
Security Analyst (Android / iOS) at OneSpan
Noida, Uttar Pradesh, IndiaFull-timeR&DPosted 7 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><p>At <a href="https://www.onespan.com/about/careers" target="_blank">OneSpan</a>, we specialize in digital identity and anti-fraud solutions that create exceptional and secure experiences.</p></div><p>At OneSpan we are looking for a <strong>Security Analyst (Android / iOS)</strong> to join our team in <strong>Noida</strong>. In this role, you will contribute to the research, development, and validation of advanced mobile security protections within our Android and iOS SDKs. You will work on identifying attack techniques, designing and implementing new countermeasures, analyzing bypass attempts, and continuously strengthening the Runtime Application Self-Protection (RASP) capabilities of our mobile security platform, collaborating closely with our engineering and security research teams.</p>
<p><strong>Here is a little taste of your challenge:</strong></p>
<p><span style="color: #002060;">· </span>Research, design, develop, and validate mobile security countermeasures for Android and iOS applications.</p>
<p><span style="color: #002060;">· </span>Analyze Android and iOS applications to identify security weaknesses, attack vectors, and potential bypass techniques against mobile protections.</p>
<p><span style="color: #002060;">· </span>Perform reverse engineering of mobile applications, malware samples, and security tools to understand attacker techniques and improve defensive capabilities.</p>
<p><span style="color: #002060;">· </span>Develop and enhance Runtime Application Self-Protection (RASP) mechanisms such as anti-debugging, anti-instrumentation, anti-tampering, anti-hooking, and environment integrity checks.</p>
<p><span style="color: #002060;">· </span>Research and reproduce real-world attacks such as hooking, dynamic instrumentation, tampering, and runtime manipulation against protected applications.</p>
<p><span style="color: #002060;">· </span>Prototype, implement, and evaluate new detection techniques in native and platform-specific code (C/C++, Kotlin, Swift, Objective-C).</p>
<p><span style="color: #002060;">· </span>Use reverse engineering and dynamic analysis tools to assess the effectiveness of protection mechanisms and identify potential bypasses.</p>
<p><span style="color: #002060;">· </span>Support the design, architecture, and continuous improvement of our Android and iOS mobile security SDKs.</p>
<p><span style="color: #002060;">· </span>Research and monitor the Indian mobile banking and fintech regulatory landscape (including RBI guidelines and CERT-In requirements) to identify emerging threats and inform the team's research direction for the region.</p>
<p><span style="color: #002060;">· </span>Engage independently with enterprise customers in the region during technical discussions, able to defend product decisions and countermeasure design without requiring real-time support from the Europe-based team.</p>
<p><span style="color: #002060;">· </span>Document research findings, attack techniques, and defensive approaches, contributing to internal security knowledge and threat intelligence.</p>
<p><span style="color: #002060;">· </span>Participate in technical discussions, security research initiatives, and product roadmap decisions.</p>
<p><strong>Who are you?</strong> There is no set route to become part of Build38. But to be successful in this role, this is the kind of profile we have in mind:</p>
<p><span style="color: #002060;">· </span>Between 5-12 years of experience in application security, mobile security, reverse engineering, or penetration testing.</p>
<p><span style="color: #002060;">· </span>Strong understanding of Android and/or iOS application security.</p>
<p><span style="color: #002060;">· </span>Experience performing reverse engineering of mobile applications.</p>
<p><span style="color: #002060;">· </span>Familiarity with dynamic instrumentation and runtime analysis techniques.</p>
<p><span style="color: #002060;">· </span>Experience using reverse engineering tools such as IDA Pro, Ghidra, JEB, or JADX.</p>
<p><span style="color: #002060;">· </span>Experience with dynamic analysis or instrumentation tools such as Frida, GDB, LLDB, or similar.</p>
<p><span style="color: #002060;">· </span>Experience developing RASP countermeasures for Android and/or iOS, or at least performing technical analysis and evaluation of mobile RASP protections.</p>
<p><span style="color: #002060;">· </span>Ability to analyze compiled code and understand low-level behavior.</p>
<p><span style="color: #002060;">· </span>Ability to communicate (verbally and writing) in English.</p>
<p><span style="color: #002060;">· </span>Ability to make recommendations and decisions independently.</p>
<p><span style="color: #002060;">· </span>Familiarity with the Indian banking/fintech regulatory environment and its implications for mobile application security.</p>
<p><span style="color: #002060;">· </span>Nice to have:</p>
<p>o Experience analyzing mobile malware.<br>o Experience in penetration testing environments or security evaluation laboratories.<br>o Knowledge of Android internals (ART, system APIs, root environments) or iOS security mechanisms.<br>o Experience with native code analysis (C/C++).<br>o Interest in mobile application protection technologies such as obfuscation, anti-tampering, and RASP.<br>o Experience with Git.<br>o Experience with CI/CD pipelines.<br>o Knowledge of the Unix/Linux command line / shell.<br>o Experience with Agile/Scrum best practices.<br>o Analytical thinking and problem-solving attitude.<br>o Strong interest in security research and continuous learning.</p>
<p><span style="color: #000000;">#LI-Onsite<br>#LI-LS1</span></p>
<p> </p>