Nord Security

Application Security Engineer | Mid-Senior | iOS

Nord Security  •  €38k - €76k/yr  •  Vilnius, LT / Kaunas, LT (Remote)  •  9 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

At Nord Security, we’re creating a safer cyber future.

We help people and businesses take back control of their online security, privacy, and data. From VPNs to password managers, threat intelligence to eSIMs for travel—our teams turn complex problems into solutions trusted by millions worldwide.

Life is online. In this role, you’ll help people own it.

Main Responsibilities

  • Conduct security reviews of application designs, source code, and third-party libraries/SDKs;
  • Perform regular application vulnerability assessments using both automated tools and manual testing techniques (e.g., SAST, DAST, SCA, penetration testing);
  • Perform end-to-end security assessments of iOS applications, covering static and dynamic analysis, runtime instrumentation
  • Collaborate with development teams to design secure architectures and implement security controls;
  • Help maintain security tools, scripts, and processes to support secure development;
  • Stay current with industry trends, zero-day vulnerabilities, platform security changes in new iOS releases, and best practices in application security;
  • Develop scripts, security automation tools and instrumentation harnesses to enhance mobile application security testing processes;
  • Design and deliver training for security engineering awareness & adoption;
  • Actively look for internal security gaps within our products
  • Ensure mobile applications are sufficiently tested and support internal and external audits, including MASVS-aligned assessments.

Core Requirements

  • Proven experience in mobile application security assessment planning, testing, methodologies, and vulnerability reporting, with a focus on iOS;
  • Strong understanding of secure coding practices;
  • Ability to perform manual security code audit;
  • Proficiency in at least one mobile/native programming language (Swift, Objective-C), and comfort reading C/C++ where it appears in dependencies;
  • Practical knowledge of the OWASP MASVS and MASTG, and the ability to plan and execute assessments against them;
  • Solid understanding of the iOS security model: sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC and inter-app communication (URL schemes, universal links, app extensions, app groups);
  • Hands-on experience with dynamic instrumentation and mobile testing tooling such as Frida, Objection, MobSF, Burp Suite, mitmproxy and class-dump/otool-style binary inspection;
  • Experience bypassing client-side controls such as certificate pinning, jailbreak detection and anti-tampering, and assessing their resilience;
  • Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol, including TLS and traffic interception on mobile devices;
  • Understanding of insecure data storage, sensitive data leakage (logs, backups, snapshots, pasteboard, caches) and cryptographic misuse in mobile apps;
  • Ability to work with networking tools such as Wireshark, tcpdump;
  • Familiarity with iOS reverse engineering and debugging tooling (e.g. Ghidra, IDA, Hopper, LLDB);
  • Ability to quickly assimilate new technologies and tools;
  • Sense of ownership with strong problem solving and investigation skills;
  • Ability to build and maintain relationships, influence key stakeholders across the business;
  • Bonus points for community contributions like public CVEs, bug bounty recognition, open-source tools, blogs, etc.

Nice to have

  • Familiarity with Android application security, to allow cross-platform coverage;
  • Familiarity with fuzzing tools and fuzzing techniques.

What We Offer

  • Sharpen your edge: training, mentorship, and room to grow — always.
  • Take the time you need: extra vacation days, sick days, and time off when life calls.
  • Get premium healthcare: private health insurance in Lithuania and Poland — fully covered.
  • Protect your peace: enjoy free subscriptions to Calm, Headspace, and Mindletic, and our own resilience and mindfulness trainings.
  • Own your fitness: in-house gyms, sport cards, online workouts, and personal guidance — on us.
  • Pack your bags for workation: experience our company-wide trip abroad to the fullest.
  • Work from anywhere: work from wherever keeps you in the zone.
  • Celebrate your milestones: birthdays, weddings, and new family members — all deserve a gift.
  • Parent with ease: children’s summer camps and flexibility around the schedule — because parenting never pauses.
  • Join the party: team building and company events people talk about for months.
  • Unlock Cyber City: coffee bar, open gyms, kids’ room, music room, massage chairs — our Vilnius HQ is yours to enjoy.

Kindly refer to our Privacy Notice for Recruitment Candidates for comprehensive information regarding our data handling procedures throughout recruitment processes.

We expect all candidates to provide accurate and complete information during the recruitment process. While limited use of AI tools to refine application materials is acceptable, candidates remain fully responsible for ensuring that their submissions reflect their own qualifications, skills, and experience. Any failure to do so may negatively affect participation in the recruitment process. If broader AI assistance is allowed for a particular role or stage, we’ll let you know in advance.

By submitting your application, you acknowledge that it may be processed using automated tools for evaluation purposes. As part of our recruitment process, we may use an AI-based application review tool to help assess applications based on skills and experience relevant to the role. This technology is used to support - not replace - human decision-making, and every application is ultimately reviewed by a recruiter.

If you would like more information about how AI is used in this process or wish to exercise your rights under applicable data privacy laws, please contact us at privacy@nordaccount.com. Should you prefer to opt out of the automated evaluation, please submit your application directly to career@nordsec.com.

Nord Security

About Nord Security

Nord Security is one of the world’s leading providers of digital security and privacy solutions for businesses and individuals.

We are a home for advanced security solutions that share the Nord brand and values. Today, our products are used by millions of customers worldwide and praised by all the major cybersecurity experts and top media outlets.

Since 2012, we have been creating and building award-winning products:

NordVPN - the fastest VPN on the planet, built to protect your online traffic and privacy with next-generation encryption.

NordLayer - an adaptive network access security solution for modern businesses, helping organizations to fulfill scaling and integration challenges.

NordPass - a password manager designed with the user in mind, from simplicity to security. Built using zero-knowledge encryption.

NordStellar - a threat exposure management solution that enables you to detect and respond to cyber threats targeting your company — before they escalate.

NordLocker - a powerful end-to-end encryption tool for safely storing and sharing files. Comes with secure cloud storage.

Saily - a global eSIM service that cuts costs, saves time, and helps travelers stay connected around the world.

Our community of cybersecurity experts, software developers, engineers, data analysts, and other tech professionals share one common goal – create a safe cyber future for everyone.

Explore our open positions here: https://nordsecurity.com/careers

Or refer a friend or colleague: https://nordsecurity.com/referrals

Learn about our Privacy notice for recruitment candidates here: https://bit.ly/3mJFoAy

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Unknown
Year Founded
Unknown
Social Media