Responsibilities
- Perform security testing of Android and iOS mobile applications used in digital payment ecosystems.
- Conduct manual and automated mobile security testing aligned with OWASP Mobile Top 10, OWASP MASVS & MSTG.
- Identify vulnerabilities related to insecure data storage, weak cryptography, insecure communication, authentication & authorization flaws, and business logic issues in payment flows.
- Perform runtime instrumentation and dynamic analysis using Frida, Objection, and Xposed.
- Reverse engineer mobile applications using APKTool, JADX (Android) and basic iOS reverse‑engineering tools (class‑dump, Hopper, Ghidra).
- Intercept and analyze mobile traffic with Burp Suite (Mobile Assistant preferred), mitmproxy or Charles Proxy.
- Test mobile backend APIs supporting payment workflows with Burp Suite and Postman.
- Validate security of payment features—including UPI, wallets, cards, tokenization, OTP, MFA, and session management.
- Prepare high‑quality vulnerability reports with risk assessment, proof‑of‑concept, and clear remediation guidance.
- Support retesting and vulnerability closure.
- Work closely with development and product teams to explain findings and fixes.
- Explore vulnerabilities beyond standard checklists through research‑driven mindset and new attack‑vector discovery.
- Analyze new Android/iOS versions, security changes, and advanced bypass techniques (SSL pinning, root/jailbreak detection).
- Develop custom test cases for complex payment and business‑logic scenarios.
- Contribute to internal tools, scripts, and testing methodologies and share knowledge of security best practices.
- Independently validate false positives and negatives.
Scripting & Automation Skills (Mandatory)
- Hands‑on scripting experience in one or more of the following: Python—automation, PoC development, API testing; JavaScript—Frida hooks and runtime manipulation; Bash—automation and tooling.
- Write and modify custom Frida scripts.
- Automate repetitive testing and analysis tasks.
- Customize open‑source tools for specific app behaviors.
- Strong understanding of secure‑coding flaws through runtime and code‑level analysis.
Mandatory Skills & Experience
- 3–4 years of experience in mobile application security testing.
- Strong understanding of Android and iOS security architectures.
- Hands‑on experience with MobSF, AndroBugs, QARK; Frida, Objection; Burp Suite.
- Experience testing BFSI / FinTech / Digital Payment applications.
- Strong knowledge of OWASP Mobile Top 10 and OWASP API Top 10 (supporting APIs).
Good to Have
- Exposure to PCI‑DSS, RBI, or CERT‑IN security requirements.
- Experience with CI/CD integration for mobile security testing.
- Basic understanding of cloud and backend security supporting mobile apps.
- iOS security testing experience is a strong plus.