About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior/ Lead Security Researcher based in India.
This is an opportunity to join a Product Security team focused on cutting-edge mobile cybersecurity research and advanced threat defense.
Responsibilities
- Research emerging threats affecting mobile operating systems and applications, including rooting/jailbreaking, app tampering, runtime tampering, and techniques used to conceal malicious modifications.
- Conduct reverse engineering, vulnerability research, exploitation, and mitigation work to develop effective mobile security protections.
- Perform penetration testing and security assessments of mobile products and applications, identifying vulnerabilities and recommending practical defenses.
- Develop scripts, tooling, and attack/defense techniques for mobile devices and applications to accelerate security research and testing.
- Create customer-facing security demonstrations that clearly communicate attack scenarios, vulnerabilities, and corresponding defensive mechanisms.
- Contribute to security solution architectures spanning mobile devices, applications, and networked components, including authentication technologies such as OAuth2 and FIDO2.
- Research and assess cryptographic protocols and algorithms when required as part of broader security architecture and product development.
- Take ownership of selected research and development projects, driving them from investigation through implementation and delivery.
- Mentor and provide technical guidance to junior security researchers, while contributing to a culture of quality, creativity, and continuous improvement.
- Collaborate closely with the wider Product Security team to develop innovative approaches to emerging mobile security challenges.
Requirements
- 5+ years of relevant experience in security research, application security, mobile security, vulnerability research, penetration testing, or a closely related field.
- Strong understanding of operating system internals across one or more platforms such as Android, iOS, HarmonyOS Next, Linux, or comparable systems.
- Solid knowledge of mobile application development and security, with practical familiarity with rooting/jailbreaking, runtime tampering, app tampering, and related evasion techniques.
- Hands-on experience with security research and reverse-engineering tools such as Frida, Theos, Ghidra, and IDA Pro.
- Familiarity with web application security and VAPT tools such as Burp Suite.
- Ability to understand how security tools and methodologies work internally and use that knowledge to develop creative, customized approaches rather than relying solely on standard workflows.
- Strong understanding of threat modeling and familiarity with at least one established threat-modeling framework.
- Experience with scripting or building custom tools to support security research, testing, attack simulation, or defensive development.
- Strong analytical and critical-thinking abilities, with a systematic and methodical approach to research and testing.
- Demonstrated ownership of technical projects, with the ability to work independently and make progress with minimal supervision.
- Excellent attention to detail and a strong commitment to quality, security, and technical rigor.
- Strong communication and interpersonal skills, with the ability to collaborate effectively and mentor less-experienced researchers.
- A proactive, adaptable, and highly driven mindset suited to a dynamic and rapidly evolving technical environment.
- A degree in Computer Science, Information Systems, Mathematics, or a related discipline is preferred, particularly with relevant cryptography coursework.
- Information security, ethical hacking, or security architecture certifications are a plus.
Conditions
- Fully remote position based in India.
- Full-time opportunity within a specialized Product Security team.
- Opportunity to work on advanced mobile cybersecurity research across Android, iOS, and HarmonyOS Next.
- Exposure to reverse engineering, vulnerability research, exploitation, penetration testing, cryptography, and security architecture.
- High level of technical ownership and the opportunity to lead selected research initiatives.
- Opportunity to mentor junior researchers and contribute to the evolution of security practices.
- Fast-paced, innovative environment with opportunities to develop new security tools, techniques, and solutions.
- Opportunity to work on security technologies protecting large-scale digital ecosystems and users globally.