Senior iOS Security Engineer
About iProov
iProov provides science-based biometric solutions that enable the world's most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Our award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance.
This global trust is built not only on our technology but on the strength of the people behind it. For us, diversity at iProov is about reflecting the customers we serve, holding the principles of equality and inclusion at the heart of everything we do and all that we stand for, embracing differences, creating possibilities, and growing together. We aim to foster a culture where individuals of all backgrounds feel confident in bringing their whole selves to work, feel included, and their talents are nurtured, empowering them to contribute fully to our purpose.
The Role
Reports to: Head of Red Team
Location: UK
Comp: Negotiable (Base) + Company Performance Bonus (10%) + Share Options + UK iProov Benefits
We are seeking an iOS Security Engineer to join our Product Security team and help secure our iOS applications, SDKs, and biometric verification technologies against evolving threats.
This role focuses on researching, designing, and implementing advanced mobile security protections, with a particular emphasis on application hardening, Runtime Application Self-Protection (RASP), anti-tampering controls, and runtime trust assessment. You will play a key role in identifying emerging attack techniques targeting mobile and biometric ecosystems and developing innovative defenses to protect our products and customers.
The successful candidate combines deep iOS engineering expertise with a security mindset and a passion for understanding how attackers operate. They will work closely with Science and Engineering teams to ensure security is embedded throughout the product lifecycle.
Mobile Security Architecture & Hardening
-
Design and implement security controls for iOS applications and SDKs.
-
Develop protections against reverse engineering, runtime manipulation, code injection, dynamic instrumentation, and application tampering.
-
Implement and enhance jailbreak detection, application integrity validation, and runtime protection mechanisms.
-
Design secure approaches for protecting sensitive data, cryptographic assets, and biometric-related workflows.
-
Define and promote mobile security best practices across engineering teams.
Mobile Security Research & RASP Innovation
-
Research emerging mobile attack techniques targeting biometric identity verification systems, including runtime manipulation, device compromise, and application abuse.
-
Evaluate, prototype, and implement Runtime Application Self-Protection (RASP) controls for iOS applications and SDKs.
-
Assess the effectiveness of commercial and custom mobile protection technologies against evolving threats.
-
Develop novel approaches to application integrity, runtime trust assessment, anti-tampering, anti-debugging, and anti-instrumentation controls.
-
Investigate bypass techniques used by attackers and security researchers to identify gaps in existing protections.
-
Be a key member of the Product Security function, collaborating with Science, Red Team and Engineering teams to evaluate, develop, and enhance security controls for biometric verification products and services.
-
Contribute to the security roadmap by identifying opportunities to strengthen trust signals within biometric verification workflows.
-
Produce technical research, proof-of-concepts, and recommendations based on threat trends affecting digital identity and biometric ecosystems.
Security Reviews & Engineering
-
Perform security architecture reviews and code reviews.
-
Assess security implications of new platform capabilities, third-party libraries, and architectural changes.
-
Build security tooling, frameworks, and libraries that improve the security posture of iOS products.
-
Support secure software development lifecycle (SSDLC) initiatives.
-
Contribute to security standards, design patterns, and technical guidance for mobile development teams.
-
Participate in strategic security initiatives and long-term product security planning.
Experience
-
3+ years of professional iOS development experience.
-
2+ years of experience in mobile security, application security, or product security.
-
Proven experience designing and implementing security controls for production mobile applications or SDKs.
Technical Skills
-
Expert-level proficiency in Swift
-
Deep understanding of:
-
iOS architecture and internals
-
Entitlements
-
Application lifecycle
-
Memory management
-
Mach-O binaries
-
Apple Security Frameworks
-
Knowledge of cryptography, secure communications, and authentication mechanisms.
Security Expertise
-
Experience designing or implementing:
-
Runtime Application Self-Protection (RASP)
-
Application hardening controls
-
Anti-tampering protections
-
Anti-debugging mechanisms
-
Certificate pinning
-
Application integrity validation
-
Strong understanding of:
-
OWASP Mobile Top 10
-
OWASP MASVS
-
Secure SDLC practices
-
Mobile attack techniques and adversarial behaviour
-
Knowledge of:
-
Frida
-
Objection
-
Dynamic instrumentation frameworks
-
Jailbreak environments
-
Runtime hooking methodologies
Nice-to-haves
The ideal candidate brings experience with biometric authentication or identity verification technologies, along with a background in securing mobile SDKs deployed within third-party applications. They will have developed custom RASP (runtime application self-protection) capabilities and have solid knowledge of device attestation and trust assessment technologies.
- 25 days Annual Leave, plus 8 Bank Holidays (more holiday with service - up to an extra 5 days off per year based on your continuous service)
-
Growth Shares allocated after passing probation (6 months of service)
-
Salary sacrifice schemes including: Pension, Cycle To Work and Electric Car Scheme
-
Nursery Sacrifice Scheme
-
Work Overseas Perk - Work globally for up to 2 weeks
-
Life Assurance
-
SmartHealth - Access to private GP, Psychologist, Nutritionist along with tailored fitness plans for both you and your family
-
Benefit from personalized 1:1 career coaching with our in-house Occupational Psychologist
-
Award winning L&D platform with personal allocated training budgets
-
Enhanced paid family leave
-
Pension - 5% employee, 3% employer
-
Flexible hybrid working environment
-
Free Barista Coffee/Tea, biscuits with fruit in the WeWork office
-
Free access to WeWork discounts and free online well-being sessions
-
Vitality Health - a range of options available on this below
The Vitality Programme includes a number of reward benefits that all employees have access to as part of the plan, for example:
-
Private Health cover including Dental, Optical, and Audiology
- 50% off monthly gym memberships
- Apple watches significantly discounted based member vitality status
- Half price trainers with Runners Need
- Weekly rewards - Free coffee with Café Nero
- Monthly rewards - Free Cinema ticket
- Discounts on travel with Expedia (hotels) and Mr & Mrs Smith with discounts getting greater throughout the year based on a members vitality status
- Amazon prime free months based on activity
- Up to 25% cashback at Waitrose when buying healthy foods
- 75% off stays at Champneys Health Spas
- Allen Carr's £299 no smoking programme for free
- Access to Vitality Healthy Mind with 30% off Headspace subscriptions and the ability to earn Vitality points for using Buddhify, Calm and Headspace
- Discounts on Weight Watchers
- 50%-80% off Comprehensive Private Health screenings
Our Culture & Recruitment Process
At iProov, we're incredibly proud of the culture we've carefully curated. Our culture enables diverse thought, curiosity and innovation. Our team strives to do everything to the highest standard possible to achieve the remarkable. To do that we need different perspectives, experiences and ideas alongside an environment where these are welcomed - we want everyone to feel confident in bringing their full capabilities to work. We firmly believe psychological safety is key to building and nurturing great teams. We're a small and dynamic company, that means having the right skills is important, and we know that our best work emerges when people feel secure, welcomed and respected.
As an equal opportunities employer, we encourage applications from people of all backgrounds. We're committed to building a workforce that is representative of the people we serve. We will not put someone at a disadvantage or treat them less favourably because of race, color, national origin, ancestry, age, disability, creed, religion or belief, sex, sexual orientation, gender reassignment, marriage or civil partnership, or pregnancy and maternity. Our goal is to find people who are passionate about creating a safer, more secure world.
Our recruitment process is designed to be fair and transparent, focusing solely on your qualifications, competence, and suitability for the role. We review all applications carefully and will be in touch with shortlisted candidates regarding the next steps in our interview process. If you need an adjustment for a disability or any other reason during the hiring process, please send a request to [email protected]