web application testingmobile application testingowaspapi securitypenetration testingfridaburp suitepython
Key Responsibilities
- Plan, scope, and independently execute web and mobile application penetration tests across the full engagement lifecycle.
- Perform manual and automated vulnerability assessments of web apps, mobile apps (Android/iOS), APIs (REST/SOAP/GraphQL), and thick clients.
- Conduct testing aligned to OWASP Top 10, OWASP API Security Top 10, OWASP MASVS/MASTG, and WSTG methodologies.
- Identify, exploit, and chain vulnerabilities (authn/authz flaws, injection, SSRF, IDOR, business-logic abuse, insecure deserialization, etc.) and demonstrate real-world impact via safe proof-of-concept.
- Perform mobile-specific assessments: static & dynamic analysis, reverse engineering, SSL pinning bypass, local data storage review, and runtime manipulation.
- Validate scanner output to eliminate false positives and confirm exploitability.
- Author clear, high-quality reports with risk ratings (CVSS), reproduction steps, evidence, and actionable remediation.
- Conduct remediation retests and verify fixes.
- Mentor and review the work of L1 testers; contribute to internal tooling, scripts, and methodology improvements.
- Communicate findings to technical and non-technical stakeholders during debrief sessions.
Required Skills & Experience
Core
- 3–6 years of hands-on web and mobile application penetration testing.
- Strong grasp of the OWASP Top 10, API Security Top 10, MASVS/MASTG, and WSTG.
- Deep understanding of HTTP/S, TLS, session management, authentication & authorization mechanisms (OAuth2, JWT, SAML, SSO).
- Proven ability to perform manual exploitation beyond automated scanning.
Web Application Testing
- Injection (SQLi, command, template), XSS, CSRF, SSRF, XXE, IDOR, access-control & business-logic flaws.
- API security testing (REST, SOAP, GraphQL).
Mobile Application Testing
- Android: APK decompilation, smali analysis, Frida/Objection instrumentation, SSL pinning bypass, insecure storage, intent abuse.
- iOS: IPA analysis, jailbreak-based testing, keychain & data-at-rest review, runtime manipulation.
- Static (SAST) and dynamic (DAST) mobile analysis.
Scripting & Networking
- Scripting in Python and/or Bash for automation and custom PoCs.
- Solid networking fundamentals and Linux proficiency.