Role Overview
Senior mobile application security professional responsible for securing Android and iOS applications across the full development lifecycle, working closely with mobile, backend, and product teams to identify, validate, and reduce security risks, with a strong focus on practical security testing, SSDLC integration, and API security.
Key Responsibilities
· Perform end-to-end security testing of Android and iOS mobile applications
· Execute static, dynamic, and runtime security testing of mobile apps
· Conduct API security testing supporting mobile applications and backend services
· Assess authentication, authorization, session management, and token handling
· Validate mobile-to-backend communication security including TLS and certificate handling
· Identify business logic flaws and abuse scenarios across mobile and API workflows
· Participate in SSDLC activities including threat modeling, secure design reviews, and security requirement definition
· Review mobile application architecture and data flows from a security perspective
· Provide clear, actionable remediation guidance and support fix validation
· Align security findings with applicable security standards, frameworks, and compliance expectations
· Support customer, audit, or certification-driven security assessments when required
Technical Skills
· Strong hands-on experience in Android and iOS application security testing
· Solid understanding of mobile application architecture and platform-specific security risks
· Practical experience with mobile reverse engineering and runtime analysis
· Strong API security testing skills aligned with OWASP API Security Top 10
· Working knowledge of OWASP Mobile Top 10, MASVS, and MASTG
· Understanding of Secure Software Development Lifecycle and secure coding practices
· Familiarity with NIST Secure SDLC principles and ISO/IEC 27001 application security controls
· Exposure to product security standards such as IEC 62443 is a plus
· Experience using industry-standard mobile and API security testing tools
· Ability to clearly document findings, risk impact, and remediation guidance
Location:IN-GJ-Ahmedabad, India-Ognaj (eInfochips)Time Type:Full timeJob Category:Engineering Services