{"schemaVersion":"jobsearcher.job.v1","id":"b49828641eae0a0fda0b0864","url":"https://jobsearcher.com/jobs/b49828641eae0a0fda0b0864","canonicalUrl":"https://jobsearcher.com/jobs/b49828641eae0a0fda0b0864","title":"Application Security Engineer – Binary Analysis & Reverse Engineering","description":"essentially a Windows Application Security Engineer or a Thick-Client Penetration Tester.Your core mission in this role is to act as the security gatekeeper for any traditional, locally installed Windows software (non-SaaS) that employees or the business want to use. You will tear down these applications, find their vulnerabilities, and decide if they are safe enough to be allowed on the company network.Here is a practical breakdown of what this job actually entails, the skills you need, and the day-to-day realities.The Day-to-Day ResponsibilitiesThe Application Interrogator: You aren't looking at web applications (SaaS). You are looking at .exe and .msi files, thick clients, and local binaries. When someone in the company says, \"I need to install this third-party Windows software to do my job,\" you are the person who tests it first.Reverse Engineering & Debugging: Because you won't always have the source code for this third-party software, you will have to decompile and debug it. You ll use tools like Ghidra, IDA Pro, x64dbg, or dnSpy to look under the hood and see what the program is actually doing to the local machine (e.g., how it interacts with the Windows Registry, memory, and file system).Network & Packet Interception: You need to see if the software is \"phoning home\" maliciously or sending data insecurely. You will use packet analyzers (like Wireshark) and interception proxies (like Burp Suite) to monitor and manipulate the traffic the application sends out over the network.Vulnerability Hunting: You will apply the OWASP Top 10 for Desktop Applications. This means actively hunting for local vulnerabilities like DLL hijacking, hardcoded credentials, insecure local data storage, and privilege escalation (e.g., an app asking for Admin rights when it doesn't need them).Setting the Rules (Conditional Approvals): You won't always just say \"Yes\" or \"No.\" A major part of the job is saying, \"Yes, you can use this software, but only if it is installed in a restricted folder, blocked from accessing the internet, and run without administrator privileges.\"The \"Hidden\" Challenges of the RoleThe Customer Service Aspect: This is often the hardest part of a security review role. The \"requestors\" are usually regular employees or department heads who just want to use their software and don't understand why security is holding it up. You need a high degree of empathy and patience to explain technical risks to non-technical people without sounding like a roadblock.Translation Skills: You will have to write reports for two completely different audiences. You must explain the core business risk to the person requesting the software, while providing deep, technical remediation steps to the engineering and IT teams who manage the network.The Ideal Candidate ProfileThis role is not for a standard web-app pentester. It requires someone with a deep, specialized understanding of the Windows OS architecture. You need a hacker's mindset to break the software, combined with a diplomat's touch to communicate the findings to frustrated internal customers.","company":"Gtech","rawCompany":"gtech","city":"Dallas","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-09-12T07:53:45.056Z","occupations":[{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer – Binary Analysis & Reverse Engineering","description":"essentially a Windows Application Security Engineer or a Thick-Client Penetration Tester.Your core mission in this role is to act as the security gatekeeper for any traditional, locally installed Windows software (non-SaaS) that employees or the business want to use. You will tear down these applications, find their vulnerabilities, and decide if they are safe enough to be allowed on the company network.Here is a practical breakdown of what this job actually entails, the skills you need, and the day-to-day realities.The Day-to-Day ResponsibilitiesThe Application Interrogator: You aren't looking at web applications (SaaS). You are looking at .exe and .msi files, thick clients, and local binaries. When someone in the company says, \"I need to install this third-party Windows software to do my job,\" you are the person who tests it first.Reverse Engineering & Debugging: Because you won't always have the source code for this third-party software, you will have to decompile and debug it. You ll use tools like Ghidra, IDA Pro, x64dbg, or dnSpy to look under the hood and see what the program is actually doing to the local machine (e.g., how it interacts with the Windows Registry, memory, and file system).Network & Packet Interception: You need to see if the software is \"phoning home\" maliciously or sending data insecurely. You will use packet analyzers (like Wireshark) and interception proxies (like Burp Suite) to monitor and manipulate the traffic the application sends out over the network.Vulnerability Hunting: You will apply the OWASP Top 10 for Desktop Applications. This means actively hunting for local vulnerabilities like DLL hijacking, hardcoded credentials, insecure local data storage, and privilege escalation (e.g., an app asking for Admin rights when it doesn't need them).Setting the Rules (Conditional Approvals): You won't always just say \"Yes\" or \"No.\" A major part of the job is saying, \"Yes, you can use this software, but only if it is installed in a restricted folder, blocked from accessing the internet, and run without administrator privileges.\"The \"Hidden\" Challenges of the RoleThe Customer Service Aspect: This is often the hardest part of a security review role. The \"requestors\" are usually regular employees or department heads who just want to use their software and don't understand why security is holding it up. You need a high degree of empathy and patience to explain technical risks to non-technical people without sounding like a roadblock.Translation Skills: You will have to write reports for two completely different audiences. You must explain the core business risk to the person requesting the software, while providing deep, technical remediation steps to the engineering and IT teams who manage the network.The Ideal Candidate ProfileThis role is not for a standard web-app pentester. It requires someone with a deep, specialized understanding of the Windows OS architecture. You need a hacker's mindset to break the software, combined with a diplomat's touch to communicate the findings to frustrated internal customers.","datePosted":"2026-09-12T07:53:45.056Z","dateModified":"2026-09-12T07:53:45.056Z","hiringOrganization":{"@type":"Organization","name":"Gtech","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dallas","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"b49828641eae0a0fda0b0864"},"url":"https://jobsearcher.com/jobs/b49828641eae0a0fda0b0864"}}