Application Security Engineer · Mid-Senior · iOS
EUR 38,400-75,600 per year
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Android @ 2
Communication @ 3
Debugging @ 2
HTTP @ 3
Manual Testing
Networking @ 3
OWASP @ 3
Objective-C @ 5
Reporting @ 3
Security @ 3
Swift @ 5
iOS @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
At Nord Security, we’re creating a safer cyber future. We help people and businesses take back control of their online security, privacy, and data. From VPNs to password managers, threat intelligence to eSIMs for travel, our teams turn complex problems into solutions trusted by millions worldwide.
Responsibilities
- Conduct security reviews of application designs, source code, and third-party libraries and SDKs.
- Perform regular application vulnerability assessments using automated tools and manual testing techniques, including SAST, DAST, SCA, and penetration testing.
- Perform end-to-end security assessments of iOS applications, covering static and dynamic analysis and runtime instrumentation.
- Collaborate with development teams to design secure architectures and implement security controls.
- Help maintain security tools, scripts, and processes that support secure development.
- Stay current with industry trends, zero-day vulnerabilities, platform security changes in new iOS releases, and application security best practices.
- Develop scripts, security automation tools, and instrumentation harnesses to improve mobile application security testing processes.
- Design and deliver security engineering awareness and adoption training.
- Actively identify internal security gaps within products.
- Ensure mobile applications are sufficiently tested and support internal and external audits, including MASVS-aligned assessments.
Requirements
- Proven experience planning and conducting mobile application security assessments, testing, applying methodologies, and reporting vulnerabilities, with a focus on iOS.
- Strong understanding of secure coding practices.
- Ability to perform manual security code audits.
- Proficiency in at least one mobile or native programming language, such as Swift or Objective-C, and comfort reading C/C++ in dependencies.
- Practical knowledge of OWASP MASVS and MASTG, with the ability to plan and execute assessments against them.
- Solid understanding of the iOS security model, including sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC, and inter-app communication through URL schemes, universal links, app extensions, and app groups.
- Hands-on experience with dynamic instrumentation and mobile testing tools such as Frida, Objection, MobSF, Burp Suite, mitmproxy, and class-dump or otool-style binary inspection.
- Experience bypassing client-side controls such as certificate pinning, jailbreak detection, and anti-tampering, as well as assessing their resilience.
- Solid understanding of TCP, UDP, HTTP, TLS, and traffic interception on mobile devices.
- Understanding of insecure data storage, sensitive data leakage through logs, backups, snapshots, pasteboard, and caches, and cryptographic misuse in mobile applications.
- Ability to work with networking tools such as Wireshark and tcpdump.
- Familiarity with iOS reverse engineering and debugging tools such as Ghidra, IDA, Hopper, and LLDB.
- Ability to quickly learn new technologies and tools.
- Strong ownership, problem-solving, and investigation skills.
- Ability to build and maintain relationships and influence key stakeholders across the business.
- Bonus: community contributions such as public CVEs, bug bounty recognition, open-source tools, or technical blogs.
Nice to Have
- Familiarity with Android application security for cross-platform coverage.
- Familiarity with fuzzing tools and fuzzing techniques.
Benefits
- Extensive online and in-person training, access to Coursera and Skillshare, mentorship, and internal career opportunities.
- Extra vacation days that increase with tenure, plus additional sick leave, special occasion, and parenting days.
- Premium private health insurance in Lithuania and Poland.
- Free subscriptions to Calm, Headspace, and Mindletic, plus resilience and mindfulness training and mental health events.
- In-house gyms, Multisport and Urban Sport cards, online workouts, mobility sessions, fitness guidance, and consultations.
- Company workation opportunities abroad.
- Ability to work from different locations.
- Gifts for birthdays, work anniversaries, weddings, and new family members.
- Summer camps for children and flexible working arrangements for parents.
- Team-building activities and company events.
- Access to Nord Security’s Vilnius headquarters, including silent rooms, gyms, a game room, a music room, and a coffee bar.
More jobs at Nord Security
DevOps Engineer - Mid - Threat Protection
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 43,200-69,600 per year
Retention Data Analyst
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 26,400-54,000 per year
Security Engineer – Mid-Senior – WebSec Team
Nord Security · Poland
PLN 206,400-396,000 per year
Site Reliability Engineer - Senior - NordVPN Apps
Nord Security · Poland
PLN 279,600-408,000 per year
Backend Engineer · Mid-Senior · Go · Coveron
Nord Security · Poland
PLN 237,600-400,800 per year
Similar jobs
Application Security Engineer - Mid-Senior - iOS
Nord Security · Poland
PLN 206,400-360,000 per year
Client Platform Security Engineer
Stripe · United States, New York City, United States
USD 173,000-259,600 per year
Service Specialist, Employee Technology Support
Bloomberg · New York City, United States
USD 85,000-100,000 per year
Application Security Engineer · Mid-Senior · Low-Level
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 38,400-75,600 per year
Systems Administrator · macOS/iOS · Junior-Mid
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 21,600-37,200 per year
Application Security Engineer · Mid-Senior · Low-Level
Nord Security · Poland
PLN 206,400-360,000 per year
Application Security Engineer - Senior
Nord Security · Poland
PLN 276,000-360,000 per year
Senior QA Automation Engineer, Network Simulation Platform
Nvidia · Warsaw, Poland
PLN 157,500-357,500 per year