Android Security & Authentication Engineer — APK Hardening
Budget / SalaryC$10–30
TypeFreelance project
LocationRemote
Posted2 hours ago
About the Project
We’re looking for an experienced Android/Kotlin security engineer to review and improve the authentication and networking security of an existing controller APK.
The primary focus is the Android client’s authentication, API communication, token handling, and security architecture. Experience with reverse engineering and dynamic instrumentation is highly valuable because the application also includes a JavaScript-injected agent, Unity/IL2CPP components, and native ARM64 code.
What You’ll Work On
Review the existing authentication and session/token architecture.
Identify unnecessary, weak, or insecure authentication mechanisms and determine how they can be safely removed or redesigned.
Harden API authentication and authorization flows.
Review token storage, lifecycle, expiration, refresh, and transmission.
Review the Retrofit/OkHttp networking layer and API interfaces.
Verify TLS configuration and certificate-pinning implementation.
Assess the client/server trust model and ensure authorization remains server-authoritative.
Analyze protobuf request/response structures and their use within the API.
Identify security weaknesses in the APK, including credential/token exposure and insecure local storage.
Recommend and implement practical security improvements without breaking legitimate application functionality.
Document security findings, changes made, and any remaining risks.
Required Technical Skills
Android / Kotlin
Strong Kotlin and Android development experience.
Familiarity with Activities, Services, SharedPreferences, lifecycle behavior, and Android application architecture.
Ability to understand and modify existing authentication and API code.
Networking
Strong understanding of HTTP/REST, Retrofit, and OkHttp.
Experience reading Retrofit interfaces such as @POST, @Body, headers, interceptors, and custom API clients.
Understanding of authentication headers, bearer/session tokens, TLS, certificate validation, and certificate pinning.
Protocol Buffers
Practical experience with Protocol Buffers (protobuf).
Ability to inspect and understand protobuf request/response messages rather than assuming JSON-based APIs.
Application Security
Strong understanding of:
Server-authoritative authorization
Session and bearer-token security
Secure credential/token storage
TLS and certificate validation
Certificate pinning and its trade-offs
Authentication/session lifecycle
Android attack surfaces
Client-side versus server-side trust boundaries
Valuable Additional Experience
The application has components beyond the Android controller, so experience with the following is a major advantage:
JavaScript — particularly injected agents and runtime interaction.
Frida / dynamic instrumentation
Unity / IL2CPP
Native Android development and ARM64 / ELF
Reverse-engineering tools such as JADX, Androguard, IDA Pro, or Ghidra
APK analysis and decompilation
Understanding of obfuscation and application-hardening techniques
Basic cryptographic analysis and encoding/serialization formats
Ideal Candidate
You’re comfortable working from an existing APK/codebase and quickly determining:
How authentication currently works.
How credentials and tokens are generated, stored, transmitted, and validated.
Which security decisions belong on the client versus the server.
Where the current implementation creates unnecessary risk.
How to remove or redesign authentication components without creating an unauthenticated security hole.
How to verify that the resulting implementation is actually more secure.
We value engineers who can explain why a security change is necessary, not just make code changes.
Deliverables
Security assessment of the existing authentication/networking implementation.
Clear identification of authentication and token-related vulnerabilities.
Recommended target architecture.
Implementation of agreed security improvements.
Testing/validation of authentication, networking, and authorization behavior.
Concise technical documentation covering the changes and remaining risks.
Important
This work is intended for an authorized application/codebase. Candidates should only use reverse-engineering, instrumentation, or security-testing techniques where they have explicit permission from the application owner.
We’re looking for an experienced Android/Kotlin security engineer to review and improve the authentication and networking security of an existing controller APK.
The primary focus is the Android client’s authentication, API communication, token handling, and security architecture. Experience with reverse engineering and dynamic instrumentation is highly valuable because the application also includes a JavaScript-injected agent, Unity/IL2CPP components, and native ARM64 code.
What You’ll Work On
Review the existing authentication and session/token architecture.
Identify unnecessary, weak, or insecure authentication mechanisms and determine how they can be safely removed or redesigned.
Harden API authentication and authorization flows.
Review token storage, lifecycle, expiration, refresh, and transmission.
Review the Retrofit/OkHttp networking layer and API interfaces.
Verify TLS configuration and certificate-pinning implementation.
Assess the client/server trust model and ensure authorization remains server-authoritative.
Analyze protobuf request/response structures and their use within the API.
Identify security weaknesses in the APK, including credential/token exposure and insecure local storage.
Recommend and implement practical security improvements without breaking legitimate application functionality.
Document security findings, changes made, and any remaining risks.
Required Technical Skills
Android / Kotlin
Strong Kotlin and Android development experience.
Familiarity with Activities, Services, SharedPreferences, lifecycle behavior, and Android application architecture.
Ability to understand and modify existing authentication and API code.
Networking
Strong understanding of HTTP/REST, Retrofit, and OkHttp.
Experience reading Retrofit interfaces such as @POST, @Body, headers, interceptors, and custom API clients.
Understanding of authentication headers, bearer/session tokens, TLS, certificate validation, and certificate pinning.
Protocol Buffers
Practical experience with Protocol Buffers (protobuf).
Ability to inspect and understand protobuf request/response messages rather than assuming JSON-based APIs.
Application Security
Strong understanding of:
Server-authoritative authorization
Session and bearer-token security
Secure credential/token storage
TLS and certificate validation
Certificate pinning and its trade-offs
Authentication/session lifecycle
Android attack surfaces
Client-side versus server-side trust boundaries
Valuable Additional Experience
The application has components beyond the Android controller, so experience with the following is a major advantage:
JavaScript — particularly injected agents and runtime interaction.
Frida / dynamic instrumentation
Unity / IL2CPP
Native Android development and ARM64 / ELF
Reverse-engineering tools such as JADX, Androguard, IDA Pro, or Ghidra
APK analysis and decompilation
Understanding of obfuscation and application-hardening techniques
Basic cryptographic analysis and encoding/serialization formats
Ideal Candidate
You’re comfortable working from an existing APK/codebase and quickly determining:
How authentication currently works.
How credentials and tokens are generated, stored, transmitted, and validated.
Which security decisions belong on the client versus the server.
Where the current implementation creates unnecessary risk.
How to remove or redesign authentication components without creating an unauthenticated security hole.
How to verify that the resulting implementation is actually more secure.
We value engineers who can explain why a security change is necessary, not just make code changes.
Deliverables
Security assessment of the existing authentication/networking implementation.
Clear identification of authentication and token-related vulnerabilities.
Recommended target architecture.
Implementation of agreed security improvements.
Testing/validation of authentication, networking, and authorization behavior.
Concise technical documentation covering the changes and remaining risks.
Important
This work is intended for an authorized application/codebase. Candidates should only use reverse-engineering, instrumentation, or security-testing techniques where they have explicit permission from the application owner.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.