Malware Reverse Engineer - Android

Malware Reverse Engineer - Android

Full-Time 45000 - 55000 £ / year (est.) Home office (partial)
Reversec

At a Glance

  • Tasks: Investigate and reverse engineer Android malware, developing detection tools and contributing to security research.
  • Company: Join Reversec, a leading cyber security consultancy with a focus on innovation and collaboration.
  • Benefits: Receive structured training, mentoring, and opportunities for professional growth in a dynamic environment.
  • Other info: Flexible roles available for all experience levels, from aspiring engineers to seasoned analysts.
  • Why this job: Make a real impact in the cyber security field while working with cutting-edge technology.
  • Qualifications: Strong programming skills and a passion for Android security are essential; experience is a plus.

The predicted salary is between 45000 - 55000 £ per year.

At Reversec, we deliver research-led cyber security services that help organisations defend against real-world threats and build long-term resilience. Our consultants are a diverse team of highly skilled technical experts, researchers, and creative problem-solvers who are passionate about advancing the cyber security industry. We believe great consultants are empowered consultants. Our people take ownership of their professional development, contribute to meaningful research, and have the freedom to shape the way we work. If you're driven by curiosity, enjoy solving complex technical challenges, and thrive in an environment that values innovation and continuous learning, we'd love to hear from you.

The Role

Reversec is a specialist security consultancy built on deep technical expertise, research, and real-world security engineering. Our consultants regularly analyse highly obfuscated software, reverse engineer complex applications, develop custom tooling, and contribute to open-source security projects used throughout the industry. Reversec maintains Android security tooling such as Drozer and invests heavily in research-led capability development. We are seeking Android reverse engineers and malware analysts across all experience levels (from those building their skills to seasoned experts) to join a specialist team supporting one of the world's largest technology platforms.

As an Android Malware Reverse Engineering Analyst, you will investigate complex and evasive Android applications, identify malicious functionality, conduct detailed reverse engineering, and support automated detection development. You will work as part of a specialist malware analysis team responsible for investigating applications that fall outside standard analysis processes and require advanced technical expertise. This includes malware research, incident investigations, escalation handling, detection engineering, and quality assurance activities. We're recruiting analysts across multiple career stages, from aspiring reverse engineers to experienced malware researchers. Your responsibilities and the expectations placed on you will depend directly on the experience you bring. Experienced analysts will take on complex samples and investigations with a high degree of independence, provide mentorship to junior team members, and assist in developing internal tooling and processes. Analysts earlier in their careers will carry out similar categories of work, with closer support and a remit that grows as their skills develop. Wherever you start, training will be available to bring you up to the standard the team works to.

Key Responsibilities

  • Malware Reverse Engineering
    • Perform detailed static and dynamic analysis of Android applications and SDKs.
    • Analyse heavily obfuscated Java/Kotlin applications, native code, and framework applications (e.g., Flutter, .NET MAUI, React Native).
    • Investigate packers, in-memory loading techniques, encrypted payloads and anti-analysis mechanisms.
    • Determine application behaviour and identify potentially harmful functionality.
    • Conduct complex investigations into suspicious applications and malware campaigns.
    • Support escalations and urgent high-priority investigations.
    • Analyse internal and external malware leads.
    • Identify indicators, behaviours, attack techniques and attacker objectives.
  • Detection Engineering
    • Develop and validate detection logic and automated rules.
    • Support improvements to malware detection capabilities.
    • Work with analysts and engineering teams to improve investigative efficiency.
  • Quality & Peer Review
    • Review analysis performed by other analysts.
    • Validate technical findings and enforcement decisions.
    • Ensure consistent technical standards and reporting quality.
  • Research & Tool Development
    • Develop one-off tools, scripts and automation to support investigations.
    • Contribute to internal research initiatives.
    • Stay current with evolving Android threats, malware techniques and analysis methodologies.

Experience and Expectations

We do not require a fixed profile. Instead, we will calibrate expectations to the experience you bring. In all cases, you will need:

  • Strong programming fundamentals in at least one object-oriented language.
  • A genuine interest in Android internals and how malicious software works.
  • An investigative mindset– curiosity, persistence, and attention to detail.
  • Clear written and spoken communication in English.

If you are an experienced analyst, we expect proven experience in one or more of: Android malware analysis, Android application security testing, mobile application reverse engineering, malware research, threat research, or mobile threat intelligence. You should be able to demonstrate skills across Java and Android internals, Smali and DEX analysis, Android application architecture, static and dynamic analysis techniques, analysis of obfuscated code, native Android libraries (C/C), and scripting or tool development (e.g. Python). In return, you will be trusted to work independently on complex cases from an early stage, lead urgent escalations, review the work of others and mentor colleagues. If you are earlier in your career, we do not expect the above on day one. Show us evidence that you enjoy understanding how software works and are actively developing technical security skills - CTFs, crackmes, personal reverse engineering projects, relevant coursework or published write-ups. You will receive structured training and mentoring to bring you up to the team's standard, and your responsibilities will expand as your capability does. Candidates anywhere between these two points are equally welcome: tell us what you can already do, and we will shape both expectations and training around it. Work is allocated according to capability and experience. All analysts receive structured mentoring, peer review and continuous technical development.

Technical Skills

An ideal candidate will demonstrate experience with some of the following:

  • Reverse engineering and static analysis – use of decompilers and disassemblers, particularly to tackle heavily obfuscated code, native libraries, and custom cryptography.
  • Dynamic analysis – frameworks like Frida and LSPosed particularly welcome.
  • Malware analysis – detection development, behavioural analysis.

Why Join Reversec?

We’ll invest in you too – through internal training, mentoring, and room to develop. What you build here won’t stay internal: our tooling, research, and methodologies are used throughout the security community.

Advice for Candidates

We expect this role to attract a significant number of applications. If you want yours to stand out, focus on helping us understand what is genuinely relevant about you. We genuinely read covering letters, and they often make the difference between two otherwise similar applications. A covering letter is your opportunity to explain:

  • Why this area of security interests you.
  • What relevant experience, projects, research, or personal work you've completed.
  • What you've been learning recently.
  • Why you believe your skills are relevant to the role.

Don't tell us what you think we want to hear. Tell us what genuinely interests you. A candidate who can clearly explain why they enjoy reverse engineering Android applications, analysing malware, writing tooling, researching software internals, or investigating complex technical problems will stand out far more than a generic application submitted to dozens of employers.

Tell Us What Excites You About the Subject

We're much more interested in why you're interested in the work than why you're interested in Reversec. We're looking for people who are excited by questions such as:

  • How does this application actually work?
  • What is this code trying to hide?
  • Why is this behaviour occurring?
  • How can this analysis be automated?
  • How can software be understood more deeply?

Genuine curiosity and enthusiasm for the subject are often stronger indicators of success than a particular certification or job title.

Differentiating Yourself

What you've built. What you've researched. What you've reverse engineered. What you've learned outside of formal education or employment. What areas of Android security or malware analysis genuinely interest you. Relevant personal projects, technical write-ups, open-source contributions, tooling, university work, challenge participation, and research are all valuable evidence of interest and capability.

What to Expect from the Recruitment Process

Our recruitment process is designed to help both sides determine whether this is the right fit.

Step One - CV Review

Our team will review your application to understand your background, technical skills, experience, aptitude and overall suitability for the role. We are not looking for a perfect checklist match. We're looking for evidence of capability, potential, curiosity, and genuine interest in the subject matter.

Step Two - Initial Interview

You’ll meet with a member of our team to discuss the role, your background, and your experience. This conversation is as much for you as it is for us. We're assessing whether the role is a good fit for your skills and aspirations, while giving you the opportunity to understand the work we do, the team you'll be joining, and whether Reversec is the right fit for you.

Step Three - Technical Challenge

Candidates who successfully complete the initial interview will be invited to complete a technical challenge. The challenge will be representative of the type of work performed by the team and may include activities such as reverse engineering, malware analysis, software investigation, tooling development, or technical problem solving. You’ll be provided with instructions, any required files or supporting material, and a defined timeframe in which to complete the exercise. We expect candidates to work independently and document their findings as they go. Your output should explain:

  • Your approach to the problem.
  • The analysis you performed.
  • Any findings or conclusions you reached.
  • Any limitations, assumptions, or questions that remain unanswered.

There is rarely a single "correct" answer. We are interested not only in whether you reach the right conclusion, but also in how you think, how you investigate technical problems, and how clearly you communicate your findings. This challenge will be timebound; however we understand applicants may have work and personal commitments, and we are happy to discuss reasonable adjustments where required. Completed challenges should be returned to the hiring manager within the specified timeframe.

Step Four - Technical Interview

You'll meet with members of the technical team for a deeper discussion around your technical background, problem-solving approach, and relevant experience. The goal is not to catch you out or test obscure facts. We want to understand how you think, how you approach technical challenges, and how your skills align with the work we perform. For experienced candidates, this may involve detailed discussions around reverse engineering, malware analysis, security research, development, or tooling. For less experienced candidates, we're often just as interested in your reasoning, curiosity, and willingness to learn.

Malware Reverse Engineer - Android employer: Reversec

At Reversec, we pride ourselves on being an exceptional employer that fosters a culture of innovation and continuous learning. Our commitment to employee development is evident through structured training and mentorship opportunities, allowing you to grow your skills in a dynamic environment while contributing to meaningful research in cyber security. With offices in both London and Manchester, we offer a collaborative workspace that values diversity and empowers our consultants to take ownership of their professional journeys.

Reversec

Contact Details:

Reversec Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Malware Reverse Engineer - Android

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Reversec, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Reversec

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Reversec. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Malware Reverse Engineer - Android

Malware Reverse Engineering
Static Analysis
Dynamic Analysis
Java
Kotlin
Android Internals
Obfuscated Code Analysis

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Reversec insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Reversec that you’re committed to staying ahead in the game.

How to prepare for a job interview at Reversec

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Reversec to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Reversec.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.