Mobile Malware Engineer
Why AIS?
When you join AIS, you’re joining a mission-driven team that’s passionate about making a difference. You’ll work on projects that matter, alongside industry-leading experts, in an environment that fosters innovation, driving client success, and empowering our team to make a lasting impact. As an employee-owned company, we value collaboration, inclusivity, continuous growth, and shared success.
What are we looking for?
We're looking for driven individuals who are passionate about making a difference, eager to grow, and aligned with our core principles.
What you will be doing?
- Designs secure architectures
- Leverages advanced threat detection
- Leads incident response
- Implements security automation
Core Knowledge & Skills
- Reverse engineer ARM/ARM64 binaries
- Bypass runtime protections
- Conduct reverse engineering of known and suspected malware files
- Identify C2 infrastructure, persistence mechanisms, and indicators of compromise (IOCs)
- Investigate attack vectors, payloads, and the extent of data exfiltration
- Identify vulnerabilities in binaries
- Analyze shellcode
- Recommend preventative or defensive actions
- Develop custom tooling, automation scripts, and YARA detection signatures
- Build network and host-based signatures
- Recommend heuristic or anomaly-based detection methods
- Produce technical reports with MITRE ATT&CK for Mobile mappings, remediation recommendations, and detailed documentation of malware behavior and command-and-control infrastructure
- Perform ongoing research into malicious software, emerging vulnerabilities, and exploitation tactics
- Collaborate with forensics, vulnerability research, and cyber operations teams
Project Summary
Seeking a Mobile Malware Engineer to analyze, reverse engineer, and characterize malicious software targeting Android and iOS platforms in support of a federal government customer. Using expertise in malware reverse engineering and analysis, the engineer will evaluate complex malicious code through tools including disassemblers, debuggers, hex editors, unpackers, virtual machines, and network sniffers. The engineer will investigate instances of malicious code to determine attack vectors, payloads, and the extent of damage and data exfiltration — delivering actionable intelligence products that directly support national security missions.
Key Responsibilities
- Perform static and dynamic analysis of mobile malware on Android and iOS platforms
- Reverse engineer ARM/ARM64 binaries; unpack APK/IPA files, bypass runtime protections, and conduct reverse engineering of known and suspected malware files
- Identify C2 infrastructure, persistence mechanisms, and indicators of compromise (IOCs); investigate attack vectors, payloads, and the extent of data exfiltration
- Identify vulnerabilities in binaries, analyze shellcode, and recommend preventative or defensive actions
- Develop custom tooling, automation scripts, and YARA detection signatures
- Build network and host-based signatures
- Recommend heuristic or anomaly-based detection methods
- Produce technical reports with MITRE ATT&CK for Mobile mappings, remediation recommendations, and detailed documentation of malware behavior and command-and-control infrastructure
- Perform ongoing research into malicious software, emerging vulnerabilities, and exploitation tactics
- Collaborate with forensics, vulnerability research, and cyber operations teams
Required For This Opportunity
- Bachelor's + 8 yrs experience, or Master's + 6 yrs experience
- A degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or related field is highly desired
- Additional four years of experience may be considered in lieu if a Bachelor's degree
- Active Top Secret with SCI eligibility clearance required
- Proficiency in ARM/ARM64 assembly and low-level binary analysis
- Strong knowledge of Android and iOS internals (APK/IPA structure, ART runtime, Mach-O binaries)
- Hands-on experience with: Ghidra, IDA Pro, Jadx, Frida, MobSF, Corellium
- Scripting in Python; familiarity with Java, Kotlin, or Swift
Nice To Have Skills
- Experience with CNO toolchains or offensive mobile capability development
- Familiarity with nation-state APT campaigns targeting mobile endpoints
- Knowledge of MDM/EMM environments and mobile forensics tools (Cellebrite, Oxygen Forensic)
- Published research, CVEs, or open-source contributions in mobile security
Preferred Certifications
- GREM, GMOB, eMAPT, OSED, OSCP, CISSP, or CompTIA SecurityX
Pay
The targeted base salary range for this role is $101,000-$152,000 per year. Please note that this range is provided as a guideline and the final offer will be based on several factors, including but not limited to, skillset and competencies, level of experience, education, certifications, and location.