Mobile Application Security Lead (AppSec)

ESP Engineered

Mumbai

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ESP Engineered is looking for a Mobile Application Security Lead (AppSec) in Mumbai to lead mobile application security testing for Android and iOS platforms. The ideal candidate will have a deep understanding of mobile security architecture, proficiency in tools like Burp Suite and Frida, and experience with mobile app penetration testing. Responsibilities include executing security assessments, mentoring junior analysts, and reporting issues based on OWASP Mobile Top 10. Join us to ensure high-quality security assessments across mobile applications.

Qualifications

  • Strong understanding of mobile security architecture and Android/iOS internals.
  • In-depth knowledge of OWASP Mobile Top 10 and secure coding practices.
  • Experience with both manual and automated mobile penetration testing.

Responsibilities

  • Lead mobile app security testing for Android and iOS.
  • Perform dynamic and static application security testing.
  • Identify and report security issues based on OWASP Mobile Top 10.

Skills

Mobile security architecture
OWASP Mobile Top 10
API testing
Mobile app penetration testing
Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)

Tools

Frida
Objection
Burp Suite
MobSF
APKTool
Jadx
Postman

Job description

Mobile Application Security Lead (AppSec)

4-5 years

Full-Time

Job Title: Mobile Application Security Lead (AppSec)

Experience Required: 4–5 Years

Job Type: Full-time, On-site

Job Overview

Talakunchi Networks Pvt Ltd is seeking a skilled and motivated Mobile Application Security Lead to oversee and deliver comprehensive security assessments across Android and iOS platforms. The ideal candidate will have a strong background in mobile app penetration testing and will serve as both a technical lead and client‑facing expert, ensuring high‑quality delivery across multiple engagements.

Key Responsibilities
  • Lead and execute mobile app security testing for Android and iOS platforms.
  • Perform both automated and manual penetration testing including:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Runtime instrumentation and analysis
  • Reverse engineer APKs/IPAs to identify vulnerabilities such as hardcoded secrets and logic flaws.
  • Identify and report security issues based on OWASP Mobile Top 10, insecure storage, transport layer issues, and platform‑specific flaws.
  • Use advanced tools: Frida, Objection, MobSF, Burp Suite, Jadx, APKTool, Xposed, Postman, etc.
  • Prepare detailed technical reports with:
    • Risk ratings (CVSSv4/custom)
    • Proof of Concept (PoC)
    • Practical remediation recommendations
  • Interact with client‑side stakeholders such as AppDev, QA, and InfoSec teams.
  • Review and validate deliverables prepared by junior team members.
  • Assist in pre‑sales efforts: scope definition, effort estimation, and technical discussions.
  • Mentor and train junior security analysts in mobile AppSec practices.
  • Stay up‑to‑date with the latest mobile vulnerabilities, trends, and tools.
Required Skills
  • Strong understanding of mobile security architecture, Android/iOS internals, and sandboxing.
  • In‑depth knowledge of OWASP Mobile Top 10 and MASVS.
  • Proficient in tools such as: Frida, Objection, Burp Suite, MobSF, Charles Proxy, APKTool, Jadx, Postman/Insomnia for API testing.
  • Experience with Jailbreaking/Rooting, SSL pinning bypass, and secure coding practices.
  • Familiarity with software development life cycle (SDLC) and CI/CD environments.
  • Experience in ticketing systems like Jira, ServiceNow, etc.
Preferred Certifications
  • CEH
  • eMAPT
  • eWPTXv2
Bonus Points For
  • Knowledge of mobile CI/CD security pipeline.
  • Familiarity with banking/fintech security standards (RBI, PCI DSS, etc.).
  • Experience in effort estimation and VAPT project planning.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Mobile Appsec - SME
Mobile Appsec - SME

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Mobile Appsec - SME
Mobile Appsec - SME

ESP Engineered • Mumbai

On-site
INR 1,000,000 - 1,500,000
Team Lead _Sr.VAPT Engineer _Web, Mobile & Application Security
Team Lead _Sr.VAPT Engineer _Web, Mobile & Application Security

REJUVENT GREENTECH • Chennai District

On-site
INR 1,400,000 - 2,200,000
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1
Security Analyst – Application Security VAPT
Security Analyst – Application Security VAPT

JUARA IT SOLUTIONS • Chennai District

On-site
INR 900,000 - 1,300,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

Hybrid
INR 900,000 - 1,500,000
Associate Security Analyst (AppSec)
Associate Security Analyst (AppSec)

Kratikal Tech • Mumbai

On-site
INR 300,000 - 600,000
Health insurance
Gratuity payment
Employees' Provident Fund
Security Analyst (Android / iOS)
Security Analyst (Android / iOS)

OneSpan • Dadri

On-site
INR 1,200,000 - 1,800,000
Associate Security Analyst (AppSec)
Associate Security Analyst (AppSec)

Kratikal Tech Private Limited • Mumbai

On-site
INR 300,000 - 500,000
Health insurance
Gratuity payment
Employees' Provident Fund