Android Reverse Engineer

Cornycorn cobCareers

Location: Remote

Full-time or contract

About the role

Corny Capital backs and builds early-stage companies. One of our portfolio companies is building in the anti-bot and Android-security space, and we’re looking for an engineer who understands these systems from the other side. Your job is to figure out how commercial bot-detection and Android-fingerprinting systems work, where their assumptions break down, and how they can be bypassed. Then you’ll turn that research into working software. You’ll spend most of your time investigating in app-behavior, fingerprinting techniques, detection signals, and the systems built to distinguish automated traffic from real users.

What you'll work on

  • Reverse-engineer iOS and Android applications to understand how they behave internally, including native code, application logic, network protocols, device signals, and anti-abuse systems.
  • Analyze commercial mobile security, fraud-detection, device-fingerprinting, integrity, and anti-tamper systems.
  • Determine which device, OS, application, network, behavioral, and environmental signals are collected and how they influence detection.
  • Perform both static and dynamic analysis using tools such as Frida, IDA Pro, Ghidra, Hopper, JADX, apktool, LLDB, objection, and whatever else gets the job done.
  • Instrument applications at runtime to understand control flow, internal state, native libraries, API usage, cryptographic operations, and communication between components.
  • Work across ARM64, Objective-C/Swift, Java/Kotlin, JNI, C/C++, and native mobile frameworks where required.
  • Analyze jailbreak/root detection, emulator and virtualization detection, device integrity checks, certificate pinning, application attestation, and other environmental controls.
  • Work with physical devices, rooted/jailbroken devices, emulators, virtualized environments, and custom instrumentation setups.
  • Reverse-engineer proprietary APIs and network protocols by combining application analysis with traffic inspection and runtime instrumentation.
  • Turn successful research into reliable internal tooling that can reproduce findings consistently across application versions and devices.
  • Document findings clearly so they can be used to improve our own systems, testing, and defensive detection.
  • Use whatever tools make the research faster, including LLMs, agents, scripting, custom instrumentation, and retrieval over previous experiments.

What we're looking for

The most important qualification is that you’ve done this before.

We’re particularly interested in people who have:

  • Meaningfully reverse-engineered complex commercial iOS or Android applications.
  • A deep understanding of mobile operating systems, application runtimes, native code, and the security boundaries between them.
  • Extensive experience with Frida or similar dynamic instrumentation frameworks.
  • Strong static-analysis skills using tools such as IDA Pro, Ghidra, Hopper, JADX, Binary Ninja, or similar.
  • Experience working with ARM64 assembly and debugging native mobile applications.
  • Reverse-engineered mobile anti-tamper, anti-fraud, device-fingerprinting, jailbreak/root-detection, integrity, or attestation systems.
  • Worked with rooted Android devices, jailbroken iPhones, emulators, virtualization, or custom device environments.
  • Experience analyzing obfuscated applications and native libraries where the interesting logic is intentionally difficult to find.
  • Reverse-engineered proprietary mobile APIs, authentication flows, binary protocols, or application-specific cryptographic schemes.
  • Built instrumentation or reverse-engineering tooling that continues working outside of a controlled proof of concept.
  • Strong opinions about modern mobile application security, device attestation, anti-tamper systems, and where current approaches succeed or fail.

Public work is useful but not required. Repositories, technical writeups, CTF work, vulnerability research, tooling, Frida scripts, reverse-engineering projects, or demonstrations of systems you’ve analyzed are all helpful.

Ear of corn with green husk

How we work

We’re remote and work primarily asynchronously. Meetings are kept to what is useful.
You’ll have significant freedom over how you approach the problem and which tools you use. What matters is whether the research is sound and what you build actually works.

Compensation and logistics

  • Competitive salary or contract rate.
  • Remote, with flexible working hours.
  • Full-time or contract depending on fit.

How to apply

Send us a short introduction and one example that demonstrates the kind of work you’ve done. That could be a repository, writeup, demo, research project, or a description of how you investigated a particular detection system.