Mobile Malware Engineer
Government Tactical Solutions, LLC · Linthicum Heights, MD · Yesterday
Engineering$120k–$150k/yrFull-time
Key Responsibilities
- Perform static and dynamic analysis of mobile malware on Android and iOS platforms.
- Reverse engineer ARM/ARM64 binaries.
- Unpack APK and IPA files, bypass runtime protections, and conduct reverse engineering of known and suspected malware files.
- Identify vulnerabilities in binaries and analyze shellcode.
- Investigate attack vectors, payloads, and the extent of data exfiltration.
- Identify command-and-control (C2) infrastructure, persistence mechanisms, and indicators of compromise (IOCs).
- Develop custom tooling, automation scripts, and YARA detection signatures.
- Build network- and host-based detection signatures and recommend heuristic or anomaly-based detection methods.
- Perform ongoing research into malicious software, emerging vulnerabilities, and exploitation tactics.
Reporting and Collaboration
- Produce technical reports that include MITRE ATT&CK for Mobile mappings, remediation recommendations, and detailed documentation of malware behavior and command-and-control infrastructure.
- Recommend preventative or defensive actions based on analysis findings.
- Collaborate with forensics, vulnerability research, and cyber operations teams.
Qualifications
- Education: Bachelor's degree and 8 years of experience, or Master's degree and 6 years of experience. Additional four years of experience may be substituted in lieu of a Bachelor's degree.
- Experience: Proficiency in ARM/ARM64 assembly and low-level binary analysis. Strong knowledge of Android and iOS internals, including APK/IPA structure, ART runtime, and Mach-O binaries. Hands-on experience with Ghidra, IDA Pro, Jadx, Frida, MobSF, and Corellium. Experience scripting in Python. Familiarity with Java, Kotlin, or Swift.
- Certifications: GREMGMOBeMAPTOSEDOSCPCISSPCompTIA SecurityX