> Markdown version of [/jobs/ext/1372238-senior-ios-security-engineer-prodsec](https://www.wearedevelopers.com/jobs/ext/1372238-senior-ios-security-engineer-prodsec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior iOS Security Engineer (ProdSec) - **Company:** iProov - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** IOS Applications, Application Lifecycle Management, Authentication Protocols, Biometrics, Mobile Application Development, Code Review, Cyber Security, Software Debugging, Software Design Patterns, Memory Management, Mobile Application Software, Open Web Application Security, Red Team (Cyber Security), Reverse Engineering, Mobile Security, Software Engineering, Software Security, Ios Frameworks - **Published:** July 22, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=e2ded7b3a542fd35 ## About the Role * 3+ years of professional iOS development experience. * 2+ years of experience in mobile security, application security, or product security. * Proven experience designing and implementing security controls for production mobile applications or SDKs. Technical Skills * Expert-level proficiency in Swift * Deep understanding of: + iOS architecture and internals + Entitlements + Application lifecycle + Memory management + Mach-O binaries + Apple Security Frameworks * Knowledge of cryptography, secure communications, and authentication mechanisms. Security Expertise * Experience designing or implementing: + Runtime Application Self-Protection (RASP) + Application hardening controls + Anti-tampering protections + Anti-debugging mechanisms + Certificate pinning + Application integrity validation * Strong understanding of: + OWASP Mobile Top 10 + OWASP MASVS + Secure SDLC practices + Mobile attack techniques and adversarial behaviour * Knowledge of: * Frida * Objection * Dynamic instrumentation frameworks * Jailbreak environments * Runtime hooking methodologies Nice-to-haves The ideal candidate brings experience with biometric authentication or identity verification technologies, along with a background in securing mobile SDKs deployed within third-party applications. They will have developed custom RASP (runtime application self-protection) capabilities and have solid knowledge of device attestation and trust assessment technologies. ## Description We are seeking an iOS Security Engineer to join our Product Security team and help secure our iOS applications, SDKs, and biometric verification technologies against evolving threats. This role focuses on researching, designing, and implementing advanced mobile security protections, with a particular emphasis on application hardening, Runtime Application Self-Protection (RASP), anti-tampering controls, and runtime trust assessment. You will play a key role in identifying emerging attack techniques targeting mobile and biometric ecosystems and developing innovative defenses to protect our products and customers. The successful candidate combines deep iOS engineering expertise with a security mindset and a passion for understanding how attackers operate. They will work closely with Science and Engineering teams to ensure security is embedded throughout the product lifecycle. How you can make an impact Mobile Security Architecture & Hardening * Design and implement security controls for iOS applications and SDKs. * Develop protections against reverse engineering, runtime manipulation, code injection, dynamic instrumentation, and application tampering. * Implement and enhance jailbreak detection, application integrity validation, and runtime protection mechanisms. * Design secure approaches for protecting sensitive data, cryptographic assets, and biometric-related workflows. * Define and promote mobile security best practices across engineering teams. Mobile Security Research & RASP Innovation * Research emerging mobile attack techniques targeting biometric identity verification systems, including runtime manipulation, device compromise, and application abuse. * Evaluate, prototype, and implement Runtime Application Self-Protection (RASP) controls for iOS applications and SDKs. * Assess the effectiveness of commercial and custom mobile protection technologies against evolving threats. * Develop novel approaches to application integrity, runtime trust assessment, anti-tampering, anti-debugging, and anti-instrumentation controls. * Investigate bypass techniques used by attackers and security researchers to identify gaps in existing protections. * Be a key member of the Product Security function, collaborating with Science, Red Team and Engineering teams to evaluate, develop, and enhance security controls for biometric verification products and services. * Contribute to the security roadmap by identifying opportunities to strengthen trust signals within biometric verification workflows. * Produce technical research, proof-of-concepts, and recommendations based on threat trends affecting digital identity and biometric ecosystems. Security Reviews & Engineering * Perform security architecture reviews and code reviews. * Assess security implications of new platform capabilities, third-party libraries, and architectural changes. * Build security tooling, frameworks, and libraries that improve the security posture of iOS products. * Support secure software development lifecycle (SSDLC) initiatives. * Contribute to security standards, design patterns, and technical guidance for mobile development teams. * Participate in strategic security initiatives and long-term product security planning. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Detect Hand Pose with Vision](https://www.wearedevelopers.com/videos/135-detect-hand-pose-with-vision) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Biometric Phone Chargers, $40m Domain Names & AI Movies Winning Awards - Peter Kröner](https://www.wearedevelopers.com/videos/1810-biometric-phone-chargers-40m-domain-names-ai-movies-winning-awards-peter-kroner) - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Cross Platform Mobile Development Frameworks to Use in 2025](https://www.wearedevelopers.com/magazine/404-cross-platform-mobile-development-frameworks-to-use-in-2025) - [Apple iOS vs. Web Apps affects us all - help the OWA to ensure you can release apps for everyone](https://www.wearedevelopers.com/magazine/389-apple-ios-vs-web-apps-affects-us-all-help-the-owa-to-ensure-you-can-release-apps-for-everyone) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)