Zimperium

Zimperium

Mobile Security Solutions | Complete Mobile Security for Apps and Devices Zimperium is the only mobile security platform purpose built for enterprise, securing both mobile devices and applications so they can securely access data. Zimperium is a leadin...

Professional Services
251-1K
Founded 2010
$60M raised

Description

  • Research and analyze advanced detection bypass techniques such as jailbreaking, hooking, and runtime application or system tampering.
  • Evaluate and reverse-engineer tools and frameworks used to attack or evade the company’s products, and document attack vectors.
  • Lead and participate in structured brainstorming sessions to generate new detection ideas and countermeasures.
  • Design, prototype, and implement new detection techniques and algorithms for the iOS platform.
  • Develop, maintain, and improve internal tooling and automation for analysis, triage, and detection development.
  • Review forensic data provided by customers, write technical reports, and provide actionable remediation guidance.
  • Participate in internal penetration testing and adversary emulation to validate new security features.
  • Write and publish technical blog posts on emerging security risks and research findings.

Requirements

  • Strong knowledge of iOS operating system internals, including sandboxing and code-signing.
  • Experience with runtime application security mechanisms and techniques for detecting system tampering and device compromise.
  • Proficiency in reverse engineering with tools such as IDA Pro, Ghidra, Hopper, or equivalent.
  • Experience writing scripts and using reverse engineering tool SDKs, with the ability to isolate and report technical issues.
  • Solid programming experience in C, Python, Objective-C, and Swift.
  • Good understanding of ARM64 assembly for task-specific, time-critical functions.
  • Proficiency with debugging and dynamic binary instrumentation tools such as LLDB, Frida, Objection, or QBDI.
  • Ability to reverse engineer proprietary protocols and interprocess communication mechanisms such as XPC, mach messages, and IOKit.
  • Practical knowledge of jailbreak methods and iOS exploit classes such as kernel exploits, sandbox escapes, and code-signing bypasses.
  • Experience with data analysis methods applied to forensic investigations is a plus.
  • Proven ability to collaborate effectively within a team and lead focused sub-groups toward specific research objectives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Engineer II, Application Security (Remote Eligible)

Smartsheet 1K-5K Internet Software & Services

Smartsheet is hiring a Senior Security Engineer II to strengthen application security for its global SaaS platform by securing AI-integrated features, expanding security automation, and leading high-impact security reviews.

AWS Azure CI/CD GCP GitLab Go Java JavaScript LLM Penetration Testing Python Ruby TypeScript
5 hours, 11 minutes ago

Senior Application Security Engineer

e.l.f. Beauty 251-1K Consumer Goods

Senior Application Security Engineer role at a remote marketing and digital commerce company focused on securing applications across the software development lifecycle.

Agile AWS Azure CI/CD Cybersecurity DevSecOps GCP HTML JavaScript Penetration Testing Python REST API
2 days, 17 hours ago

Binance Accelerator Program - Blockchain / Smart Contract Security

Binance 5K-10K Capital Markets

Binance is seeking a Binance Accelerator Program participant to support smart contract and blockchain security work, including audits, vulnerability analysis, and risk detection across Web3 systems.

Blockchain Git Python VS Code
3 days, 21 hours ago

Senior Application Security Tester & AI Red Team Subject Matter Expert

Evolve Security Academy 11-50 Internet Software & Services

Evolve Security is seeking a senior offensive security specialist to lead complex web, API, and AI red team engagements while defining the firm’s testing methodology for LLM-enabled and agentic systems.

Bash GraphQL JavaScript JWT Metasploit Nmap OpenID Connect Penetration Testing Postman PowerShell Python REST API SAML SPA TypeScript
5 days, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers