Trellix logo
TrellixPosted 6 days ago

Reverse Engineer (Android)

RemoteUnited States

Full TimeLargeTECH

Job Summary

Conduct in-depth analysis of Android applications and SDKs to understand their codebase, architecture, and functionality while identifying potential risks. Employ advanced reverse engineering techniques including decompilation, disassembly, and debugging to extract information from various codebases. Identify user and device risks, data leakage, and malicious code execution within Android apps and SDKs. Gather, analyze, and report threat intelligence related to Android malware, exploits, and emerging security trends. Collaborate with security researchers, developers, and stakeholders to share findings and contribute to the development of secure applications. Requires 3-5+ years of expertise in Android Development, Reverse Engineering, or Application Security Assessments. Hands-on experience with tools like Jadx, Ghidra, Frida, and IDA Pro is essential.

Required Qualifications

  • 3 - 5+ years of expertise in one or more of the following: Android Development, Reverse Engineering, Pentesting, Application Security Assessments, Capture the Flag (CTF)
  • hands on experience with the following: Analyzing, unpacking, and reverse engineering code of malicious applications or SDKs
  • Static and Dynamic Analysis Techniques
  • Reverse Engineering tools such as Jadx, Ghidra, Frida, IDA Pro, Burp, to perform binary and APK analysis
  • Java, Kotlin, JavaScript, Flutter, and other mobile software languages
  • ELF (Native Binaries) reverse engineering
  • Development of signatures (SQL, Yara, etc.)
  • An understanding of the following topics will be greatly appreciated and utilized: Android Fundamentals such as Android activity lifecycles, common Android API usage, AOSP, and how an Android application is created
  • Techniques utilized by malicious applications to harm the user's device or their data
  • Mobile App store policies (Ads, PHAs, Developer, etc.)
  • Network traffic analysis; security fundamentals
  • Research on threats such as APT using Open-Source Intelligence (Virus Total, Web, ExploitDB, MITRE, etc.)
  • Encoding and Cryptography
  • Authentication mechanisms and security
  • Device rooting
  • Complex frameworks and application packers

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce