- Nord Security
- Poland, 10
- 27 days ago
- zł 17,200–zł 30,000 / month
Application Security Engineer · Mid-Senior · iOS Nord Security Poland Remote Engineering.
Before you go
Before you leave us, sign up for our email alerts
We don't do job spam, just the best digital jobs delivered straight to your inbox.
Application Security Engineer · Mid-Senior · iOS Nord Security Poland Remote Engineering: our view in 3 lines...
- The Role:This role is for an application security engineer focused on iOS mobile applications and secure development practices.
- The Person:The person will review application designs and source code, run vulnerability assessments and security tests, secure architectures with developers, maintain security tools and processes, and deliver security awareness training.
- Requirements:The ideal candidate has proven experience in mobile application security assessment planning, testing, methodologies, and vulnerability reporting, with a focus on iOS, plus strong knowledge of OWASP MASVS and MASTG.
About the role
try{(function(){var e=typeof window<`u`?window:typeof global<`u`?global:typeof globalThis<`u`?globalThis:typeof self<`u`?self:{},t=new e.Error().stack;t&&(e._sentryDebugIds=e._sentryDebugIds||{},e._sentryDebugIds[t]=`c3f8b993-9ee4-42ab-b11d-325efcff15de`,e._sentryDebugIdIdentifier=`sentry-dbid-c3f8b993-9ee4-42ab-b11d-325efcff15de`)})()}catch{}(function(){try{var e=typeof window<`u`?window:typeof global<`u`?global:typeof globalThis<`u`?globalThis:typeof self<`u`?self:{};e._sentryModuleMetadata=e._sentryModuleMetadata||{},e._sentryModuleMetadata[new e.Error().stack]=function(e){for(var t=1;t{let n=t.getBoundingClientRect().top>window.innerHeight;e.classList.toggle(`translate-y-full`,!n),e.classList.toggle(`opacity-0`,!n),e.classList.toggle(`translate-y-0`,n),e.classList.toggle(`opacity-100`,n)};window.addEventListener(`scroll`,n,{passive:!0}),window.addEventListener(`resize`,n),n()}
Join our team as
Application Security Engineer · Mid-Senior · iOS
At Nord Security, weâre creating a safer cyber future.
We help people and businesses take back control of their online security, privacy, and data. From VPNs to password managers, threat intelligence to eSIMs for travelâour teams turn complex problems into solutions trusted by millions worldwide.
Life is online. In this role, youâll help people own it.
Main Responsibilities
-
Conduct security reviews of application designs, source code, and third-party libraries/SDKs;
-
Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing);
-
Perform end-to-end security assessments of iOS applications, covering static and dynamic analysis, runtime instrumentation
-
Collaborate with development teams to design secure architectures and implement security controls;
-
Help maintain security tools, scripts, and processes to support secure development;
-
Stay current with industry trends, zero-day vulnerabilities, platform security changes in new iOS releases, and best practices in application security;
-
Develop scripts, security automation tools and instrumentation harnesses to enhance mobile application security testing processes;
-
Design and deliver training for security engineering awareness & adoption;
-
Actively look for internal security gaps within our products
-
Ensure mobile applications are sufficiently tested and support internal and external audits, including MASVS-aligned assessments.
Core Requirements
-
Proven experience in mobile application security assessment planning, testing, methodologies, and vulnerability reporting, with a focus on iOS;
-
Strong understanding of secure coding practices;
-
Ability to perform manual security code audit;
-
Proficiency in at least one mobile/native programming language (Swift, Objective-C), and comfort reading C/C++ where it appears in dependencies;
-
Practical knowledge of the OWASP MASVS and MASTG, and the ability to plan and execute assessments against them;
-
Solid understanding of the iOS security model: sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC and inter-app communication (URL schemes, universal links, app extensions, app groups);
-
Hands-on experience with dynamic instrumentation and mobile testing tooling such as Frida, Objection, MobSF, Burp Suite, mitmproxy and class-dump/otool-style binary inspection;
-
Experience bypassing client-side controls such as certificate pinning, jailbreak detection and anti-tampering, and assessing their resilience;
-
Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol, including TLS and traffic interception on mobile devices;
-
Understanding of insecure data storage, sensitive data leakage (logs, backups, snapshots, pasteboard, caches) and cryptographic misuse in mobile apps;
-
Ability to work with networking tools such as Wireshark, tcpdump;
-
Familiarity with iOS reverse engineering and debugging tooling (e.g. Ghidra, IDA, Hopper, LLDB);
-
Ability to quickly assimilate new technologies and tools;
-
Sense of ownership with strong problem solving and investigation skills;
-
Ability to build and maintain relationships, influence key stakeholders across the business;
-
Bonus points for community contributions like public CVEs, bug bounty recognition, open-source tools, blogs, etc.
Nice to have
-
Familiarity with Android application security, to allow cross-platform coverage;
-
Familiarity with fuzzing tools and fuzzing techniques.
What we offer
ð Sharpen your edge
Growth is built into how we work. Extensive online and in-person training programs, access to platforms like Coursera and Skillshare, a mentorship program, and internal career moves when youâre ready for something new â your development has no ceiling here.
ð¿ Take the time you need
Rest isnât a reward â itâs part of the deal. Enjoy extra vacation days that grow with your time here, plus additional days off for sick leave, special occasions, and parenting.
ð¥ Get premium healthcare
Your health shouldnât be something you worry about. We provide premium private health insurance so you have peace of mind and fast access to care whenever you need it. Available in Lithuania and Poland.
𪷠Protect your peace
A peaceful mind isnât a luxury â itâs the foundation. We provide free subscriptions to top-rated Calm, Headspace, and Mindletic apps, offer resilience and mindfulness trainings, and run dedicated mental health events.
ðð» Own your fitness
Feeling good shapes how you work, think, and create. Thatâs why we offer in-house gyms, Multisport and Urban Sport cards, and online workouts. Need something tailored? Our Physical Well-Being experts are here with group mobility sessions, fitness guidance, and one-on-one consultations.
ð´ Pack your bags for workation
Picture this: the entire company flies out abroad. The days are packed with workshops, activities, concerts, and real time together. Itâs legendary. If youâve heard stories, theyâre probably true.
âï¸ Work from anywhere
New surroundings spark new thinking. When you need a reset, switch location and work from wherever keeps you sharp, creative, and in the zone.
ð Celebrate your milestones
The moments that make life special shouldnât pass quietly. Birthdays, work anniversaries, weddings, new family members â each is marked with a special gift.
ð¶ð» Parent with ease
When youâre a parent, the juggle is real. To make it smoother, we organize summer camps for the little ones and offer flexibility that lets you show up both for your family and your team.
ð Join the party
It never gets boring here. Get ready for team buildings that bring people closer, year-round company events that are equal parts educational and energizing, and the highlights everyone waits for â our iconic summer and winter celebrations.
â Unlock Cyber City
Whether Vilnius-based or visiting from remote, our Vilnius HQ is fully yours to enjoy. Need focus? Silent room. Need energy? Open gyms. Need a break? Game room, music room, coffee bar. Itâs a modern workspace built with your comfort in mind.
Kindly refer to our Privacy Notice for Recruitment Candidates for comprehensive information regarding our data handling procedures throughout recruitment processes.
We expect all candidates to provide accurate and complete information during the recruitment process. While limited use of AI tools to refine application materials is acceptable, candidates remain fully responsible for ensuring that their submissions reflect their own qualifications, skills, and experience. Any failure to do so may negatively affect participation in the recruitment process. If broader AI assistance is allowed for a particular role or stage, weâll let you know in advance.
By submitting your application, you acknowledge that it may be processed using automated tools for evaluation purposes. As part of our recruitment process, we may use an AI-based application review tool to help assess applications based on skills and experience relevant to the role. This technology is used to support - not replace - human decision-making, and every application is ultimately reviewed by a recruiter.
If you would like more information about how AI is used in this process or wish to exercise your rights under applicable data privacy laws, please contact us at [email protected]. Should you prefer to opt out of the automated evaluation, please submit your application directly to [email protected].
Congrats â we have received your application!
If your application is a good fit for our team, weâll contact you directly.
Explore other roles that match your skills
