Zimperium

Zimperium

Mobile Security Solutions | Complete Mobile Security for Apps and Devices Zimperium is the only mobile security platform purpose built for enterprise, securing both mobile devices and applications so they can securely access data. Zimperium is a leadin...

Professional Services
251-1K
Founded 2010
$60M raised

Description

  • Research and analyze advanced detection bypass techniques such as jailbreaking, hooking, and runtime application or system tampering.
  • Evaluate and reverse-engineer tools and frameworks used to attack or evade the company’s products, and document attack vectors.
  • Lead and participate in structured brainstorming sessions to generate new detection ideas and countermeasures.
  • Design, prototype, and implement new detection techniques and algorithms for the iOS platform.
  • Develop, maintain, and improve internal tooling and automation for analysis, triage, and detection development.
  • Review forensic data provided by customers, write technical reports, and provide actionable remediation guidance.
  • Participate in internal penetration testing and adversary emulation to validate new security features.
  • Write and publish technical blog posts on emerging security risks and research findings.

Requirements

  • Strong knowledge of iOS operating system internals, including sandboxing and code-signing.
  • Experience with runtime application security mechanisms and techniques for detecting system tampering and device compromise.
  • Proficiency in reverse engineering with tools such as IDA Pro, Ghidra, Hopper, or equivalent.
  • Experience writing scripts and using reverse engineering tool SDKs, with the ability to isolate and report technical issues.
  • Solid programming experience in C, Python, Objective-C, and Swift.
  • Good understanding of ARM64 assembly for task-specific, time-critical functions.
  • Proficiency with debugging and dynamic binary instrumentation tools such as LLDB, Frida, Objection, or QBDI.
  • Ability to reverse engineer proprietary protocols and interprocess communication mechanisms such as XPC, mach messages, and IOKit.
  • Practical knowledge of jailbreak methods and iOS exploit classes such as kernel exploits, sandbox escapes, and code-signing bypasses.
  • Experience with data analysis methods applied to forensic investigations is a plus.
  • Proven ability to collaborate effectively within a team and lead focused sub-groups toward specific research objectives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Product Security Engineer (Contract)

Iru Enterprise IT, cybersecurity, identity/security, endpoint management, compliance software

Iru is seeking a Senior Product Security Engineer for a 6-month, 40-hour-per-week contract to embed security throughout the software development lifecycle and help teams build secure-by-design products.

AWS Azure GCP GitHub Actions Kubernetes Microservices OAuth OpenID Connect
13 hours, 5 minutes ago

Senior Application Security Engineer

Radicle Health 11-50 Internet Software & Services

Radicle Health is seeking a Senior Application Security Engineer to strengthen security across its 10 SaaS platforms by integrating security tooling and practices into software development and operations.

AWS HIPAA OWASP Penetration Testing
13 hours, 50 minutes ago

Lead Security Engineer - Penetration Testing & AI Security

HighLevel 251-1K Internet Software & Services

HighLevel is seeking a Lead Security Engineer to secure its SaaS platform and AI-enabled products through application security leadership, secure development practices, and adversarial testing of AI systems.

Bash CI/CD Cybersecurity DevSecOps Docker Go JavaScript JWT Kubernetes Microservices OpenID Connect OWASP Penetration Testing Python SAML
6 days, 14 hours ago

Application Security Engineer II - Contract ( 6 months )

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a remote Application Security Engineer to triage and validate vulnerability submissions for client bug bounty programs, assess severity, and coordinate responses with researchers and customers.

Burp Suite Nmap
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers