Static Code Analysis/ Secure Code Review Strong experience with the following tools – Burp Suite, Wireshark, Nmap, Metasploit, Checkmarx/Fortify, and Nessus. Conduct comprehensive security analysis to identify...


  • Bengaluru, India Iron Mountain Full time

    At Iron Mountain we know that work, when done well, makes a positive impact for our customers, our employees, and our planet. That’s why we need smart, committed people to join us. Whether you’re looking to start your career or make a change, talk to us and see how you can elevate the power of your work at Iron Mountain.We provide expert, sustainable...


  • Bengaluru, India Swift Strategic Staff Solutions INC Full time

    We are looking for a talented and experienced Mobile Application Developer to join our growing team. You will play a key role in designing, developing, and deploying innovative mobile applications that enhance our user experience and drive business Bachelor's Degree in Computer Science or a related field from an accredited university.- Minimum of 6+...


  • Bengaluru, India Factree Communications Full time

    At Factree Communications, we are currently looking for a Mobile App Developer. The ideal candidate will be responsible for the technical design and implementation of new products and enhancements. Support the application development lifecycle: concept, design, test, implementation and support. As a developer, you can put your passion for programming and...