Mobile App Security & Reverse Engineering Intern
Decompile Android APKs, inspect iOS bundles, bypass SSL pinning with Frida, analyze API communications, and audit mobile app security posture.
Role Overview & Operational Scope
Mobile applications are primary entry points for enterprise services. You will learn the art of mobile reverse engineering, analyzing binary packages, inspecting runtime behavior, and securing mobile client-server transactions.
Key Responsibilities & Production Deliverables
- Perform static analysis on Android APKs using Jadx, MobSF, and Apktool.
- Configure emulators and physical devices with Frida and Objection to bypass SSL pinning and root detection.
- Intercept and assess mobile API communications in Burp Suite for authentication and authorization flaws.
- Verify compliance against OWASP Mobile Application Security Verification Standard (MASVS).
- Compile actionable remediation reports with concrete source-code level guidance for mobile developers.
Mandatory Foundational Knowledge
- Understanding of the Android operating system architecture (Manifest, Activities, Services, Content Providers).
- Familiarity with mobile networking, certificate pinning, and client-side storage mechanisms (SharedPreferences, SQLite, Keychain).
- Basic familiarity with Java, Kotlin, or Swift.
Mandatory Practical Skills & Architecture
- Hands-on experience running Jadx, MobSF, or Android Studio.
- Ability to proxy mobile device traffic through Burp Suite.
- Basic understanding of how to run Frida scripts for runtime instrumentation.
Problem Solving, Execution Rigor & Curiosity
- Fascination with understanding how compiled applications execute on user devices.
- Tenacious problem-solver who enjoys working through anti-tamper protections ethically.
- Pride in delivering comprehensive, developer-friendly remediation reports.
5-Day Live Technical Evaluation Milestone
5-Day Live Practical Milestone: Decompile and evaluate a synthetic Android test application, bypass its root detection and certificate pinning, and extract a proof-of-concept secret key (strictly 5 working days). Successful completion qualifies for immediate PPO review.
Institutional Hiring Protocol: Candidates who pass initial resume screening are invited to a live, practical evaluation milestone spanning strictly not more than 5 working days. Verifiable completion and code audit by your assigned senior engineering mentor is the sole prerequisite for official corporate offer letter issuance.
Compensation, Total Rewards & Advancement
- Monthly paid fellowship (₹12,000–₹20,000/month).
- Direct PPO track into Full-Time Mobile Security Engineer (₹8,00,000–₹14,00,000 CTC).
- Direct mentorship from experienced mobile security consultants.
- Fully remote setup with flexible hours.
Dedicated Inquiries Inbox for This Role
Have questions regarding architecture scope or wish to share private research repos directly? Messages sent to this address route straight to the engineering leads reviewing this opening.
mobile-security-reverse-engineer-careers@cehpoint.co.in
Open Mail Client →