1

Android Reverse Engineer Jobs in Toronto, ON (NOW HIRING)

Android Reverse Engineer information

What is an Android Reverse Engineer job?

An Android Reverse Engineer analyzes and deconstructs Android applications to understand their functionality, security mechanisms, and potential vulnerabilities. They use tools like APK decompilers, debuggers, and dynamic analysis frameworks to reverse-engineer apps, often for security research, malware analysis, or software compatibility purposes. This role requires expertise in Android internals, Java, Kotlin, Smali, and ARM assembly, as well as knowledge of encryption and obfuscation techniques.

What are the key skills and qualifications needed to thrive in the Android Reverse Engineer position, and why are they important?

To thrive as an Android Reverse Engineer, you should possess a deep understanding of Android operating system internals, proficiency in programming languages like Java and C/C++, and hands-on experience with reverse engineering concepts and tools such as IDA Pro, Ghidra, or Apktool. Familiarity with ARM architecture, Android emulators, and security certifications like OSCP or GIAC GREM are common requirements in the field. Excellent analytical thinking, attention to detail, and strong problem-solving abilities help engineers tackle complex tasks and communicate findings clearly to stakeholders. These combined skills are essential for identifying vulnerabilities, securing applications, and ensuring compliance with security standards.

What are the typical day-to-day responsibilities of an Android Reverse Engineer?

On a typical day, an Android Reverse Engineer disassembles and analyzes Android applications or firmware to uncover vulnerabilities, understand app behavior, or verify code integrity. You may work closely with security teams, developers, and sometimes legal teams to ensure findings are communicated and remediation steps are implemented. Tasks can include static and dynamic analysis, malware detection, creating proof-of-concept exploits, and writing detailed technical reports. The role requires strong analytical focus, attention to detail, and a willingness to keep up with emerging threats and evolving mobile technologies.
Infographic showing various Android Reverse Engineer job openings in Toronto, ON as of May 2026, with employment types broken down into 67% Full Time, and 33% Part Time. Highlights an 100% Physical job distribution.

Senior Security Consultant (Android Malware Reverse Engineering)

NetSPI Canada Ltd

Toronto, ON

Full-time

Posted 16 days ago


Job description

NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.

NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.

We are seeking an experienced professional with demonstrated technical depth and breadth in Android Malware Reverse Engineering as well as the soft skills to effectively communicate with executive and technical teams. In this role, you'll have the ability to work alongside a world-class team using top-tier custom tools. Applicants are expected to leverage strong problem-solving skills, as well as lead, collaborate, and innovate to deliver high-quality exercises and exceptional experiences for our customers.

Responsibilities:

  • Perform malware reverse engineering on Android applications.
  • Create and deliver reports to clients.
  • Collaborate with clients to create remediation strategies that will help improve their security posture.
  • Research and develop innovative techniques, tools, and methodologies for reverse engineering Android applications.
  • Participate in the ongoing development/enhancement of NetSPI services and processes, in addition to thought leadership (via blogs, presentations, white papers, webinars, podcast, vlogs and tweets.)
  • Provide pre-sales support by assisting with scoping prospective engagements.
  • Act as a resource for internal team members as it relates to in-depth technical questions or best practices.
  • Responsible for QA activities in assigned service lines.

    Minimum Qualifications:

    • Bachelor’s degree or higher, preferably in Computer Science, Engineering, Mathematics, IT, or a related field; equivalent experience will also be considered.
    • 1-5 years of experience performing Android malware reverse engineering.
      • Includes experience with reversing tools such as Ghidra, IDA, jadx, etc.
    • 3-5 years of offensive security experience.
    • Experience with disassemblers and debuggers.
    • Experience with dynamic instrumentation toolkits.
      • Examples include Frida
    • Strong communication skills, both verbal and written.
    • Knowledge of Android Operating System.

    Preferred Qualifications:

    • Programming experience in one or more of the following languages: Java, JavaScript, Python.
    • Experience analyzing malicious Android applications.
    • The ability to reverse engineer proprietary application layer protocols.
    • Knowledge of operating system and application internals for Android.
    • GREM, PMRP, Zero2Automated or similar certifications.

    We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.