Neumeric Technologies Corporation - Plano, TX
posted 5 months ago
The Product Security Engineer for Mobile Application Security will play a crucial role in ensuring the security of mobile applications, specifically focusing on Android and iOS platforms. This position requires a highly technical and passionate individual who is self-driven and eager to learn and solve complex problems. The engineer will be responsible for conducting comprehensive security testing, which includes both manual and automated assessments, to verify security requirements such as the Mobile Application Security Verification Standard (MASVS) and Common Weakness Enumerations (CWEs). In this role, the engineer will perform security assessments and penetration testing, which encompasses mobile application binary analysis, source code review, inter-process communication (IPC) analysis, and software development kit (SDK) analysis. A significant part of the job involves analyzing the application sandbox on both iOS and Android platforms to identify privilege issues. The engineer will also participate in mobile application development, facilitating the development and verification of security requirements. The engineer will be tasked with identifying various security vulnerabilities, including hardcoded secrets, insecure storage, insecure communication, improper permissions, sensitive data disclosures, and insecure data validation within platform features such as DeepLinks and Exported Activities/Content Providers. Additionally, the engineer will need to identify weak or deprecated algorithms used in third-party and internal libraries. The role requires producing detailed reports and artifacts, offering remediation recommendations, and providing support to enhance the security posture of mobile applications. Familiarity with the Mobile Security Testing Guide is essential, as the engineer will leverage this framework to test both iOS and Android applications. Participation in various security projects, technical design reviews, code reviews, and test specifications will also be part of the responsibilities.