
Security Testing | Technical Lead
CitiusTech โข Bengaluru, Karnataka, India
**Role & seniority: ** Mobile Application Security Engineer (security testing; likely mid-level based on responsibilities)
**Stack/tools: **
-
Mobile: Android & iOS security testing; Flutter (security implications)
-
SOUP: Security testing of 3rd-party components & open-source libraries
-
App/API security: Application Security, API Security, secure coding
-
Tools/frameworks: Burp Suite, OWASP ZAP, MobSF; static/dynamic analysis; penetration testing; vulnerability scanning; reverse engineering/code analysis
-
Top 3 responsibilities:
-
Run mobile security testing (static + dynamic analysis, penetration testing, vulnerability scanning)
-
Identify, document, and report vulnerabilities with actionable remediation recommendations
-
Perform SOUP validation for third-party components/open-source libraries
-
-
Must-have skills:
-
Strong knowledge of mobile app security (Android/iOS) and common vulnerability prevention via secure coding practices
-
Ability to use/manage security testing tools (Burp Suite, OWASP ZAP, MobSF)
-
Competence in API security and reverse engineering/code analysis
-
Experience integrating security testing into SDLC and collaborating with dev/QA/product
-
-
Nice-to-haves:
-
Healthcare domain experience
-
Familiarity with other mobile frameworks (e.g., React Native)
-
-
Location & work type: Not specified in provided text
Full Description
Technical Skills
- Mobile (Android & iOS) Security Testing 'Mobile (Android & iOS) Security Testing SOUP Security Testing (of the 3rd party components and open-source libraries)
- Knowledge on Flutter development framework
- API security
- Application Security
- Experience in healthcare domain
- Experience with security testing tools and frameworks
Roles and Responsibilities
- Conduct thorough security testing of mobile applications, including static and dynamic analysis, penetration testing, and vulnerability scanning.
- Identify and document security vulnerabilities and risks, providing detailed reports with actionable recommendations for remediation.
- Conduct SOUP validation security testing for the 3rd party components and open-source libraries.
- Understanding of secure coding practices for mobile applications to prevent common vulnerabilities.
- Familiarity with popular mobile development frameworks and their security implications (e.g., Flutter, React Native).
- Utilize and manage security testing tools and frameworks (e.g., Burp Suite, OWASP ZAP, MobSF) to assess mobile application security.
- Perform reverse engineering and code analysis to uncover security weaknesses and potential exploits.
- Work closely with development, QA, and product teams to integrate security testing into the software development lifecycle (SDLC).'