Senior Cybersecurity Analyst
AIO App Inc
- Islamabad
- Permanent
- Full-time
- Conduct thorough Vulnerability Assessment and Penetration Testing (VAPT) on Android applications
- Perform risk assessments to evaluate the potential impact of identified vulnerabilities and provide
- Conduct API testing to ensure the security of interfaces used by mobile applications.
- Conduct code reviews to identify security flaws and weaknesses in Android application code.
- Develop and implement security policies, procedures, and processes tailored to mobile application
- Automate security assessment tasks to improve efficiency and effectiveness.
- Perform threat modelling to identify potential security threats and vulnerabilities in Android
- Collaborate with stakeholders to ensure compliance with Governance, Risk, and Compliance (GRC)
- Stay up to date with the latest security threats, vulnerabilities, and best practices related to mobile
- Collaborate with development teams to integrate security into the software development lifecycle
- Supervise and guide the daily operations of the cyber security team
- Bachelor's degree in Computer Science, Information Security, or a related field
- Minimum of 5 years of experience in cyber security, with a focus on mobile application security.
- Demonstrated experience in conducting VAPT on Android applications.
- Proficiency in API testing and code review techniques.
- Experience in developing security policies, processes, and procedures.
- Strong scripting skills with experience in Python, Shell scripting, or similar languages for security
- In-depth knowledge of security best practices for app development, including secure coding practices,
- In-depth knowledge of security best practices for app development, including secure coding practices,
- Familiarity with AWS security best practices
- Knowledge of endpoint security solutions and best practices.
- Experience with threat modelling methodologies and tools.
- Familiarity with Governance, Risk, and Compliance (GRC) practices and standards.
- Certifications: CEH, OSCP, CISM or eCPPT are preferred