Summary of Role
V-Key is one of the world’s leading deep-tech companies in mobile cyber-security. Our patented technology V-OS has been deployed by top banks, mobile payment providers, and governments to secure software solutions and protect more than 500 million users globally.
We are rapidly expanding into new markets and new customer segments. Apart from securing digital transactions for everyone, we are also enabling new generation technology by providing the cyber-security infrastructure for banking, government and smart homes, among many others.
At V-Key, we are building towards a future where technology users can enjoy unprecedented security and convenience.
We are looking for a (Senior or Lead) Security Researcher, as part of the Product Security Team. Your primary focus will be to work with the team on cutting-edge Research and Development (R&D) of threats on mobile phones to develop innovative products and solutions to defend against such threats.
Duties and Responsibilities
- Research into threats (such as root/jailbreak and hiding thereof, app tampering, runtime tampering, etc.) in mobile phone operating systems and applications on Android / iOS / Harmony OS Next.
- Work with the team to develop protection mechanisms through reverse engineering, vulnerability research, exploitation and mitigation techniques and mobile/embedded development.
- Work with the team to perform penetration test on V-Key’s products and applications.
- Work with the team to script attacks and defences for mobile devices in general and for mobile applications.
- Develop customer-facing security attack and defense demonstrations.
- Work with the team on security solutions architectures involving not just the mobile device, but also other networked components, leveraging authentication protocols (OAuth2, FIDO2, etc.), and understanding and assessing cryptographic protocols and algorithms as needed.
Requirements
- Should have 5+years of experience into this relevant field.
- Good understanding of operating system internals (one or more of Android, iOS, Harmony OS Next, Linux, etc.) and app development (especially mobile).
- Familiar with rooting/jailbreaking, runtime tampering, app tampering, and tools that can be used to hide them.
- Familiar with attack and reverse engineering tools such as Frida, Theos, Ghidra, and IDA Pro.
- Familiar with web VAPT tools like Burp Suite.
- Familiar with how various tools/methodologies work, allowing innovation and creative solutions, not just comfortable using the tools as is.
- Good understanding of threat modelling, including familiarity with at least one threat modelling framework.
- A strong self-starter and able to work with minimal supervision, while still receptive to suggestions and ways to improve.
- Project ownership on selected projects.
- Guidance/mentorship of junior security researchers.
- Detail oriented with a strong focus on quality.
- Systematic and methodical in research and testing, while being creative and innovative.
- Ability to work in a dynamic, fast moving and growing environment.
- Positive work attitude, proactive and highly driven.
- Critical thinker and problem-solving skills.
- Team player with great interpersonal and communication skills.
Nice to have
- Degree in Computer Science, Information Systems, Math (especially related to cryptography) or related field.
- Certifications related to information security, ethical hacking, security solution design.
- Have built tools/scripts to help with various security research tasks.
Skills Required
- 5+ years relevant experience
- Strong understanding of OS internals (Android, iOS, Harmony OS, Linux) and mobile app development
- Familiarity with rooting/jailbreaking, runtime tampering, app tampering and concealment techniques
- Experience with reverse engineering and exploitation tools (Frida, Theos, Ghidra, IDA Pro)
- Familiarity with web VAPT tools such as Burp Suite
- Ability to innovate beyond tool use and develop custom attack/defense techniques and scripts
- Experience with threat modelling and at least one threat modelling framework
- Experience performing penetration tests on products and applications
- Experience developing customer-facing attack and defense demonstrations
- Familiarity with authentication and cryptographic protocols (e.g., OAuth2, FIDO2) and assessing crypto algorithms
- Self-starter able to work with minimal supervision and take project ownership
- Experience mentoring or guiding junior security researchers
- Detail-oriented, systematic researcher with strong problem-solving and communication skills
- Degree in Computer Science, Information Systems, Math or related field
- Information security or ethical hacking certifications and security solution design certifications
- Experience building tools/scripts for security research tasks
What We Do
V-Key is a global leader in software based digital security, and is the inventor of V-OS, the world's first virtual secure element. FIPS 140-2 Validated and accredited by IMDA, V-Key's Security, Authorization, and Verification solutions are used widely across banking and government mobile and digital platforms across the region. ★ The World's First Deployed by top banks, mobile payment providers, and governments globally, V-OS is the world’s first virtual secure element. With V-OS as a strong security base, V-Key is able to provide a complete mobile application security for any mobile application. Our solutions allow businesses to roll out cloud-based payments, trusted authentication for mobile banking, and other secured mobile applications for user data protection without the need to use any form of hardware secure elements. After all, software security is the new hardware. ★ Certified Cryptography Using a FIPS 140-2 certified module for cryptographic assurance, our solutions have been accredited and accepted by multiple government agencies and regulatory bodies globally. The hardened V-OS virtual machine has been proven in multiple penetration tests to be able to withstand many classes of hacking attacks that are rarely protected against – challenging security standards previously held by hardware tokens. This allows our customers to easily comply with stringent regulatory requirements and other security requirements of cloud-based payments and mobile transactions. ★ Patented Protections V-OS has been architected and developed like a hardware encryptor in order to provide military-grade protection for your mobile app. Traditional tamper-protection relies on techniques such as code obfuscation, whitebox cryptography, and anti-tampering / anti-debugging mechanisms. V-Key tightly integrates these best-of-breed techniques into the V-OS virtual machine in a groundbreaking manner in order to create a reinforcing system of protection. (tag: vkey, mobile app protection, digital identity, 2fa, mfa)









