Summary
NetSPI is a cybersecurity company specializing in penetration testing and proactive security solutions. The Security Consultant II will conduct mobile application and API penetration tests, identify vulnerabilities, produce client-focused reports, and develop security testing techniques and methodologies.
Responsibilities
- Conduct penetration testing engagements on mobile applications and underlying APIs
- Identify insecure data storage, communications, or cryptography in mobile applications
- Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
- Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
- Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations
Skills
- • Bachelor's degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience
- • Minimum of 2-3 years of work experience in mobile application penetration testing
- • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra)
- • Experience developing Frida tools to bypass application protections or exploit vulnerabilities
- • Understanding of mobile application data security, communications, and sandboxes
- • Knowledge of Android and iOS operating systems
- • Familiarity with offensive and defensive IT concepts and protocols
- • Extensive understanding of the OWASP Top 10 and various security frameworks
- • Working knowledge of Windows, Linux and MacOS operating systems internals
- • Ability to work independently and as part of a team
- • Proficient communication skills, both written and verbal
- • Willingness to travel up to 5-10%
- • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
- With a concentration in Computer Science, Engineering, Math, or IT preferred
- • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
- • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
- • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
- • Experience in ARM reverse engineering
Qualifications
Must Haves
- • Bachelor's degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience
- • Minimum of 2-3 years of work experience in mobile application penetration testing
- • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra)
- • Experience developing Frida tools to bypass application protections or exploit vulnerabilities
- • Understanding of mobile application data security, communications, and sandboxes
- • Knowledge of Android and iOS operating systems
- • Familiarity with offensive and defensive IT concepts and protocols
- • Extensive understanding of the OWASP Top 10 and various security frameworks
- • Working knowledge of Windows, Linux and MacOS operating systems internals
- • Ability to work independently and as part of a team
- • Proficient communication skills, both written and verbal
- • Willingness to travel up to 5-10%
- • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
Nice to Haves
- with a concentration in Computer Science, Engineering, Math, or IT preferred
- • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
- • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
- • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
- • Experience in ARM reverse engineering