Mobile App Penetration Testing

Job ID: 40558023

Budget: ₹75,000 – ₹150,000 INR

I’m looking for a security professional to carry out a full-scale penetration test on our production mobile app, targeting both iOS and Android builds. Because this assessment is mobile-specific, I need you to zero in on three critical areas:

• Authentication – verify that login, session management and any social/SSO flows can’t be bypassed or abused.
• Data storage security – confirm that sensitive information is never left exposed in local storage, keychains, logs or backups.
• API integrations – probe every call the app makes to our back-end, ensuring proper authorization, rate-limiting and input validation.

I’ll provide the latest IPA and APK, test accounts, and high-level architecture docs. Your job is to emulate realistic attacker behavior, using standard toolsets such as OWASP Mobile Testing Guide techniques, Burp Suite, Frida or similar, and to keep meticulous notes for evidence.

Deliverables:
1. Executive summary in plain language for management.
2. Detailed technical report mapping each finding to CVSS/CWE, proof-of-concept steps, reproducible screenshots or videos, and clear remediation advice.
3. Clean retest confirmation once fixes are applied.

All testing must respect responsible disclosure and be performed within the agreed window. Let me know your estimated timeline and any prerequisites you need before kickoff.