Perform manual and automated security testing of Android and iOS mobile applications supporting digital payment ecosystems. Conduct dynamic analysis, runtime instrumentation, reverse engineering, API testing, and payment-flow security assessments. Identify vulnerabilities, develop proof-of-concept exploits and custom scripts, report findings, support remediation and retesting, and research emerging attack vectors. Collaborate with development and product teams while contributing to security tools, methodologies, and knowledge sharing.
Key Responsibilities
- Perform security testing of Android and iOS mobile applications used in digital payment ecosystems
- Conduct manual and automated mobile security testing aligned with:
- OWASP Mobile Top 10
- OWASP MASVS & MSTG
- Identify vulnerabilities related to:
- Insecure data storage
- Weak cryptography
- Insecure communication
- Authentication & authorization flaws
- Business logic issues in payment flows
- Perform runtime instrumentation and dynamic analysis using:
- Frida, Objection, Xposed
- Reverse engineer mobile applications using:
- APKTool, JADX (Android)
- Basic iOS reverse engineering tools (class-dump, Hopper, Ghidra)
- Intercept and analyze mobile traffic using:
- Burp Suite (Mobile Assistant preferred)
- mitmproxy / Charles Proxy
- Test mobile backend APIs supporting payment workflows using:
- Burp Suite, Postman
- Validate security of payment features, including:
- UPI, wallets, cards, tokenization
- OTP, MFA, session management
- Prepare high-quality vulnerability reports with:
- Risk assessment
- Proof of Concept (PoC)
- Clear remediation guidance
- Support retesting and vulnerability closure
- Work closely with development and product teams to explain findings and fixes
R&D Mindset & Innovation (Mandatory)
- Strong research-driven mindset to explore vulnerabilities beyond standard checklists
- Ability to research and validate new attack vectors in mobile and FinTech environments
- Regularly analyze:
- New Android/iOS versions and security changes
- Advanced bypass techniques (SSL pinning, root/jailbreak detection)
- Develop custom test cases for complex payment and business logic scenarios
- Contribute to:
- Internal tools, scripts, and testing methodologies
- Knowledge sharing and security best practices
- Ability to independently validate false positives and negatives
Scripting & Automation Skills (Mandatory)
- Hands-on scripting experience in one or more of the following:
- Python – automation, PoC development, API testing
- JavaScript – Frida hooks and runtime manipulation
- Bash – automation and tooling
- Ability to:
- Write and modify custom Frida scripts
- Automate repetitive testing and analysis tasks
- Customize open-source tools for specific app behaviors
- Strong understanding of secure coding flaws through runtime and code-level analysis
Mandatory Skills & Experience
- 3–4 years of experience in mobile application security testing
- Strong understanding of Android and iOS security architectures
- Hands-on experience with:
- MobSF, AndroBugs, QARK
- Frida, Objection
- Burp Suite
- Experience testing BFSI / FinTech / Digital Payment applications
- Strong knowledge of:
- OWASP Mobile Top 10
- OWASP API Top 10 (supporting APIs)
Good to Have
- Exposure to PCI-DSS, RBI, or CERT-In security requirements
- Experience with CI/CD integration for mobile security testing
- Basic understanding of cloud and backend security supporting mobile apps
- iOS security testing experience is a strong plus
Similar Jobs
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads complex, cross-functional scientific learning projects for Medical Affairs. Develops curricula, e-learning, and blended learning programs; partners with medical, scientific, agency, and learning systems teams; manages multiple projects, timelines, budgets, and priorities; evaluates emerging e-learning technologies; and updates existing learning resources across therapeutic areas.
Top Skills:
Articulate StorylineDigital Learning TechnologyE-Learning Authoring ToolsLearning Management Systems
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Leads multiple software engineering teams through new product development from concept to implementation. Provides technical and strategic leadership across architecture, Java and Spring-based applications, cloud-native systems, microservices, CI/CD, quality initiatives, automation, and real-time platforms. Manages stakeholders, project metrics, cross-location coordination, business execution, team development, and strategic technology direction while ensuring consistent delivery and security practices.
Top Skills:
AICi/CdDigital Native ArchitectureJavaMicroservicesPivotal Cloud FoundryReal-Time Online SystemsScaled Agile FrameworkSpring BootSpring Framework
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Designs, develops, tests, deploys, and maintains secure software solutions across the full SDLC. Leads technical solution planning, production support, incident remediation, technology evaluations, and proof-of-concept initiatives. Creates technical documentation, ensures testing and quality compliance, coordinates offshore development, supports vendor collaboration, and mentors team members through training and knowledge transfer.
What you need to know about the Mumbai Tech Scene
From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.


