Android Reverse EngineerIn support of our global Android Reverse Engineering program, we seek highly skilled Android App and SDK Reverse Engineers to join our team. This role will involve analyzing and deconstructing Android applications and SDKs to identify potential security risks and gain insights into their underlying functionality. About The Role
Deep Dive Analysis: Conduct in-depth analysis of Android applications and SDKs to understand their codebase, architecture, functionality and to identify potential risks.
Reverse Engineering Techniques: Employ advanced reverse engineering techniques to extract information from various codebases, including decompilation, disassembly, and debugging.
Risk Identification: Identify user and device risk, data leakage, and malicious code execution within Android apps and SDKs.
Threat Intelligence: Gather, analyze and report threat intelligence related to Android malware, exploits, and emerging security trends.
Collaboration: Collaborate with security researchers, developers, and other stakeholders to share findings, provide recommendations, and contribute to the development of secure applications and ecosystem. ABOUT YOU
We require a minimum of 3 - 5+ years of expertise in one or more of the following: Android Development, Reverse Engineering, Pentesting, Application Security Assessments, Capture the Flag (CTF).
Our Android Reverse Engineering Program also requires hands on experience with the following:
Analyzing, unpacking, and reverse engineering code of malicious applications or SDKs.
Static and Dynamic Analysis Techniques
Reverse Engineering tools such as Jadx, Ghidra, Frida, IDA Pro, Burp, to perform binary and APK analysis
Java, Kotlin, JavaScript, Flutter, and other mobile software languages
ELF (Native Binaries) reverse engineering
Development of signatures (SQL, Yara, etc.)
An understanding of the following topics will be greatly appreciated and utilized:
Android Fundamentals such as Android activity lifecycles, common Android API usage, AOSP, and how an Android application is created.
Techniques utilized by malicious applications to harm the user’s device or their data
Mobile App store policies (Ads, PHAs, Developer, etc.)
Network traffic analysis; security fundamentals
Research on threats such as APT using Open-Source Intelligence (Virus Total, Web, ExploitDB, MITRE, etc.)
Encoding and Cryptography
Authentication mechanisms and security
Device rooting
Complex frameworks and application packers