Security Consultant II (Mobile Application Penetration Tester)

NetSPI

Minneapolis (MN)

On-site

USD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

NetSPI is seeking a skilled Penetration Tester to conduct mobile application security assessments, identify vulnerabilities, and provide actionable recommendations to strengthen client security postures.

You will work with clients to deliver clear reports, develop best practices, and contribute to NetSPI's ongoing security research and tooling, with travel up to 5-10% as needed.

Qualifications

  • Bachelor’s degree or higher in CS/Engineering/Math/IT or equivalent experience
  • 2–3 years of mobile application penetration testing experience
  • Experience with offensive tools: Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra
  • Experience developing Frida tools to bypass protections or exploit vulnerabilities
  • Understanding of mobile data security, communications, and sandboxes
  • Knowledge of Android and iOS security and OS internals
  • Familiarity with OWASP Top 10 and security frameworks
  • Strong written and verbal communication; able to work independently and in a team
  • Willingness to travel up to 5–10%
  • 8‑hour workday with occasional evenings/weekends to meet deadlines

Responsibilities

  • Conduct penetration testing engagements on mobile applications and underlying APIs
  • Identify insecure data storage, communications, or cryptography in mobile apps
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments
  • Research and develop innovative testing techniques and methodologies
  • Perform administrative tasks to ensure smooth consulting operations

Education

Bachelor’s degree or higher in Computer Science, Engineering, Math, or IT, or equivalent experience

Tools

Kali Linux
Burp Suite
Frida
Drozer
Objection
Ghidra

Job description

NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

Join the mission as a Security Consultant II. We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting mobile applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.

Responsibilities
  • Conduct penetration testing engagements on mobile applications and underlying APIs
  • Identify insecure data storage, communications, or cryptography in mobile applications
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.
Minimum Qualifications
  • Bachelor’s degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience
  • Minimum of 2-3 years of work experience in mobile application penetration testing
  • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra)
  • Experience developing Frida tools to bypass application protections or exploit vulnerabilities
  • Understanding of mobile application data security, communications, and sandboxes
  • Knowledge of Android and iOS operating systems
  • Familiarity with offensive and defensive IT concepts and protocols
  • Extensive understanding of the OWASP Top 10 and various security frameworks
  • Working knowledge of Windows, Linux and MacOS operating systems internals
  • Ability to work independently and as part of a team
  • Proficient communication skills, both written and verbal
  • Willingness to travel up to 5-10%
  • This position requires an 8‑hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
Preferred Qualifications
  • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
  • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
  • Experience in ARM reverse engineering

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 80,000 - 110,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 85,000 - 110,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 110,000 - 150,000
Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Senior Security Consultant (Network Penetration Tester)
Senior Security Consultant (Network Penetration Tester)

NetSPI • United States

On-site
USD 90,000 - 120,000
Remote Mobile App Security Penetration Tester II
Remote Mobile App Security Penetration Tester II

NetSPI Inc. • Minneapolis (MN)

On-site
USD 110,000 - 150,000
Security Consultant II (AI/ML Penetration Tester)
Security Consultant II (AI/ML Penetration Tester)

NetSPI • United States

On-site
USD 80,000 - 120,000
Collaborative workplace culture
Opportunities for professional growth
Senior Security Consultant (Mainframe Penetration Tester)
Senior Security Consultant (Mainframe Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 120,000
Senior Security Consultant (Mainframe Penetration Tester)
Senior Security Consultant (Mainframe Penetration Tester)

NetSPI Inc. • Minneapolis (MN), Northern (KY)

Hybrid
USD 120,000 - 170,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 100,000 - 130,000