Android Penetration Tester Needed

via Freelancer ·

Budget / Salary€8–30
TypeFreelance project
LocationRemote
Posted1 hour ago
# Android Security Researcher / Ethical Hacker
## Penetration Testing of BlowFish Android Security Platform

### Project Overview

BlowFish is an Italian cybersecurity technology company developing solutions for **secure communications, mobile security and privacy**.

We are looking for an experienced **Android Security Researcher / Ethical Hacker** to perform an authorized penetration test of our Android-based security solution.

The goal is to identify vulnerabilities, weaknesses and potential attack vectors that could compromise the application, the device, communications or sensitive data.

All testing will be performed **only against systems, devices, applications and accounts provided by BlowFish and within an agreed testing scope**.

### What you will test

The engagement may include:

- BlowFish Android application;
- APK and application components;
- authentication and session management;
- local storage and sensitive data handling;
- network communications;
- APIs used by the application;
- cryptographic key and data handling;
- Android permissions and application components;
- IPC and Android components;
- Accessibility Services and other sensitive Android capabilities;
- reverse-engineering and tamper resistance;
- TLS and certificate pinning;
- traffic interception and manipulation;
- static and dynamic application analysis;
- privilege escalation opportunities;
- security of connected infrastructure;
- potential attack paths against the mobile environment;
- malware/spyware-related attack scenarios where relevant.

### Required skills

We are looking for someone with **hands-on experience in Android security and mobile penetration testing**.

Relevant experience includes:

- Android security internals;
- ADB;
- APK analysis;
- reverse engineering;
- static and dynamic analysis;
- Frida;
- Burp Suite;
- JADX / apktool;
- Android Emulator and physical Android devices;
- network traffic analysis;
- API security testing;
- authentication and session security;
- Android cryptography;
- anti-debugging and anti-tampering analysis;
- vulnerability research and exploitation in authorized environments.

Knowledge of **OWASP MASVS and MASTG** is strongly preferred.

Experience with Android malware, spyware, secure communication applications or cryptographic applications is a significant advantage.

### What we are looking for

We are **not looking for an automated vulnerability scan or a generic security report**.

We want someone who can think like a real attacker and determine:

**"What could an attacker actually do if this weakness were exploited?"**

For significant findings, we expect:

1. Technical description;
2. Affected component;
3. Severity/risk assessment;
4. Conditions required for exploitation;
5. Proof of concept where appropriate;
6. Technical evidence;
7. Security impact;
8. Potential attack path;
9. Recommended remediation.

### Deliverables

The final deliverable should include a technical penetration-testing report containing:

- Executive Summary;
- Testing methodology;
- Scope and limitations;
- Identified vulnerabilities;
- Severity classification;
- Technical evidence;
- Proofs of concept where applicable;
- Potential attack chains;
- Remediation recommendations;
- Additional areas requiring investigation, if identified.

A short technical debrief with the BlowFish team will also be required.

### Authorization and scope

**All testing will be explicitly authorized by BlowFish.**

Testing must be limited to the devices, applications, accounts, APIs and infrastructure included in the agreed scope.

No testing against third-party devices, accounts, networks or systems is authorized.

### To apply

Please provide:

- Your experience with Android penetration testing;
- Tools you regularly use;
- Relevant certifications, if any (OSCP, OSWE, OSEP, eWPTX, CREST or equivalent);
- Examples of previous Mobile Security Research or Android security projects, where you are able to disclose them;
- Your availability.

We are looking for someone who can **think like an attacker, work like a security researcher, and communicate findings clearly to a development team.**
android certified ethical hacking
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.