Job Category: Technical
Job Type: On-Site
Job Location: Lahore
The Senior Mobile Application Security Tester will lead security assessments of Android and iOS applications and their supporting APIs for Catalyic Security’s clients. You will uncover vulnerabilities through hands-on testing and code review, deliver clear remediation guidance, verify fixes, and mentor junior testers on the team.
Key Responsibilities
- Lead end-to-end security testing of Android and iOS applications
- Perform API security testing for mobile backends
- Conduct source code reviews and vulnerability assessments, including:
- Insecure data storage and cryptography
- Authentication, authorization, and session management
- Network communication and certificate pinning
- Reverse engineering, tampering, and runtime protections
- Test against OWASP Mobile Top 10 and OWASP MASVS
- Document findings in clear, actionable technical reports
- Recommend fixes and verify remediation with development teams
- Mentor junior testers on mobile testing methodology and tooling
Required Skills & Experience
- 5+ years of experience in mobile application security testing
- Strong hands-on experience with both Android and iOS platforms
- Proficiency with tools such as Frida, Objection, MobSF, Burp Suite, and Jadx
- Experience with static and dynamic analysis, including rooted and jailbroken device testing
- Solid understanding of API security and OWASP API Top 10
- Strong report writing and technical communication skills
- Ability to lead assessments and manage multiple projects
Education & Certifications (Preferred)
- Bachelor’s degree in Cyber Security, Computer Science, IT, or a related field
- Relevant certifications preferred, supported by strong mobile security testing experience:
- eMAPT (eLearnSecurity Mobile Application Penetration Tester)
- PMPA (Practical Mobile Pentest Associate)