Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Android @ 2
Debugging @ 2
HTTP @ 3
Manual Testing
Networking @ 3
OWASP @ 3
Objective-C @ 5
Reporting @ 3
Security @ 3
Swift @ 5
iOS @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
At Nord Security, you’ll help create a safer cyber future by securing applications used by millions of people worldwide.
Responsibilities
- Conduct security reviews of application designs, source code, and third-party libraries and SDKs.
- Perform application vulnerability assessments using automated tools and manual testing techniques, including SAST, DAST, SCA, and penetration testing.
- Perform end-to-end security assessments of iOS applications, including static and dynamic analysis and runtime instrumentation.
- Collaborate with development teams to design secure architectures and implement security controls.
- Maintain security tools, scripts, and processes supporting secure development.
- Monitor industry trends, zero-day vulnerabilities, new iOS platform security changes, and application security best practices.
- Develop scripts, security automation tools, and instrumentation harnesses to improve mobile application security testing.
- Design and deliver security engineering awareness and adoption training.
- Identify internal security gaps within products.
- Ensure mobile applications are sufficiently tested and support internal and external audits, including MASVS-aligned assessments.
Requirements
- Proven experience planning and conducting mobile application security assessments, testing, methodologies, and vulnerability reporting, with a focus on iOS.
- Strong understanding of secure coding practices.
- Ability to perform manual security code audits.
- Proficiency in at least one mobile or native programming language, such as Swift or Objective-C, and ability to read C/C++ in dependencies.
- Practical knowledge of OWASP MASVS and MASTG, with the ability to plan and execute assessments against them.
- Solid understanding of the iOS security model, including sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC, URL schemes, universal links, app extensions, and app groups.
- Hands-on experience with dynamic instrumentation and mobile testing tools such as Frida, Objection, MobSF, Burp Suite, mitmproxy, and class-dump or otool-style binary inspection.
- Experience bypassing client-side controls such as certificate pinning, jailbreak detection, and anti-tampering, and assessing their resilience.
- Solid understanding of TCP, UDP, HTTP, TLS, and traffic interception on mobile devices.
- Understanding of insecure data storage, sensitive data leakage through logs, backups, snapshots, pasteboards, and caches, and cryptographic misuse in mobile applications.
- Ability to work with networking tools such as Wireshark and tcpdump.
- Familiarity with iOS reverse engineering and debugging tools such as Ghidra, IDA, Hopper, and LLDB.
- Ability to quickly learn new technologies and tools.
- Strong ownership, problem-solving, and investigation skills.
- Ability to build relationships and influence stakeholders across the business.
- Community contributions such as public CVEs, bug bounty recognition, open-source tools, or technical blogs are a bonus.
Nice to Have
- Familiarity with Android application security for cross-platform coverage.
- Familiarity with fuzzing tools and techniques.
Benefits
- Extensive online and in-person training, access to Coursera and Skillshare, mentorship, and internal career opportunities.
- Extra vacation days, additional sick leave, special-occasion and parenting leave.
- Premium private health insurance in Lithuania and Poland.
- Free Calm, Headspace, and Mindletic subscriptions, resilience and mindfulness training, and mental health events.
- In-house gyms, Multisport and Urban Sport cards, online workouts, and physical well-being support.
- Company workations abroad.
- The ability to work from different locations.
- Gifts for birthdays, work anniversaries, weddings, and new family members.
- Summer camps for children and flexible working arrangements for parents.
- Team buildings and company events.
- Access to Nord Security’s Vilnius headquarters and facilities.
More jobs at Nord Security
DevOps Engineer - Mid - Threat Protection
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 43,200-69,600 per year
Retention Data Analyst
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 26,400-54,000 per year
Security Engineer – Mid-Senior – WebSec Team
Nord Security · Poland
PLN 206,400-396,000 per year
Site Reliability Engineer - Senior - NordVPN Apps
Nord Security · Poland
PLN 279,600-408,000 per year
Backend Engineer · Mid-Senior · Go · Coveron
Nord Security · Poland
PLN 237,600-400,800 per year
Similar jobs
Application Security Engineer · Mid-Senior · iOS
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 38,400-75,600 per year
Client Platform Security Engineer
Stripe · United States, New York City, United States
USD 173,000-259,600 per year
Application Security Engineer · Mid-Senior · Low-Level
Nord Security · Poland
PLN 206,400-360,000 per year
Application Security Engineer - Senior
Nord Security · Poland
PLN 276,000-360,000 per year
Application Security Engineer · Mid-Senior · Low-Level
Nord Security · Vilnius, Lithuania, Kaunas, Lithuania
EUR 38,400-75,600 per year
Service Specialist, Employee Technology Support
Bloomberg · New York City, United States
USD 85,000-100,000 per year
iOS Engineer - Senior - Active Growth Squad
Nord Security · Warsaw, Poland
PLN 276,000-400,800 per year
Senior QA Automation Engineer, Network Simulation Platform
Nvidia · Warsaw, Poland
PLN 157,500-357,500 per year