Position Overview
We are seeking a highly skilled Senior iOS Reverse Engineer with extensive experience analyzing iOS applications, binaries, frameworks, and system components.
The ideal candidate is first and foremost an expert reverse engineer, but must also possess a strong understanding of iOS security architecture and security mechanisms.
This individual will be responsible for understanding complex and undocumented software behavior through static and dynamic analysis, analyzing compiled code, identifying how applications and system components interact, and producing detailed technical findings.
The successful candidate must be comfortable working independently on difficult technical problems where documentation may be limited or nonexistent.
Key ResponsibilitiesiOS Reverse Engineering
- Perform advanced static and dynamic analysis of iOS applications and authorized system components.
- Reverse engineer ARM64 and ARM64e binaries.
- Analyze Mach-O executables, libraries, frameworks, and related components.
- Reverse engineer compiled Objective-C, Swift, C, and C++ code.
- Reconstruct application logic, algorithms, data structures, and control flow from compiled binaries.
- Analyze undocumented application and system behavior.
- Analyze interactions between applications, frameworks, libraries, services, and operating-system components.
- Investigate APIs, protocols, data formats, and communication mechanisms.
- Identify functionality and dependencies within complex software.
- Perform debugging, instrumentation, tracing, and runtime analysis.
- Develop repeatable methodologies for complex reverse-engineering tasks.
- Clearly document technical findings and research results.
iOS Security Knowledge
While this is primarily a reverse-engineering position, candidates must have a strong understanding of iOS security.
The candidate should understand how Apple's security architecture affects the software being analyzed, including:
- iOS application sandboxing
- Entitlements
- Code signing
- Application and process isolation
- Keychain and data protection concepts
- Authentication and authorization
- iOS permissions
- Inter-process communication
- XPC and Mach services
- Memory protections
- ASLR
- Pointer Authentication Codes (PAC)
- ARM64e
- Secure Boot and chain-of-trust concepts
- Secure Enclave concepts
- Dynamic linking and dyld
- Kernel and user-space boundaries
- Apple's platform security model
- Modern iOS security mitigations
The candidate should be capable of recognizing when security mechanisms are influencing application or system behavior and incorporate that understanding into their reverse-engineering work.
Technical Skills
Strong experience is expected in:
- ARM64 / ARM64e assembly
- Mach-O binary analysis
- Objective-C runtime
- Swift and Swift runtime
- C/C++
- iOS internals
- Static analysis
- Dynamic analysis
- Debugging and instrumentation
- Operating-system fundamentals
- Networking and communications protocols
Experience with tools such as:
- IDA Pro
- Ghidra
- Binary Ninja
- Hopper
- LLDB
- Frida
- Xcode
- Python
Candidates who have developed their own reverse-engineering, debugging, instrumentation, or analysis tools are particularly desirable.
Research & Analysis
The Senior iOS Reverse Engineer will be expected to:
- Take an unfamiliar application, binary, or component and determine how it operates.
- Identify important functions, classes, objects, and data structures.
- Reconstruct undocumented functionality.
- Trace execution paths and data flows.
- Analyze communications between software components.
- Understand security boundaries affecting the analyzed software.
- Develop scripts and tools to accelerate analysis.
- Validate technical hypotheses through controlled testing.
- Produce clear and reproducible technical documentation.
Required Qualifications
- 5+ years of relevant reverse-engineering experience, preferably involving iOS or other Apple platforms.
- Demonstrable expertise in software reverse engineering.
- Strong iOS reverse-engineering experience.
- Strong ARM64 assembly knowledge.
- Experience analyzing Mach-O binaries.
- Strong understanding of Objective-C.
- Experience analyzing compiled Swift applications.
- Strong understanding of iOS internals.
- Strong understanding of iOS security architecture and security mechanisms.
- Extensive experience with static and dynamic analysis.
- Strong debugging skills.
- Programming or scripting experience in Python, C, C++, Objective-C, Swift, or similar languages.
- Ability to independently solve difficult technical problems.
- Ability to work effectively with undocumented or poorly documented systems.
- Strong technical documentation and communication skills.
Exceptional candidates with fewer years of formal experience may be considered based on demonstrated technical capability.
Preferred Experience
Additional experience in the following areas is highly desirable:
- Mobile security research
- Vulnerability analysis
- Binary instrumentation
- Protocol reverse engineering
- Network protocol analysis
- macOS reverse engineering
- WebKit analysis
- Kernel internals
- Fuzzing
- Cryptography
- Secure communications
- Automated binary analysis
- Custom reverse-engineering tool development
Published research, technical presentations, CVEs, security advisories, open-source projects, or other demonstrated reverse-engineering work is highly valued.
Senior-Level Responsibilities
As a senior member of the research team, the individual will also be expected to:
- Independently own complex reverse-engineering assignments.
- Determine the most effective technical approach to an investigation.
- Provide realistic assessments of technical feasibility and difficulty.
- Assist other researchers when they encounter difficult reverse-engineering problems.
- Review and validate technical findings.
- Mentor junior reverse engineers.
- Develop internal tools and methodologies.
- Improve research workflows and technical documentation.
- Share technical knowledge with the broader engineering and research organization.
- Stay current with changes to iOS, Apple hardware, ARM architecture, and relevant security mechanisms.
Ideal Candidate
The ideal candidate is a reverse engineer who also thinks about security.
They should be capable of receiving an unfamiliar iOS application, binary, framework, or system component and systematically determining:
What does it do?
How does it work internally?
How does it communicate?
What other components does it depend upon?
What security controls affect its operation?
What protections or restrictions must be considered when analyzing it?
The candidate should have the curiosity and persistence required to work through complex binaries and undocumented behavior while maintaining a strong understanding of the security architecture surrounding the software.
Security & Confidentiality
This position may involve sensitive proprietary technology and confidential research.
Candidates must demonstrate excellent discretion and professional judgment.
All reverse engineering, analysis, testing, and related research must be conducted within authorized environments and approved scopes and in accordance with applicable legal, security, privacy, intellectual-property, and confidentiality requirements.
What Success Looks Like
A successful Senior iOS Reverse Engineer will be able to independently take a complex iOS target, determine how it functions through advanced reverse engineering, understand the relevant security mechanisms affecting it, develop tools where necessary to accelerate analysis, and produce clear and technically accurate findings.
We are seeking someone who can become a senior technical authority in iOS reverse engineering, while bringing the security knowledge necessary to understand the modern iOS environment in which that software operates.
Pay: $92,950.38 - $111,940.23 per year
Benefits:
Work Location: In person