Job Closed
This listing is no longer active.
A private community for global citizens.
Senior Product Security Engineer – iOS Mobile App
Location
California
Posted
152 days ago
Salary
0
Seniority
Senior
Job Description
Senior Product Security Engineer – iOS Mobile App
Raya
• Lead the security review of iOS application architecture and design, ensuring security is built-in from the ground up. • Conduct security-focused code reviews for the iOS application, and implement/manage static and dynamic application security testing (SAST/DAST) tools. • Oversee the identification, assessment, and remediation of vulnerabilities within the iOS application and its supporting infrastructure. • Perform threat modeling for new features and existing components of the iOS application and its backend services. • Drive the adoption and enforcement of secure development practices within the mobile engineering teams. • Ensure the security of APIs consumed and exposed by the iOS application. • Manage and refine cloud IAM roles and permissions for the mobile app's backend infrastructure to enforce the principle of least privilege and improve our cloud security posture. • Support incident response activities related to the iOS application, including investigation and remediation. • Evaluate, implement, and manage security tools relevant to mobile application security. • Provide guidance and training to mobile developers on secure coding practices. • Report directly to the Head of Information Security on the security posture of the iOS application and related infrastructure.
Job Requirements
- 8+ years of experience in a security role with a strong focus on application security.
- 5+ years of experience in a product security engineering role with a strong focus on mobile (iOS) application security.
- Extensive experience with secure coding principles, mobile security frameworks, and common mobile vulnerabilities (e.g., OWASP Mobile Top 10).
- Strong understanding of iOS platform security features and best practices.
- Proficiency in Swift/Objective-C with a minimum of 3 years of Swift experience, and experience with mobile development tools and environments.
- Proficiency in NodeJS with a minimum of 3 years of NodeJS experience, and experience with NodeJS backend mobile development tools and environments.
- 3+ years of experience with cloud security principles and cloud IAM (e.g., AWS IAM, Cloud Connectivity) as it relates to mobile backend infrastructure.
- Experience with static and dynamic application security testing (SAST/DAST) tools for mobile applications.
- Excellent analytical, problem-solving, and troubleshooting skills.
- 2+ years of experience in a senior or lead security engineer role.
- Strong proficiency of AI coding platforms like Claude Code, Copilot, etc.
- Strong leadership and communication skills, with the ability to influence and collaborate across engineering teams.
- Ability to prioritize tasks and manage projects effectively in a fast-paced environment.
- Experience with scripting and automation (e.g., Python, Bash) for security tasks.
- Experience with GitHub Actions.
- Experience with DevSecOps and CICD SCA tools.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Compliance Specialist – DoD
CloudflareAt Cloudflare, we have our eyes set on an ambitious goal — to help build a better Internet.
• Lead Cloudflare through the DoD IL4 Authorization process • Manage all aspects of the DoD IL4 assessment and authorization process and Authorization maintenance • Update and maintain the DoD IL4 requirements in Cloudflare’s Common Control Framework • Work cross-functionally with Engineering, Legal, Product, and operational teams to drive security control implementation for the organization • Improve the maturity of Cloudflare’s Security Compliance program • Help guide our overall security policy and governance architecture • Have input into the overall security compliance strategy
• Design and implement security controls across cloud infrastructure, endpoints, identity systems and applications • Harden GCP environments including compute, networking, GKE, IAM and logging configurations • Deploy, configure, and maintain security tooling including SIEM, vulnerability scanners, EDR, and secrets management • Build automation for security operations, evidence collection and compliance reporting using Python, Terraform, and CI/CD pipelines • Develop and maintain logging and monitoring architecture to support detection, response, and audit requirements • Implement and enforce identity and access management controls, including SSO, MFA and least privilege access • Conduct vulnerability assessments and drive remediation efforts across infrastructure and applications • Support incident response activities including investigation, containment, and root cause analysis • Collaborate with engineering teams to integrate security into development workflows and CI/CD pipelines • Document security configurations, architecture decisions, and runbooks • Support compliance efforts by implementing technical controls required for CMMC, FedRAMP, ITAR and DFARS
Cybersecurity GRC – Compliance Analyst
Trimble Inc.Trimble technology is transforming critical industries to power an interconnected world of work.
• Perform SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701 and ISO 42001 gap analysis and recommend process, procedural, documentation and tooling recommendations to remediate. • Improve Compliance and certification scope efficiency via review and enhancements of the Trimble Common Control Framework • Perform ISO 27001 & ISO27701 Internal Audits. • Perform SOC 1 & 2, NIST 800-171 Internal & External Audits • Contribute to annual policy revisions and maintenance of the IMS. • Constantly coordinate with key business stakeholders and the external auditor • Present metrics derived from the Integrated Management System, audit results, trends in risk, and corrective action plans to senior leadership. • Contribute to the creation of processes and procedures that increase efficiency of the overall compliance program across all standards and frameworks. • Collaborate with Cybersecurity team members, Trimble businesses across various geographies. • Contribute to risk management processes to ensure business risk posture is properly calculated and proactively managed. • Produce and analyze information that will accurately demonstrate the risk posture of each business and drive actions to reduce and manage technical risks. • Be able to understand and communicate technical risks to a broad set of stakeholders.
• I’m seeking a knowledgeable, collaborative, and creative leader to scale our security program and build out our security team. • This leader will report directly to me. • You’ll inherit a competent security program and scale this program through our next phase of high growth. • This includes building the Security team from scratch (which means you’ll be a hands-on security generalist to start). • By the end of the year, you’ll have defined our security strategy and roadmap, and added people (1-3 individuals), processes, and automation to scale yourself out of routine work. • Collaborate with other departments to solve interesting security challenges concerning sensitive information and PII. • Lead and grow a culture of security awareness among over 250 people today and more than 500 people by the end of the year.




