The Role
Perform manual and automated security testing of Android and iOS mobile applications supporting digital payment ecosystems. Conduct dynamic analysis, runtime instrumentation, reverse engineering, API testing, and payment-flow security assessments. Identify vulnerabilities, develop proof-of-concept exploits and custom scripts, report findings, support remediation and retesting, and research emerging attack vectors. Collaborate with development and product teams while contributing to security tools, methodologies, and knowledge sharing.
Summary Generated by Built In
Key Responsibilities
- Perform security testing of Android and iOS mobile applications used in digital payment ecosystems
- Conduct manual and automated mobile security testing aligned with:
- OWASP Mobile Top 10
- OWASP MASVS & MSTG
- Identify vulnerabilities related to:
- Insecure data storage
- Weak cryptography
- Insecure communication
- Authentication & authorization flaws
- Business logic issues in payment flows
- Perform runtime instrumentation and dynamic analysis using:
- Frida, Objection, Xposed
- Reverse engineer mobile applications using:
- APKTool, JADX (Android)
- Basic iOS reverse engineering tools (class-dump, Hopper, Ghidra)
- Intercept and analyze mobile traffic using:
- Burp Suite (Mobile Assistant preferred)
- mitmproxy / Charles Proxy
- Test mobile backend APIs supporting payment workflows using:
- Burp Suite, Postman
- Validate security of payment features, including:
- UPI, wallets, cards, tokenization
- OTP, MFA, session management
- Prepare high-quality vulnerability reports with:
- Risk assessment
- Proof of Concept (PoC)
- Clear remediation guidance
- Support retesting and vulnerability closure
- Work closely with development and product teams to explain findings and fixes
R&D Mindset & Innovation (Mandatory)
- Strong research-driven mindset to explore vulnerabilities beyond standard checklists
- Ability to research and validate new attack vectors in mobile and FinTech environments
- Regularly analyze:
- New Android/iOS versions and security changes
- Advanced bypass techniques (SSL pinning, root/jailbreak detection)
- Develop custom test cases for complex payment and business logic scenarios
- Contribute to:
- Internal tools, scripts, and testing methodologies
- Knowledge sharing and security best practices
- Ability to independently validate false positives and negatives
Scripting & Automation Skills (Mandatory)
- Hands-on scripting experience in one or more of the following:
- Python – automation, PoC development, API testing
- JavaScript – Frida hooks and runtime manipulation
- Bash – automation and tooling
- Ability to:
- Write and modify custom Frida scripts
- Automate repetitive testing and analysis tasks
- Customize open-source tools for specific app behaviors
- Strong understanding of secure coding flaws through runtime and code-level analysis
Mandatory Skills & Experience
- 3–4 years of experience in mobile application security testing
- Strong understanding of Android and iOS security architectures
- Hands-on experience with:
- MobSF, AndroBugs, QARK
- Frida, Objection
- Burp Suite
- Experience testing BFSI / FinTech / Digital Payment applications
- Strong knowledge of:
- OWASP Mobile Top 10
- OWASP API Top 10 (supporting APIs)
Good to Have
- Exposure to PCI-DSS, RBI, or CERT-In security requirements
- Experience with CI/CD integration for mobile security testing
- Basic understanding of cloud and backend security supporting mobile apps
- iOS security testing experience is a strong plus
Skills Required
- 3–4 years of experience in mobile application security testing
- Strong understanding of Android and iOS security architectures
- Hands-on experience with MobSF, AndroBugs, QARK, Frida, Objection, and Burp Suite
- Experience testing BFSI, FinTech, or digital payment applications
- Strong knowledge of OWASP Mobile Top 10 and OWASP API Top 10
- Hands-on scripting experience with Python, JavaScript, or Bash
- Ability to write and modify custom Frida scripts
- Strong research-driven mindset for discovering and validating new mobile and FinTech attack vectors
- Exposure to PCI-DSS, RBI, or CERT-In security requirements
- Experience integrating mobile security testing into CI/CD
- Basic understanding of cloud and backend security supporting mobile applications
- iOS security testing experience
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Talakunchi Networks Private Limited is a global information-security consulting company that helps organizations protect their IT infrastructure. Its services include vulnerability assessment and penetration testing (VAPT), website and network security audits, threat monitoring and management, security consulting, compliance audits, exposure scanning, governance, risk, and compliance support, and security training. The company has been a CERT-In-empanelled IT security auditor since 2018.








