Principal Mobile SME (Offensive Security)
Location : Bangalore, Pune, Hyderabad.
The Principal Mobile SME (Offensive Security) supports the Mobile Cyber Fusion Cell, by bringing an deep expertise of attacks against applications on end-user mobile devices and using security research and testing methodologies to help uplift the cybersecurity posture of HSBC’s customer mobile applications.
The role holder will sit within the Offensive Security function and embed in the Mobile Cyber Fusion Cell where they will work alongside malware experts, mobile developers, and other key technical SMEs to help the Bank respond to the ever-changing set of cybersecurity attacks against mobile banking applications.
The role holder will be testing known Tactics, Techniques and Procedures to ensure efficacy of preventative an detective controls and applying SME knowledge to get ahead of the attacker.
The role holder may be required to be flexible and able to perform varying duties depending on the shifting needs of the function.
What you’ll do : (List out Key Responsibilities)
- Perform highly technical analysis of known TTPs leading to mobile app fraud, enhance testing methodologies for other Offensive Security services to consume, and develop proof-of-concept malware to replicate TTPs in a controlled manner
- Clearly and professionally document root cause and risk analysis of all findings
- Adhere to the security testing process and raise any gaps or opportunities for improvement with manager.
- Work closely with the Mobile Cyber Fusion Cell to build a common understanding of mobile app fraud.
- Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks.
- Other responsibilities as assigned.
What you will need to succeed in the role :
At least 5 years of prior demonstrable hands-on experience in penetration testing or security research.Solid understanding of the platform security models for iOS and Android platforms.Excellent understanding of platform-specific security risks, common vulnerabilities for mobileapplications, common risks in financial applications.
Practical knowledge of penetration testing of widely understood infrastructure, web and mobiletechnologies, using manual and automated testing methods.
Proven programming / scripting skills, ideally in Java / Kotlin / Objective C / Swift.Working knowledge of reverse engineering mobile apps.Ability to explain security functionality from first principles.Ability to adapt and apply known techniques to unfamiliar situations.What additional skills will be good to have :
Strong grasp of common technologies, protocols and architectures commonly used by mobileapplication. (HTML, XML, JavaScript, JSON, REST, Micro-services etc.)
Advanced knowledge of common security analysis tools and testing techniques especially for the mobile security space