5+ years of experience in mobile application security or offensive security, with hands-on expertise in iOS and/or Android platforms
In-depth understanding of security risks, vulnerabilities, and concepts in mobile and web applications
Proficient in code review across Kotlin, Swift, TypeScript, or JavaScript, with a strong grasp of application security threats
Able to create proof-of-concepts (PoCs) to demonstrate vulnerabilities, review patch code for adherence to standards, and collaborate with repository owners on remediation
Actively uses AI tools in your security engineering workflow — including building AI-leveraged workflows and codifying repeatable agent skills so tools like Claude Code or Codex deliver reliably on real production work
Strong analytical and problem-solving abilities with excellent verbal and written communication skills
Prior experience developing mobile security SDKs at scale — products with a daily active user base of over ten million
Experience in large-scale business risk control projects, or practical experience in threat intelligence, business risk prevention, and countermeasures against black and grey industries
In-depth reverse engineering of major apps from first-tier vendors, or other projects that demonstrate strong reverse engineering capabilities
Proficiency in ARM assembly, with the ability to implement deep-level countermeasures at the native and application layers
Experience with device fingerprint recognition — including simulating new devices through methods such as flashing, modification, and application cloning
Ability to work across multiple mobile platforms simultaneously