Application Security Engineer | Mid-Senior | iOS

17.2k - 30k PLN/ mies.UoP
MidFull-time·Umowa o pracę
#429532·Dodano wczoraj·3
Źródło: Nord Security
Aplikuj teraz

Tech Stack / Keywords

SecurityiOSManual TestingTestingSwiftObjective-CC/C++OWASP

Firma i stanowisko

Nord Security specializes in online security, privacy, and data protection solutions including VPNs, password managers, threat intelligence, and eSIMs for travel, trusted by millions worldwide.

Wymagania

  • Proven experience in mobile application security assessment with a focus on iOS.
  • Strong understanding of secure coding practices.
  • Ability to perform manual security code audits.
  • Proficiency in at least one mobile/native programming language (Swift, Objective-C); ability to read C/C++.
  • Practical knowledge of OWASP MASVS and MASTG; ability to plan and conduct assessments.
  • Solid understanding of the iOS security model including sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC, and inter-app communication methods.
  • Hands-on experience with dynamic instrumentation and mobile testing tools such as Frida, Objection, MobSF, Burp Suite, mitmproxy, class-dump, and otool-style binary inspection.
  • Experience bypassing client-side controls like certificate pinning, jailbreak detection, and anti-tampering mechanisms.
  • Solid understanding of networking protocols such as TCP, UDP, and HTTP, including TLS and traffic interception on mobile devices.
  • Understanding insecure data storage, sensitive data leakage, and cryptographic misuse in mobile apps.
  • Ability to use networking tools such as Wireshark and tcpdump.
  • Familiarity with iOS reverse engineering and debugging tools such as Ghidra, IDA, Hopper, LLDB.
  • Quick assimilation of new technologies and tools.
  • Strong problem-solving and investigation skills with sense of ownership.
  • Ability to build and maintain relationships and influence stakeholders.

Nice to have:

  • Familiarity with Android application security.
  • Familiarity with fuzzing tools and fuzzing techniques.

Obowiązki

  • Conduct security reviews of application designs, source code, and third-party libraries/SDKs.
  • Perform regular application vulnerability assessments using automated tools and manual testing techniques such as SAST, DAST, SCA, and penetration testing.
  • Perform end-to-end security assessments of iOS applications, including static and dynamic analysis and runtime instrumentation.
  • Collaborate with development teams to design secure architectures and implement security controls.
  • Maintain security tools, scripts, and processes to support secure development.
  • Stay updated with industry trends, zero-day vulnerabilities, platform security changes in new iOS releases, and best practices in application security.
  • Develop scripts, security automation tools, and instrumentation harnesses to enhance mobile application security testing.
  • Design and deliver training for security engineering awareness and adoption.
  • Identify internal security gaps within products.
  • Ensure mobile applications are tested appropriately and support internal and external audits, including MASVS-aligned assessments.

Benefity

  • Training, mentorship, and opportunities for professional growth.
  • Extra vacation days, sick days, and personal time off.
  • Private health insurance coverage in Lithuania and Poland.
  • Free subscriptions to Calm, Headspace, Mindletic, and company mindfulness trainings.
  • Access to in-house gyms, sport cards, online workouts, and personal fitness guidance.
  • Company-wide trip abroad (workation).
  • Flexible remote work arrangements.
  • Gifts for birthdays, weddings, and new family members.
  • Support for parenting with summer camps and flexible schedules.
  • Team building and company events.
  • Access to Vilnius HQ amenities including coffee bar, open gyms, kids’ room, music room, and massage chairs.
Dofinansowanie szkoleń
Płatny urlop
Opieka zdrowotna
Karta sportowa
Spotkania integracyjne

Inne informacje

Candidates must provide accurate and complete information during recruitment. Limited use of AI tools for application refinement is acceptable but candidates are responsible for their submissions. Automated tools may be used for application assessment, supporting but not replacing human decision-making. Candidates can opt-out from automated evaluation by direct email. Privacy notices provided for data handling transparency.

Nord Security

Nord Security

34 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz