Mobile Appsec - SME

ESP Engineered

Mumbai

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

ESP Engineered in Mumbai is hiring a Mobile Application Security Tester to perform security testing on Android and iOS applications used in digital payment ecosystems. The role requires 3-4 years of experience with mobile application security, along with strong knowledge of OWASP standards. Responsibilities include scripting automated tests, identifying vulnerabilities, and preparing detailed security reports. Candidates should have hands-on experience with tools like Burp Suite and MobSF. Join a dynamic team focused on enhancing mobile security practices.

Qualifications

  • 3–4 years of experience in mobile application security testing.
  • Strong understanding of Android and iOS security architectures.
  • Experience testing BFSI / FinTech / Digital Payment applications.

Responsibilities

  • Perform security testing of Android/iOS mobile applications.
  • Identify vulnerabilities in payment flows.
  • Prepare high-quality vulnerability reports.

Skills

Security testing of mobile applications
Scripting in Python
Mobile security testing tools (MobSF, Burp Suite)
Android and iOS security knowledge

Tools

Burp Suite
Frida
Objection
APKTool

Job description

Responsibilities
  • Perform security testing of Android and iOS mobile applications used in digital payment ecosystems.
  • Conduct manual and automated mobile security testing aligned with OWASP Mobile Top 10, OWASP MASVS & MSTG.
  • Identify vulnerabilities related to insecure data storage, weak cryptography, insecure communication, authentication & authorization flaws, and business logic issues in payment flows.
  • Perform runtime instrumentation and dynamic analysis using Frida, Objection, and Xposed.
  • Reverse engineer mobile applications using APKTool, JADX (Android) and basic iOS reverse‑engineering tools (class‑dump, Hopper, Ghidra).
  • Intercept and analyze mobile traffic with Burp Suite (Mobile Assistant preferred), mitmproxy or Charles Proxy.
  • Test mobile backend APIs supporting payment workflows with Burp Suite and Postman.
  • Validate security of payment features—including UPI, wallets, cards, tokenization, OTP, MFA, and session management.
  • Prepare high‑quality vulnerability reports with risk assessment, proof‑of‑concept, and clear remediation guidance.
  • Support retesting and vulnerability closure.
  • Work closely with development and product teams to explain findings and fixes.
  • Explore vulnerabilities beyond standard checklists through research‑driven mindset and new attack‑vector discovery.
  • Analyze new Android/iOS versions, security changes, and advanced bypass techniques (SSL pinning, root/jailbreak detection).
  • Develop custom test cases for complex payment and business‑logic scenarios.
  • Contribute to internal tools, scripts, and testing methodologies and share knowledge of security best practices.
  • Independently validate false positives and negatives.
Scripting & Automation Skills (Mandatory)
  • Hands‑on scripting experience in one or more of the following: Python—automation, PoC development, API testing; JavaScript—Frida hooks and runtime manipulation; Bash—automation and tooling.
  • Write and modify custom Frida scripts.
  • Automate repetitive testing and analysis tasks.
  • Customize open‑source tools for specific app behaviors.
  • Strong understanding of secure‑coding flaws through runtime and code‑level analysis.
Mandatory Skills & Experience
  • 3–4 years of experience in mobile application security testing.
  • Strong understanding of Android and iOS security architectures.
  • Hands‑on experience with MobSF, AndroBugs, QARK; Frida, Objection; Burp Suite.
  • Experience testing BFSI / FinTech / Digital Payment applications.
  • Strong knowledge of OWASP Mobile Top 10 and OWASP API Top 10 (supporting APIs).
Good to Have
  • Exposure to PCI‑DSS, RBI, or CERT‑IN security requirements.
  • Experience with CI/CD integration for mobile security testing.
  • Basic understanding of cloud and backend security supporting mobile apps.
  • iOS security testing experience is a strong plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Mobile Appsec - SME
Mobile Appsec - SME

TalaKunchi Networks Pvt Ltd • Mumbai

On-site
INR 800,000 - 1,200,000
Mobile Application Security Lead (AppSec)
Mobile Application Security Lead (AppSec)

ESP Engineered • Mumbai

On-site
INR 1,500,000 - 2,500,000
Mobile Application Penetration Tester ( Pentest )
Mobile Application Penetration Tester ( Pentest )

Shashwath Solution • Pune District

On-site
INR 350,000 - 550,000
Mobile Application Penetration Tester ( Pentest )
Mobile Application Penetration Tester ( Pentest )

Shashwath Solution • Dadri

On-site
INR 4,500,000 - 6,500,000
Application Security Tester (Web, Mobile & API) – BFSI Domain
Application Security Tester (Web, Mobile & API) – BFSI Domain

ESP Engineered • Mumbai

On-site
INR 700,000 - 900,000
Senior Application Security Tester
Senior Application Security Tester

Hdfc Bank • Navi Mumbai, Mumbai

On-site
INR 3,500,000 - 7,000,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

On-site
INR 900,000 - 1,500,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Senior Security Engineer
Senior Security Engineer

Delta6Labs FinTech Pvt Ltd • Dadri

On-site
INR 1,500,000 - 2,500,000