Want to know if you’re a fit? Upload your resume and let our AI show you.
Skills
Analysis Skillsunmatched
Androidunmatched
Android Applicationsunmatched
Application Programming Interface (API)unmatched
Authenticationunmatched
Automationunmatched
Code Reviewsunmatched
Computer Engineeringunmatched
Computer Networksunmatched
Computer Scienceunmatched
Computer Securityunmatched
Cryptographyunmatched
Database Programming Languagesunmatched
Dynamic Analysisunmatched
IDA Prounmatched
Information Technology & Information Systemsunmatched
Javaunmatched
JavaScriptunmatched
Kotlinunmatched
Malwareunmatched
Mobile Applicationsunmatched
Network Protocolsunmatched
Network Securityunmatched
OSINT (Open Source Intelligence)unmatched
Process Improvementunmatched
Reporting Skillsunmatched
Reverse Engineeringunmatched
SQL (Structured Query Language)unmatched
Security Analysisunmatched
Software Developmentunmatched
Software Engineeringunmatched
Static Analysisunmatched
Virusesunmatched
Description
NSS is currently hiring for an Android Malware Reverse Engineer to support a well known client. This individual is required to be onsite 3 days a week with 2 days remote, in their respective locations including Austin, Texas, Bothell, WA, or San Jose, CA.
The Android Malware Reverse Engineers will conduct reverse engineering, security assessments, and code reviews. You will conduct and assist with complex decompilation, unpacking, code review and malicious mobile software reviews. The goal of the work is to identify families of malware and act on apps at scale. You will be responsible for developing static and dynamic signatures for mobile code, binaries, and executable code leading to the detection of a variety of threat types including malware, potentially unwanted programs (PUPs) and advanced persistent threats. Additionally, you will identify weaknesses in detections and automations and make recommendations for improvements in the detection process and automation pipeline. You are required to write complex reports for consumption of non-technical audiences, review peer reports and assist with investigations.
Requirements:
Hands on Experience with the following:
Analyzing, unpacking, and reverse engineering code of malicious applications or SDKs.
Static and Dynamic Analysis Techniques
Reverse Engineering tools such as Jadx, Ghidra, Frida, IDA Pro, Burp, to perform binary and APK analysis
Java, Kotlin, JavaScript, Flutter, and other mobile software languages
ELF (Native Binaries) reverse engineering
Query languages such as SQL
Understanding of the following topics
Android Fundamentals such as Android activity lifecycles, common Android API usage, AOSP, and how an android application is created.
Java and/or Kotlin Programing Language
Techniques utilized by malicious software to harm the user’s device or their data
Mobile App store policies (Ads, PHAs, Developer, etc.)
Ability to read, comprehend and analyze source code
Additional:
Development of signatures (Yara, etc.)
Research on threats such as APT using Open-Source Intelligence (Virus Total, Web, ExploitDB, MITRE, etc.)
In depth knowledge of security engineering and analysis topics, computer and network security, cryptography, authentication security, rooting, packing, network protocols and interception
Nice to Have:
Experience with Vulnerability Analysis or security code review
Android Software Development Experience
Background / Familiarity with Google Ads or Content moderation
Participation in a Capture the Flag (CTF) for Mobile software
Pentesting, Blue Team, and/or Red Team experience
Professional Experience and Education
Required:
None
Preferred:
Associates/Bachelor’s Degree/master’s in computer science, computer engineering, CS, or information systems, or related discipline.
3-5 years of hands on Android and reverse engineering