Application Security Engineer - Mid-Senior - iOS

📍 Poland
PLN 206,400-360,000 per year
MIDDLE SENIOR
✅ Remote

Tech Stack

Android @ 2 Debugging @ 2 HTTP @ 3 Manual Testing Networking @ 3 OWASP @ 3 Objective-C @ 5 Reporting @ 3 Security @ 3 Swift @ 5 iOS @ 3

Details

At Nord Security, you’ll help create a safer cyber future by securing applications used by millions of people worldwide.

Responsibilities

  • Conduct security reviews of application designs, source code, and third-party libraries and SDKs.
  • Perform application vulnerability assessments using automated tools and manual testing techniques, including SAST, DAST, SCA, and penetration testing.
  • Perform end-to-end security assessments of iOS applications, including static and dynamic analysis and runtime instrumentation.
  • Collaborate with development teams to design secure architectures and implement security controls.
  • Maintain security tools, scripts, and processes supporting secure development.
  • Monitor industry trends, zero-day vulnerabilities, new iOS platform security changes, and application security best practices.
  • Develop scripts, security automation tools, and instrumentation harnesses to improve mobile application security testing.
  • Design and deliver security engineering awareness and adoption training.
  • Identify internal security gaps within products.
  • Ensure mobile applications are sufficiently tested and support internal and external audits, including MASVS-aligned assessments.

Requirements

  • Proven experience planning and conducting mobile application security assessments, testing, methodologies, and vulnerability reporting, with a focus on iOS.
  • Strong understanding of secure coding practices.
  • Ability to perform manual security code audits.
  • Proficiency in at least one mobile or native programming language, such as Swift or Objective-C, and ability to read C/C++ in dependencies.
  • Practical knowledge of OWASP MASVS and MASTG, with the ability to plan and execute assessments against them.
  • Solid understanding of the iOS security model, including sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC, URL schemes, universal links, app extensions, and app groups.
  • Hands-on experience with dynamic instrumentation and mobile testing tools such as Frida, Objection, MobSF, Burp Suite, mitmproxy, and class-dump or otool-style binary inspection.
  • Experience bypassing client-side controls such as certificate pinning, jailbreak detection, and anti-tampering, and assessing their resilience.
  • Solid understanding of TCP, UDP, HTTP, TLS, and traffic interception on mobile devices.
  • Understanding of insecure data storage, sensitive data leakage through logs, backups, snapshots, pasteboards, and caches, and cryptographic misuse in mobile applications.
  • Ability to work with networking tools such as Wireshark and tcpdump.
  • Familiarity with iOS reverse engineering and debugging tools such as Ghidra, IDA, Hopper, and LLDB.
  • Ability to quickly learn new technologies and tools.
  • Strong ownership, problem-solving, and investigation skills.
  • Ability to build relationships and influence stakeholders across the business.
  • Community contributions such as public CVEs, bug bounty recognition, open-source tools, or technical blogs are a bonus.

Nice to Have

  • Familiarity with Android application security for cross-platform coverage.
  • Familiarity with fuzzing tools and techniques.

Benefits

  • Extensive online and in-person training, access to Coursera and Skillshare, mentorship, and internal career opportunities.
  • Extra vacation days, additional sick leave, special-occasion and parenting leave.
  • Premium private health insurance in Lithuania and Poland.
  • Free Calm, Headspace, and Mindletic subscriptions, resilience and mindfulness training, and mental health events.
  • In-house gyms, Multisport and Urban Sport cards, online workouts, and physical well-being support.
  • Company workations abroad.
  • The ability to work from different locations.
  • Gifts for birthdays, work anniversaries, weddings, and new family members.
  • Summer camps for children and flexible working arrangements for parents.
  • Team buildings and company events.
  • Access to Nord Security’s Vilnius headquarters and facilities.

More jobs at Nord Security

Similar jobs