Mobile Assessment Engineer Offline
Job Description:
White & black-box software vulnerability assessment of Android components:
- security review of Android mobile applications and firmware components
- risk analysis and security issues mitigation advisory
- exploitability Proof-of-Concepts development
- emerging threats research: new attack methods, (un)known security issues risks
Security validation is typically executed in 1-2 months iterations.
Major Requirements:
- in-depth understanding of Android security architecture and typical security issuesin-depth understanding of Android security architecture and typical security issues
- practical experience in reverse-engineering (preferably *.apk and ARM binaries), software exploitation, binary and source code audit
- knowledge of Linux Kernel security architecture and Android-specific add-ons (IPC, SE Android, application security framework)
- ability to understand execution logic in C/C++, Java, Assembler; scripting skills
- good technical English, strong reporting and communication skills
Optional Requirements:
- security background (University, relevant prior employment)
- participation in security contests (CTF), own write-ups publications, community activities
- hands-on experience with assessment automation tools (fuzzers, static source code analyzers)
- experience in reversing ( IDA Pro, JEB) reversing protected solutions (obfuscated/ packed code)
- applied crypto: knowledge of existing algorithms and protocols (AES/RSA/ECC/SHA, authentification/key exchange, digital signature, SSL/TLS)
- software exploitation experience
- awareness of security-related standards and best practices
Working Conditions:
- GIG contract
- remote work is possible as well as work in Kyiv office
Benefits:
- competitive salary, annual salary review, annual bonuses
- paid 28 work days of annual vacations and sick leaves
- opportunity to become an inventor of international patents with paid bonuses
- medical & life insurance for employees and their children
paid lunches
- discounts to Samsung products, services
- regular education and self-development on internal courses and seminars
- hybrid work format, working in office is required for some tasks