N
NetSPI
Posted 24 days agoVerified live 1d ago

Security Consultant II (Mobile Application Penetration Tester)

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
5 H-1B approvalsDept. of Labor
1 green cardsCertified filings
Mobile Application Penetration TestingKali LinuxBurp SuiteFridaDrozerObjectionGhidraMobile Application SecurityAndroidiOSOWASP Top 10PythonARM Reverse Engineering

Visa sponsorship history

3 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
5H-1B approved
100%approval rate
1PERM certified
$89,680median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20233
20242
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20232
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20251
Top sponsored roles
Senior Security ConsultantSecurity Consultant II

Job description

Summary

NetSPI is a cybersecurity company specializing in penetration testing and proactive security solutions. The Security Consultant II will conduct mobile application and API penetration tests, identify vulnerabilities, produce client-focused reports, and develop security testing techniques and methodologies.

Responsibilities

  • Conduct penetration testing engagements on mobile applications and underlying APIs
  • Identify insecure data storage, communications, or cryptography in mobile applications
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
  • Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations

Skills

  • • Bachelor's degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience
  • • Minimum of 2-3 years of work experience in mobile application penetration testing
  • • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra)
  • • Experience developing Frida tools to bypass application protections or exploit vulnerabilities
  • • Understanding of mobile application data security, communications, and sandboxes
  • • Knowledge of Android and iOS operating systems
  • • Familiarity with offensive and defensive IT concepts and protocols
  • • Extensive understanding of the OWASP Top 10 and various security frameworks
  • • Working knowledge of Windows, Linux and MacOS operating systems internals
  • • Ability to work independently and as part of a team
  • • Proficient communication skills, both written and verbal
  • • Willingness to travel up to 5-10%
  • • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
  • With a concentration in Computer Science, Engineering, Math, or IT preferred
  • • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
  • • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
  • • Experience in ARM reverse engineering

Qualifications

Must Haves

  • • Bachelor's degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience
  • • Minimum of 2-3 years of work experience in mobile application penetration testing
  • • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Frida, Drozer, Objection, Ghidra)
  • • Experience developing Frida tools to bypass application protections or exploit vulnerabilities
  • • Understanding of mobile application data security, communications, and sandboxes
  • • Knowledge of Android and iOS operating systems
  • • Familiarity with offensive and defensive IT concepts and protocols
  • • Extensive understanding of the OWASP Top 10 and various security frameworks
  • • Working knowledge of Windows, Linux and MacOS operating systems internals
  • • Ability to work independently and as part of a team
  • • Proficient communication skills, both written and verbal
  • • Willingness to travel up to 5-10%
  • • This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs

Nice to Haves

  • with a concentration in Computer Science, Engineering, Math, or IT preferred
  • • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
  • • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
  • • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT)
  • • Experience in ARM reverse engineering

More jobs like this