Malware Reverse Engineer (Android) - UK

Reversec

Greater London

On-site

GBP 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Reversec is a specialist security consultancy delivering research-led cyber security services. Our consultants analyse obfuscated software, reverse engineer complex apps, and develop tooling to support detection and incident response.

We emphasise research-driven capability and ongoing professional development. We are recruiting Android reverse engineers and malware analysts at multiple levels to join a team working on one of the world’s largest technology platforms.

Qualifications

  • Strong programming fundamentals in at least one object-oriented language.
  • Genuine interest in Android internals and how malicious software works.
  • Investigative mindset – curiosity, persistence, and attention to detail.
  • Clear written and spoken English.

Responsibilities

  • Malware Reverse Engineering: static/dynamic analysis of Android apps, obfuscated code, and native libraries.
  • Detection Engineering: develop and validate detection logic and automated rules.
  • Quality & Peer Review: review analyses and ensure reporting quality.
  • Research & Tool Development: create tools and scripts to support investigations.

Skills

Android reverse engineering
Malware analysis
Static analysis
Dynamic analysis
Java Kotlin

Tools

Frida
LSPosed

Job description

Location: UK (Offices in London and Manchester) - Applicants must have the right to work in the UK.

About Reversec

At Reversec, we deliver research-led cyber security services that help organisations defend against real-world threats and build long-term resilience. Our consultants are a diverse team of highly skilled technical experts, researchers, and creative problem-solvers who are passionate about advancing the cyber security industry.

We believe great consultants are empowered consultants. Our people take ownership of their professional development, contribute to meaningful research, and have the freedom to shape the way we work. If you're driven by curiosity, enjoy solving complex technical challenges, and thrive in an environment that values innovation and continuous learning, we'd love to hear from you.

The Role

Reversec is a specialist security consultancy built on deep technical expertise, research, and real-world security engineering. Our consultants regularly analyse highly obfuscated software, reverse engineer complex applications, develop custom tooling, and contribute to open-source security projects used throughout the industry. Reversec maintains Android security tooling such as Drozer and invests heavily in research-led capability development.

We are seeking Android reverse engineers and malware analysts across all experience levels (from those building their skills to seasoned experts) to join a specialist team supporting one of the world's largest technology platforms.

As an Android Malware Reverse Engineering Analyst, you will investigate complex and evasive Android applications, identify malicious functionality, conduct detailed reverse engineering, and support automated detection development.

You will work as part of a specialist malware analysis team responsible for investigating applications that fall outside standard analysis processes and require advanced technical expertise. This includes malware research, incident investigations, escalation handling, detection engineering, and quality assurance activities.

We're recruiting analysts across multiple career stages, from aspiring reverse engineers to experienced malware researchers. Your responsibilities and the expectations placed on you will depend directly on the experience you bring. Experienced analysts will take on complex samples and investigations with a high degree of independence, provide mentorship to junior team members, and assist in developing internal tooling and processes. Analysts earlier in their careers will carry out similar categories of work, with closer support and a remit that grows as their skills develop. Wherever you start, training will be available to bring you up to the standard the team works to.

Key Responsibilities

All analysts contribute across the areas below. The complexity of the cases assigned to you, the degree of independence expected of you, and any additional oversight and reporting duties will reflect your experience.

Malware Reverse Engineering
  • Perform detailed static and dynamic analysis of Android applications and SDKs.
  • Analyse heavily obfuscated Java/Kotlin applications, native code, and framework applications (e.g., Flutter, .NET MAUI, React Native).
  • Investigate packers, in-memory loading techniques, encrypted payloads and anti-analysis mechanisms.
  • Determine application behaviour and identify potentially harmful functionality.
  • Conduct complex investigations into suspicious applications and malware campaigns.
  • Support escalations and urgent high-priority investigations.
  • Analyse internal and external malware leads.
  • Identify indicators, behaviours, attack techniques and attacker objectives.
Detection Engineering
  • Develop and validate detection logic and automated rules.
  • Support improvements to malware detection capabilities.
  • Work with analysts and engineering teams to improve investigative efficiency.
Quality & Peer Review
  • Review analysis performed by other analysts.
  • Validate technical findings and enforcement decisions.
  • Ensure consistent technical standards and reporting quality.
Research & Tool Development
  • Develop one-off tools, scripts and automation to support investigations.
  • Contribute to internal research initiatives.
  • Stay current with evolving Android threats, malware techniques and analysis methodologies.
Experience and Expectations

We do not require a fixed profile. Instead, we will calibrate expectations to the experience you bring

In all cases, you will need:

  • Strong programming fundamentals in at least one object-oriented language.
  • A genuine interest in Android internals and how malicious software works.
  • An investigative mindset – curiosity, persistence, and attention to detail.
  • Clear written and spoken communication in English.

If you are an experienced analyst, we expect proven experience in one or more of: Android malware analysis, Android application security testing, mobile application reverse engineering, malware research, threat research, or mobile threat intelligence. You should be able to demonstrate skills across Java and Android internals, Smali and DEX analysis, Android application architecture, static and dynamic analysis techniques, analysis of obfuscated code, native Android libraries (C/C++), and scripting or tool development (e.g. Python). In return, you will be trusted to work independently on complex cases from an early stage, lead urgent escalations, review the work of others and mentor colleagues.

If you are earlier in your career, we do not expect the above on day one. Show us evidence that you enjoy understanding how software works and are actively developing technical security skills - CTFs, crackmes, personal reverse engineering projects, relevant coursework or published write-ups. You will receive structured training and mentoring to bring you up to the team's standard, and your responsibilities will expand as your capability does.

Candidates anywhere between these two points are equally welcome: tell us what you can already do, and we will shape both expectations and training around it.

Work is allocated according to capability and experience. All analysts receive structured mentoring, peer review and continuous technical development

Technical Skills

An ideal candidate will demonstrate experience with some of the following:

  • Reverse engineering and static analysis – use of decompilers and disassemblers, particularly to tackle heavily obfuscated code, native libraries, and custom cryptography
  • Dynamic analysis – frameworks like Frida and LSPosed particularly welcome
  • Malware analysis – detection development, behavioural analysis
Why Join Reversec?

We’ll invest in you too – through internal training, mentoring, and room to develop. What you build here won’t stay internal: our tooling, research, and methodologies are used throughout the security community.

Reversec is committed to creating an inclusive workplace. We welcome applications from suitably qualified candidates regardless of age, disability, gender identity, marital status, race, religion or belief, sex, sexual orientation, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Android Malware Reverse Engineer | Research & Tools
Android Malware Reverse Engineer | Research & Tools

Reversec • Greater London

On-site
GBP 60,000 - 90,000
Senior Security Consultant (Android Malware Reverse Engineering)
Senior Security Consultant (Android Malware Reverse Engineering)

NetSPI • United Kingdom

On-site
GBP 40,000 - 70,000
Senior Android Malware Reverse Engineering Consultant
Senior Android Malware Reverse Engineering Consultant

NetSPI • United Kingdom

On-site
GBP 40,000 - 70,000
Malware Researcher
Malware Researcher

Alice • Greater London

On-site
GBP 55,000 - 75,000
Senior Full Stack Software Engineer
Senior Full Stack Software Engineer

Hyperproof • United Kingdom

Remote
GBP 81,000 - 103,000
Paid annual leave
Competitive compensation package
Quarterly Wellness Weekends
+4
Senior Security Researcher
Senior Security Researcher

Searchability® • United Kingdom

Remote
GBP 90,000 - 100,000
Private medical
Life assurance
Critical illness
+3
Android Vulnerability Researcher
Android Vulnerability Researcher

Interrupt Labs • Basingstoke

On-site
GBP 50,000 - 75,000
25 days holiday
Yearly company bonus
Training and conference budgets
+6
Senior Software Engineer
Senior Software Engineer

Secure Source • Greater London

On-site
GBP 70,000 - 90,000
Experienced Vulnerability Researcher
Experienced Vulnerability Researcher

CoreTech Security • Cheltenham

On-site
GBP 75,000 - 110,000
Promotions based on technical merit
20–25 days holiday + bank holidays
Relocation financial support
+4
Cyber Technical Lead
Cyber Technical Lead

Maersk • Maidenhead

On-site
GBP 90,000 - 150,000