{"schemaVersion":"jobsearcher.job.v1","id":"2a77378faf6c67c3f43395c0","url":"https://jobsearcher.com/jobs/2a77378faf6c67c3f43395c0","canonicalUrl":"https://jobsearcher.com/jobs/2a77378faf6c67c3f43395c0","title":"Senior Application Security Analyst (Pentester)","description":"Join Our Mission: To Save the World from Unsafe Mobile Apps! NowSecure is the mobile app security software company trusted by the world’s most demanding organizations and most advanced security teams. As the standards-based mobile app risk management company, NowSecure protects the Mobile App Economy. The world’s most demanding organizations, innovative mobile developers and advanced security, privacy, safety and compliance teams entrust NowSecure to safeguard millions of mobile app users across banking, insurance, high tech, IoT, retail, hospitality, energy and government sectors. Only NowSecure delivers continuous security and compliance with the depth, speed, accuracy, and efficiency to meet modern business demands. Dedicated to the open-source community and standards including OWASP,and NIAP, NowSecure is SOC 2 certified and recognized by IDC, Deloitte, Gartner and TAG Cyber.www.nowsecure.com\nYOUR OPPORTUNITY\nWe’re looking for a Senior Application Security Analyst — a hands-on pentester who thrives on technical challenges, thinks creatively under pressure, and has an insatiable curiosity for how things work (and how they break).\nIf you’re the kind of person who spins up a quick Python script to automate a test, roots a phone just to see what’s inside, or finds joy in reverse engineering an app at 2 AM — you’ll fit right in.\nIn this role, you’ll hunt vulnerabilities, dissect mobile apps and APIs, and collaborate with a team of world-class testers who live and breathe offensive security. You’ll also help evolve our methodologies, develop new tooling, and contribute to NowSecure’s cutting-edge research across mobile, web, and connected systems.\nWHAT YOU’LL DO\nPerform hands-on penetration testing of mobile apps (iOS/Android), APIs, web apps and connected ecosystems (IoT, automotive, medical, wearable).\nConduct vulnerability assessments and reverse engineering using tools like Burp Suite, Frida, mitmproxy, Ghidra, Radare2, IDA, or custom scripts.\nCreate clear, actionable technical reports that communicate findings and remediation guidance to both developers and security teams.\nAct as a trusted advisor to customers, helping them make informed, risk-based decisions about their mobile and app security posture\nBuild or adapt custom scripts, fuzzers, or automation tools to make testing faster, smarter, and more reliable.\nCollaborate with teammates to refine methodologies, share research, and continuously push the boundaries of mobile and web security testing.\nTackle complex problems with creativity; when something doesn’t work, figure out another way. “Scrappy” is a skill set here, not a slogan.\nWHO YOU ARE\nYou’re a technical problem-solver who thrives on exploration and experimentation. You’re comfortable diving into unfamiliar codebases, debugging network traffic, and learning new tools on the fly. You’re not a button pusher; you’re the kind of tester who asks why something works (or doesn’t) and can pivot quickly when the usual tools fall short. You can translate technical detail into clear communication and enjoy mentoring or collaborating with others. You take ownership, seek out challenges, and are never satisfied with “good enough.”\nREQUIREMENTS (You must have … )\nBachelor’s degree in a technical field or 6–8 years of equivalent security experience.\n2+ years of experience in penetration testing or vulnerability assessment of mobile, web, or IoT apps/devices.\nDeep understanding of OWASP MASVS / MASTG and app security fundamentals.\nStrong experience with intercepting and analyzing traffic using tools like Burp Suite, mitmproxy, ZAP, Charles, or Fiddler.\nProficiency in mobile device rooting/jailbreaking and familiarity with iOS and Android internals, or equivalent hands-on experience in web application penetration testing or firmware reverse engineering.\nStrong scripting or development experience (e.g., Python, Java, JavaScript, Ruby, or PowerShell).\nSolid grasp of network and web fundamentals — TCP/UDP, HTTP requests, headers, cookies, APIs, and authentication flows.\nExcellent technical writing and documentation skills.\nComfort working with Linux, Windows, and macOS environments.\nA self-starter mindset - able to work independently, manage multiple projects, and find creative solutions to tough problems.\nA demonstrated drive to learn, experiment, and stay on the cutting edge of mobile and appsec trends.\nDESIRED SKILLS (Stand out from the crowd…)\nFamiliarity with DAST/SAST tools, mobile instrumentation (e.g., Frida), and dynamic analysis.\nProfessional services or consulting experience.\nPrior security research or exploit development experience.\nKnowledge of system/network security, authentication, and applied cryptography.\nFamiliarity with Frida, Binary Ninja, Radare2, or IDA Pro.\nExperience testing in AWS, Azure, or GCP environments.\nContributions to open-source security projects or published research.\nPast public speaking experience (conferences, podcasts, etc)\nOne or more active certifications such as:\nInfosec Certified Mobile and Web Application Penetration Tester (CMWAPT)\nOffensive Security Web Expert (OSWE)\nOffensive Security Certified Professional (OSCP)\nGIAC Certified Penetration Tester (GPEN)\nGIAC Certified Web Application Defender (GWEB)\nGIAC Web Application Penetration Tester (GWAPT)\nINE Web Application Penetration Tester eXtreme (eWPTX)\nGIAC Mobile Device Security Analyst (GMOB)\n8kSec Certified Mobile Security Engineer (CMSE)\nINE Mobile Application Penetration Tester (eMAPT)\nTCM-SEC Mobile Application Penetration Testing\nBONUS POINTS (You have our attention…)\nExperience with LTE / GSM protocols or 5G network analysis.\nPrior experience using NowSecure tools.\nMaster’s degree in Computer Science, Cybersecurity, or related field.\nWE VALUE DIVERSITY\nWe believe that the best ideas come from teams where diverse points of view uncover new solutions to hard problems. We welcome and value team members who bring diverse life experiences, educational backgrounds, cultures, and work experiences.\nCOMPENSATION & BENEFITS\nThe salary band for this position ranges is competitive and commensurate with experience and performance. This position will be eligible for a competitive annual bonus and equity package.\nComprehensive Medical/Dental/Vision coverage\n401K Plan + Company Match\nRemote work flexibility\nHome Office Stipend\nPaid Parental Leave\nFlexible PTO\n79WMFmL8jd","company":"Nowsecure","rawCompany":"nowsecure","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-04-14T11:19:56.946Z","occupations":[{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Application Security Analyst (Pentester)","description":"Join Our Mission: To Save the World from Unsafe Mobile Apps! NowSecure is the mobile app security software company trusted by the world’s most demanding organizations and most advanced security teams. As the standards-based mobile app risk management company, NowSecure protects the Mobile App Economy. The world’s most demanding organizations, innovative mobile developers and advanced security, privacy, safety and compliance teams entrust NowSecure to safeguard millions of mobile app users across banking, insurance, high tech, IoT, retail, hospitality, energy and government sectors. Only NowSecure delivers continuous security and compliance with the depth, speed, accuracy, and efficiency to meet modern business demands. Dedicated to the open-source community and standards including OWASP,and NIAP, NowSecure is SOC 2 certified and recognized by IDC, Deloitte, Gartner and TAG Cyber.www.nowsecure.com\nYOUR OPPORTUNITY\nWe’re looking for a Senior Application Security Analyst — a hands-on pentester who thrives on technical challenges, thinks creatively under pressure, and has an insatiable curiosity for how things work (and how they break).\nIf you’re the kind of person who spins up a quick Python script to automate a test, roots a phone just to see what’s inside, or finds joy in reverse engineering an app at 2 AM — you’ll fit right in.\nIn this role, you’ll hunt vulnerabilities, dissect mobile apps and APIs, and collaborate with a team of world-class testers who live and breathe offensive security. You’ll also help evolve our methodologies, develop new tooling, and contribute to NowSecure’s cutting-edge research across mobile, web, and connected systems.\nWHAT YOU’LL DO\nPerform hands-on penetration testing of mobile apps (iOS/Android), APIs, web apps and connected ecosystems (IoT, automotive, medical, wearable).\nConduct vulnerability assessments and reverse engineering using tools like Burp Suite, Frida, mitmproxy, Ghidra, Radare2, IDA, or custom scripts.\nCreate clear, actionable technical reports that communicate findings and remediation guidance to both developers and security teams.\nAct as a trusted advisor to customers, helping them make informed, risk-based decisions about their mobile and app security posture\nBuild or adapt custom scripts, fuzzers, or automation tools to make testing faster, smarter, and more reliable.\nCollaborate with teammates to refine methodologies, share research, and continuously push the boundaries of mobile and web security testing.\nTackle complex problems with creativity; when something doesn’t work, figure out another way. “Scrappy” is a skill set here, not a slogan.\nWHO YOU ARE\nYou’re a technical problem-solver who thrives on exploration and experimentation. You’re comfortable diving into unfamiliar codebases, debugging network traffic, and learning new tools on the fly. You’re not a button pusher; you’re the kind of tester who asks why something works (or doesn’t) and can pivot quickly when the usual tools fall short. You can translate technical detail into clear communication and enjoy mentoring or collaborating with others. You take ownership, seek out challenges, and are never satisfied with “good enough.”\nREQUIREMENTS (You must have … )\nBachelor’s degree in a technical field or 6–8 years of equivalent security experience.\n2+ years of experience in penetration testing or vulnerability assessment of mobile, web, or IoT apps/devices.\nDeep understanding of OWASP MASVS / MASTG and app security fundamentals.\nStrong experience with intercepting and analyzing traffic using tools like Burp Suite, mitmproxy, ZAP, Charles, or Fiddler.\nProficiency in mobile device rooting/jailbreaking and familiarity with iOS and Android internals, or equivalent hands-on experience in web application penetration testing or firmware reverse engineering.\nStrong scripting or development experience (e.g., Python, Java, JavaScript, Ruby, or PowerShell).\nSolid grasp of network and web fundamentals — TCP/UDP, HTTP requests, headers, cookies, APIs, and authentication flows.\nExcellent technical writing and documentation skills.\nComfort working with Linux, Windows, and macOS environments.\nA self-starter mindset - able to work independently, manage multiple projects, and find creative solutions to tough problems.\nA demonstrated drive to learn, experiment, and stay on the cutting edge of mobile and appsec trends.\nDESIRED SKILLS (Stand out from the crowd…)\nFamiliarity with DAST/SAST tools, mobile instrumentation (e.g., Frida), and dynamic analysis.\nProfessional services or consulting experience.\nPrior security research or exploit development experience.\nKnowledge of system/network security, authentication, and applied cryptography.\nFamiliarity with Frida, Binary Ninja, Radare2, or IDA Pro.\nExperience testing in AWS, Azure, or GCP environments.\nContributions to open-source security projects or published research.\nPast public speaking experience (conferences, podcasts, etc)\nOne or more active certifications such as:\nInfosec Certified Mobile and Web Application Penetration Tester (CMWAPT)\nOffensive Security Web Expert (OSWE)\nOffensive Security Certified Professional (OSCP)\nGIAC Certified Penetration Tester (GPEN)\nGIAC Certified Web Application Defender (GWEB)\nGIAC Web Application Penetration Tester (GWAPT)\nINE Web Application Penetration Tester eXtreme (eWPTX)\nGIAC Mobile Device Security Analyst (GMOB)\n8kSec Certified Mobile Security Engineer (CMSE)\nINE Mobile Application Penetration Tester (eMAPT)\nTCM-SEC Mobile Application Penetration Testing\nBONUS POINTS (You have our attention…)\nExperience with LTE / GSM protocols or 5G network analysis.\nPrior experience using NowSecure tools.\nMaster’s degree in Computer Science, Cybersecurity, or related field.\nWE VALUE DIVERSITY\nWe believe that the best ideas come from teams where diverse points of view uncover new solutions to hard problems. We welcome and value team members who bring diverse life experiences, educational backgrounds, cultures, and work experiences.\nCOMPENSATION & BENEFITS\nThe salary band for this position ranges is competitive and commensurate with experience and performance. This position will be eligible for a competitive annual bonus and equity package.\nComprehensive Medical/Dental/Vision coverage\n401K Plan + Company Match\nRemote work flexibility\nHome Office Stipend\nPaid Parental Leave\nFlexible PTO\n79WMFmL8jd","datePosted":"2026-04-14T11:19:56.946Z","dateModified":"2026-04-14T11:19:56.946Z","hiringOrganization":{"@type":"Organization","name":"Nowsecure","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2a77378faf6c67c3f43395c0"},"url":"https://jobsearcher.com/jobs/2a77378faf6c67c3f43395c0"}}