Mobile Application Security Engineer at 631 Booz Allen Hamilton_United States — Fort Meade, MD
Full job description
Mobile Application Security EngineerThe Opportunity:
Are you looking to build your problem-solving prowess in a rapidly evolving systems security research and engineering environment? You’re eager to learn how embedded application developers, reverse engineers, and vulnerability analysts all play key roles in the capability development life cycle. As a Mobile Application Security Engineer, you’ll have the opportunity to use skills in mobile operating system security, mobile application pen testing, and networking protocols to support our government clients. We’re looking for someone like you to have a direct impact on the nation’s security.
On our team, you’ll be involved in the full life cycle of mobile application security and solution design. Working on an agile team of experts, you’ll perform reverse engineering and vulnerability analysis of various software problems. You’ll inform operational parameters for complex systems and leverage automation and machine learning to influence the delivery of your work. You’ll determine what the art of the possible is, and what can be done, and then you’ll bring it to life for your clients. Are you ready to help us combat the most advanced adversaries?
Join us. The world can’t wait.
You Have:
- 2+ years of experience with iOS and Android mobile device operating systems
- Knowledge of static and dynamic mobile app security analysis concepts
- Knowledge of protocol and network analysis using Wireshark
- Knowledge of common mobile application vulnerabilities and mobile threats
- Secret clearance
- Bachelor's degree
Nice If You Have:
- Experience developing iOS and Android mobile applications
- Experience with reverse engineering tools and frameworks, such as Frida, APKtool, Jadx, MobSF, NowSecure, or Quokka
- Knowledge of common mobile application authentication and encryption methods, including OAuth and PKI
- Knowledge of the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Application Security Testing Guide (MASTG)
- Knowledge of OWASP Mobile Top 10 and the Mobile Security Testing Guide (MSTG)
- Possession of excellent verbal and written communication skills
- Security+, Certified Ethical Hacker (CEH), SANS Mobile Device Security, or Ethical Hacking Certification
Compensation
Identity Statement
Candidate AI Usage Policy
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination