
Application Security Engineer – Mid-Senior, iOS
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland.
• Execute security evaluations of application architecture, source code, and third-party libraries/SDKs.
• Conduct application vulnerability assessments utilizing automated tools and manual testing methods, including SAST, DAST, SCA, and penetration testing.
• Carry out comprehensive security assessments of iOS applications, incorporating both static and dynamic analysis as well as runtime instrumentation.
• Partner with development teams to establish secure architectures and implement security controls.
• Oversee the maintenance of security tools, scripts, and processes that facilitate secure development.
• Stay updated on industry trends, zero-day vulnerabilities, new security changes in the iOS platform, and best practices in application security.
• Create scripts, security automation tools, and instrumentation harnesses for testing mobile application security.
• Design and provide training in security engineering awareness.
• Detect internal security vulnerabilities within products.
• Confirm that mobile applications undergo adequate testing and comply with internal and external audits, including assessments aligned with MASVS.
• Demonstrated experience in planning, testing methodologies, and vulnerability reporting for mobile application security, with an emphasis on iOS.
• In-depth knowledge of secure coding practices.
• Capability to perform manual security code audits.
• Proficiency in Swift or Objective-C, with the capacity to interpret C/C++ in dependencies.
• Practical understanding of OWASP MASVS and MASTG, including the ability to plan and carry out assessments against them.
• Comprehensive grasp of the iOS security model, which encompasses sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC, URL schemes, universal links, app extensions, and app groups.
• Hands-on experience with tools like Frida, Objection, MobSF, Burp Suite, mitmproxy, and class-dump/otool-style binary inspection.
• Experience in circumventing certificate pinning, jailbreak detection, and anti-tampering mechanisms.
• Strong understanding of TCP, UDP, HTTP, TLS, and mobile traffic interception.
• Awareness of insecure data storage, sensitive data leakage, and cryptographic misuse within mobile applications.
• Proficiency in using Wireshark and tcpdump.
• Familiarity with iOS reverse engineering and debugging tools, such as Ghidra, IDA, Hopper, and LLDB.
• Ability to swiftly adapt to new technologies and tools.
• Excellent problem-solving and investigative skills.
• Capacity to build relationships and influence stakeholders across the organization.
• Knowledge of Android application security is advantageous.
• Familiarity with fuzzing tools and techniques is a plus.
• Contributions to the community, such as public CVEs, bug bounty acknowledgments, open-source tools, or blogs, are a bonus.
• Training, mentorship, and opportunities for growth.
• Additional vacation days, sick leave, and time off.
• Comprehensive private health insurance in Lithuania and Poland, fully covered.
• Complimentary subscriptions to Calm, Headspace, and Mindletic.
• Resilience and mindfulness training programs.
• Access to in-house gyms, sport cards, online workouts, and personal coaching.
• Company-wide workation trips abroad.
• Flexibility to work from any location that enhances your productivity.
• Gifts for birthdays, weddings, and new family members.
• Children’s summer camps and flexible scheduling options.
• Team building and company events.
• Access to Vilnius HQ facilities including a coffee bar, gyms, a kids’ room, a music room, and massage chairs.
• Performance bonuses available.
Bugcrowd
PowerSchool
PowerSchool
Thermal Scientific Works
Get handpicked remote jobs straight to your inbox weekly.