|
Why AIS?
When you join AIS, you're joining a mission-driven team that's passionate about making a difference. You'll work on projects that matter, alongside industry-leading experts, in an environment that fosters innovation, driving client success, and empowering our team to make a lasting impact. As an employee-owned company, we value collaboration, inclusivity, continuous growth, and shared success.
Employee Ownership: Your contributions directly impact the company's success, and you share in its achievements. Continuous Learning: Access to resources, training, and mentorship to support your professional growth. Inclusive Culture: A workplace where diversity is celebrated, and everyone's voice is valued. Mission-Driven Work: Engage in projects that make a meaningful difference for our clients and communities.
What are we looking for?
At AIS, we're looking for more than just skills - we're looking for driven individuals who are passionate about making a difference, eager to grow, and aligned with our core principles.
What you will be doing?At AIS, we are dedicated to providing our employees with diverse opportunities to grow their careers while supporting a variety of impactful projects. For this position, we are seeking a talented individual to join AIS as a Senior Security Engineer.
Core Knowledge & Skills: Designs secure architectures, leverages advanced threat detection, leads incident response, and implements security automation. Work & Complexity: Manages complex incidents, conducts threat analysis, leads audits, and implements process improvements. Quality & Independence: Delivers high-quality reports, aligns practices with industry standards, and operates with high autonomy. Teamwork & Communication: Leads team projects, collaborates cross-functionally, mentors juniors, and resolves conflicts. Consulting & Engagement: Provides strategic consulting, leads improvement initiatives, recommends advanced technologies, and manages vendor relationships.
As your initial career assignment, you will support the priorities and vital functions of our shared services teams as a(n) Mobile Malware Engineer.
Project Summary
Seeking a Mobile Malware Engineerto analyze, reverse engineer, and characterize malicious software targeting Android and iOS platforms in support of a federal government customer. Using expertise in malware reverse engineering and analysis, the engineer will evaluate complex malicious code through tools including disassemblers, debuggers, hex editors, unpackers, virtual machines, and network sniffers. The engineer will investigate instances of malicious code to determine attack vectors, payloads, and the extent of damage and data exfiltration - delivering actionable intelligence products that directly support national security missions.
Key Responsibilities
Perform static and dynamic analysis of mobile malware on Android and iOS platforms. Reverse engineer ARM/ARM64 binaries; unpack APK/IPA files, bypass runtime protections, and conduct reverse engineering of known and suspected malware files. Identify C2 infrastructure, persistence mechanisms, and indicators of compromise (IOCs); investigate attack vectors, payloads, and the extent of data exfiltration. Identify vulnerabilities in binaries, analyze shellcode, and recommend preventative or defensive actions. Develop custom tooling, automation scripts, and YARA detection signatures; build network and host-based signatures and recommend heuristic or anomaly-based detection methods. Produce technical reports with MITRE ATT&CK for Mobile mappings, remediation recommendations, and detailed documentation of malware behavior and command-and-control infrastructure. Perform ongoing research into malicious software, emerging vulnerabilities, and exploitation tactics to stay ahead of evolving threats. Collaborate with forensics, vulnerability research, and cyber operations teams.
Required For This Opportunity
Bachelor's + 8 yrs experience, or Master's + 6 yrs experience. A degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Information Systems, or related field is highly desired. However, an additional four years of experience may be considered in lieu if a Bachelor's degree. Active Top Secret with SCI eligibility clearance required. Proficiency in ARM/ARM64 assembly and low-level binary analysis. Strong knowledge of Android and iOS internals (APK/IPA structure, ART runtime, Mach-O binaries). Hands-on experience with: Ghidra, IDA Pro, Jadx, Frida, MobSF, Corellium. Scripting in Python; familiarity with Java, Kotlin, or Swift.
Nice to Have Skills
Experience with CNO toolchains or offensive mobile capability development. Familiarity with nation-state APT campaigns targeting mobile endpoints. Knowledge of MDM/EMM environments and mobile forensics tools (Cellebrite, Oxygen Forensic). Published research, CVEs, or open-source contributions in mobile security.
Preferred Certifications: GREM, GMOB, eMAPT, OSED, OSCP, CISSP, or CompTIA SecurityX. At AIS, we are committed to offering competitive and fair compensation that reflects the skills, experience, and contributions of each team member. The targeted base salary range for this role is $101,000-$152,000 per year. Please note that this range is provided as a guideline and the final offer will be based on several factors, including but not limited to, skillset and competencies, level of experience, education, certifications, and location. We value transparency in our hiring process and are happy to discuss how your unique qualifications align with our compensation structure during the interview process.
Applied Information Sciences does not discriminate on the basis of race, national origin, religion, color, gender, sexual orientation, age, disability, protected veteran status, or any other basis. Employment decisions are based solely on qualifications, merit, and business needs.
|