Proven experience in mobile application security assessment planning, testing, methodologies, and vulnerability reporting, with a focus on iOS; Strong understanding of secure coding practices; Ability to perform manual security code audit; Proficiency in at least one mobile/native programming language (Swift, Objective-C), and comfort reading C/C++ where it appears in dependencies; Practical knowledge of the OWASP MASVS and MASTG, and the ability to plan and execute assessments against them; Solid understanding of the iOS security model: sandboxing, entitlements, code signing, Keychain, Data Protection classes, App Transport Security, IPC and inter-app communication (URL schemes, universal links, app extensions, app groups); Hands-on experience with dynamic instrumentation and mobile testing tooling such as Frida, Objection, MobSF, Burp Suite, mitmproxy and class-dump/otool-style binary inspection; Experience bypassing client-side controls such as certificate pinning, jailbreak detection and anti-tampering, and assessing their resilience; Solid understanding of networking protocols such as TCP, UDP and the HTTP protocol, including TLS and traffic interception on mobile devices; Understanding of insecure data storage, sensitive data leakage (logs, backups, snapshots, pasteboard, caches) and cryptographic misuse in mobile apps; Ability to work with networking tools such as Wireshark, tcpdump; Familiarity with iOS reverse engineering and debugging tooling (e.g. Collaborate with development teams to design secure architectures and implement security controls; Help maintain security tools, scripts, and processes to support secure development; Stay current with industry trends, zero-day vulnerabilities, platform security changes in new iOS releases, and best practices in application security; Develop scripts, security automation tools and instrumentation harnesses to enhance mobile application security testing processes; Design and deliver training for security engineering awareness & adoption; Actively look for internal security gaps within our products.