Perform hands-on compliance testing of mobile applications against technology security standards and regulatory / industry requirements, including Monetary Authority of Singapore Technology Risk Management (MAS TRM) guidelines and OWASP Foundation Mobile Security Testing Guide (MSTG).
Demonstrate strong knowledge of iOS and Android architectures, including their underlying security controls and mechanisms.
Conduct secure code reviews for mobile applications developed in Swift, Kotlin, Objective-C, and Java.
Utilize reverse engineering and dynamic analysis tools such as IDA Pro, Ghidra, and Frida or equivalent tools.
Familiarity with architectures such as armeabi-v7a, arm64-v8a, and related runtime environments is advantageous.
Assess and bypass security controls commonly implemented in mobile applications, including SSL pinning, root/jailbreak detection, anti-tampering controls, in-app VPNs, and similar protections.
Develop custom extensions or plugins for Burp Suite to enhance mobile and web application testing.
Conduct web application penetration testing using industry-standard methodologies and frameworks.
Perform comprehensive source code reviews across multiple technology stacks, including mobile, web, and backend systems.
Conduct web and infrastructure security assessments, vulnerability validation, and technical reporting.
Qualifications & Skills
Bachelor's degree in Computer Science, Information Security, or a related discipline.
Minimum 2 years of hands-on penetration testing or relevant offensive security experience.
CREST CRT certification is mandatory.
Additional certifications such as OffSec OSCP, OSCE, OSEE, OSWE, Red Teaming, Cloud Security, or AI Security certifications are highly advantageous.
Strong verbal and written communication skills, with the ability to clearly present technical findings to both technical and non-technical stakeholders.
Excellent organizational and time management skills, with the ability to manage multiple engagements and meet tight deadlines.
Self-motivated, proactive, and capable of working independently as well as collaboratively within a team.