At a Glance
- Tasks: Conduct mobile app penetration tests and identify security vulnerabilities.
- Company: Join NetSPI, a leader in innovative security solutions.
- Benefits: Competitive salary, flexible work hours, and opportunities for professional growth.
- Why this job: Make a real impact on security for top companies while working with cutting-edge technology.
- Qualifications: 2-3 years in application penetration testing and familiarity with security tools.
- Other info: Collaborative culture with a focus on innovation and career development.
The predicted salary is between 36000 - 60000 £ per year.
NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001. NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team.
We are seeking a skilled and detail-oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting mobile applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
Responsibilities
- Conduct penetration testing engagements on mobile applications and underlying APIs.
- Identify insecure data storage, communications, or cryptography in mobile applications.
- Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture.
- Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes.
- Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.
Minimum Qualifications
- Bachelor’s degree or higher required, with a concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent experience.
- Minimum of 2-3 years of work experience in application penetration testing.
- Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus, Frida, Drozer, Objection, Ghidra).
- Understanding of mobile application data security, communications, and sandboxes.
- Knowledge of Android and iOS operating systems.
- Familiarity with offensive and defensive IT concepts and protocols.
- Extensive understanding of the OWASP Top 10 and various security frameworks.
- Working knowledge of Windows, Linux and MacOS operating systems internals.
- Ability to work independently and as part of a team.
- Proficient communication skills, both written and verbal.
- Willingness to travel up to 5-10%.
- This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs.
Preferred Qualifications
- Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences.
- Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#).
- Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, CISSP, GWAPT).
- Experience in ARM reverse engineering.
- Experience developing Frida tools to bypass application protections or exploit vulnerabilities.
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.
Security Consultant II (Mobile Application Penetration Tester) employer: NetSPI
Contact Detail:
NetSPI Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Consultant II (Mobile Application Penetration Tester)
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or conferences related to penetration testing. It's a great way to connect with potential employers and other professionals who can give you the inside scoop on job openings.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your penetration testing projects, tools you've developed, or any innovative techniques you've used. This will help you stand out and demonstrate your expertise to potential employers.
✨Tip Number 3
Don’t just apply blindly! Tailor your approach for each application by researching the company and its culture. Mention specific projects or values that resonate with you in your conversations to show you're genuinely interested.
✨Tip Number 4
Apply through our website! We love seeing candidates who take the initiative to engage directly with us. Plus, it gives you a chance to learn more about our award-winning workplace culture and the exciting growth journey we're on.
We think you need these skills to ace Security Consultant II (Mobile Application Penetration Tester)
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Consultant II role. Highlight your experience in mobile application penetration testing and any relevant tools you've used. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Share your passion for security and how you can contribute to our mission at NetSPI. Be sure to mention any innovative techniques or methodologies you've developed in your previous roles.
Showcase Your Communication Skills: Since you'll be delivering reports and collaborating with clients, it's crucial to demonstrate your communication skills. Use clear and concise language in your application materials to show us you can convey complex information effectively.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll find all the details you need about the role and our awesome company culture there!
How to prepare for a job interview at NetSPI
✨Know Your Tools Inside Out
Make sure you’re familiar with the offensive tools mentioned in the job description, like Kali Linux and Burp Suite. Brush up on how to use them effectively, as you might be asked to demonstrate your skills or discuss your experience with these tools during the interview.
✨Understand Mobile Security Fundamentals
Since this role focuses on mobile application penetration testing, it’s crucial to have a solid grasp of mobile data security, communications, and the OWASP Top 10. Prepare to discuss specific vulnerabilities you've encountered and how you addressed them in past projects.
✨Prepare for Scenario-Based Questions
Expect scenario-based questions that assess your problem-solving skills. Think about past experiences where you identified vulnerabilities or improved security postures. Be ready to explain your thought process and the steps you took to resolve issues.
✨Show Your Collaborative Spirit
NetSPI values a collaborative mindset, so be prepared to discuss how you’ve worked with teams in the past. Share examples of how you’ve mentored others or contributed to team projects, highlighting your ability to communicate effectively and work towards common goals.