← Back to the catalogue
Domain 05 . Security

Mobile Security

45
Hours of teaching
Intermediate to Advanced
Level
8
Modules
Classroom . Online . Hybrid
Mode
Course overview

A mobile application security course covering Android and iOS assessment against OWASP MASVS. Learners set up instrumented devices and emulators, decompile and review applications, intercept and manipulate traffic, examine insecure storage and authentication, and test platform-specific controls.

Each learner completes an assessment of a deliberately vulnerable application and reports findings.

Who it is for
  • Mobile developers
  • Application security analysts
  • Penetration testers extending to mobile
  • QA engineers on mobile products
Prerequisites
Basic Android or iOS development awareness, networking and Linux command line.
How it runs
Learn → Practise → Build → Experience → Demonstrate, ending in a capstone. Delivered by practitioners from the engineering bench, in Madurai, Coimbatore and online.
Final project
Mobile App Security Assessment Report

Programme sheet

The printed sheet carries the full module breakdown, labs, project work and certification path. Fees, dates and formats for the next intake are confirmed by the education team on enquiry.

Learning outcomes

01
Set up a mobile testing environment with proxying.
02
Decompile and review Android and iOS applications.
03
Find insecure data storage and logging.
04
Intercept and modify API traffic despite pinning.
05
Test authentication, session and biometric flows.
06
Assess platform permissions and IPC surfaces.
07
Report findings against OWASP MASVS.

Module structure

8 modules
Module 01

Mobile Threat Model

Platform architectures . Permission models . OWASP Mobile Top 10 . Sandboxing . Threats and attackers
Module 02

Test Environment

Emulators and real devices . Proxy setup . Rooting and jailbreaking basics
Tools — Burp Suite, Frida, Certificate Installation
Module 03

Android Static Analysis

APK structure . Decompilation . Third-party SDKs . Manifest review . Hardcoded secrets
Tools — jadx, Apktool
Module 04

Android Dynamic Analysis

Runtime hooking . Insecure storage . Deep links and exported components . Logcat . WebView issues
Lab
Vulnerable App Assessment
Module 05

iOS Assessment

IPA structure . Plist and cache data . Runtime instrumentation . Keychain
Module 06

API and Traffic Security

TLS validation . Authentication tokens . Rate limiting . Backend authorisation
Module 07

Hardening and Defence

Secure storage APIs . Obfuscation . Root and tamper detection . Secure update paths . Play Integrity and DeviceCheck
Module 08

Reporting

Severity rating . Evidence capture . Developer-ready remediation . Retesting . MASVS mapping

Assessment & certification

Module assignments and labs
25%
Internal assessments
15%
Mini projects
20%
Final project and review
40%

Learners who complete all modules, submit the final project and clear the review receive a course completion certificate from Kaizen Infinities Private Limited. Project work is documented for the learner's portfolio, and interview preparation is included in the closing sessions.

Career outcomes . Roles this programme prepares for
Mobile Security AnalystApplication Security EngineerPenetration Tester (mobile)Secure Mobile DeveloperProduct Security Engineer
Enquire or apply →Programme sheet (PDF)Institutions can commission a cohort

Also in Security