Who We Are
Founded in 2012 by three expert hackers with no investment capital, Trail of Bits is a place for security experts to advance security and address technology’s newest and most challenging risks. The company has helped secure some of the world’s most targeted organizations and devices. Its combination of novel research and practical solutions reduces the security risks clients face from emerging technologies. This work helps drive the security industry and public understanding of the technology underlying the world.
Cybersecurity preparedness is a moving target. Trail of Bits uses a research-based and custom-engineering approach to help ensure that clients’ capabilities remain at the forefront of what is available. Companies and technologies that depend on security require a proactive and tailored approach to remain ahead of attackers.
Democratizing security information is essential. Trail of Bits provides ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. Greater community understanding of security also helps people understand the value and distinctiveness of the company’s work.
Role
Trail of Bits seeks a Security Engineer 1 for its growing Software Assurance practice. You will contribute to security assessments of client software, partner with senior engineers, and identify vulnerabilities at the application and system levels. You will own defined parts of client engagements, conduct your own vulnerability analysis, and develop tools alongside the team.
This role connects vulnerability research with applied security. You will find real issues in real code and help clients understand and remediate them. The work is hands-on and autonomous, involving complex code analysis, custom tooling, threat modeling, and ownership of findings through client delivery.
What You’ll Achieve
- Security Assessment Ownership: Lead security assessments for specific components, modules, or systems within larger client engagements. Identify vulnerabilities, trace root causes, and own the analysis from discovery through delivery.
- Vulnerability Discovery and Analysis: Find and validate vulnerabilities in application code and systems. Explain exploitation paths, assess impact, and develop proof-of-concept code when needed.
- Custom Security Tooling: Design and build security-testing tools and vulnerability-detection automation. Own tool development from concept through deployment on client projects.
- Architecture and Threat Modeling: Conduct architecture reviews and threat modeling of software systems. Identify attack surfaces, data flows, and security boundaries, and propose concrete mitigations.
- Client Communication: Translate technical findings into clear and actionable recommendations for engineering teams. Own client relationships for your portion of the work.
- Research and Innovation: Contribute to security research, build tools, document findings, and remain current with vulnerability research and application security.
What You’ll Bring
- Demonstrable vulnerability research capability: Evidence may include CTF achievements, published CVEs, bug bounty findings, or security research demonstrating the ability to discover exploitable issues.
- Strong code analysis skills: You can read complex code, trace execution, identify logic flaws, and explain exploitability. You understand the difference between an automated warning and a validated vulnerability.
- Hands-on coding proficiency: Fluency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript. You use code for security analysis and tool development.
- Memory safety understanding: Knowledge of memory corruption vulnerabilities, including buffer overflows and use-after-free conditions, and mitigations such as stack cookies, ASLR, NX/DEP, CFI, and MTE.
- Systems knowledge: Familiarity with operating systems, inter-process communication, privilege boundaries, and application interaction with system internals.
- Autonomous problem-solving: You can own work, ask appropriate questions, debug issues, and reach conclusions independently.
- Clear technical communication: You can explain complex findings to engineers and defend your analysis through clear and actionable reporting.
Nice to Have
- Current or recent CTF participation, wins, or rankings.
- Published vulnerability research, CVEs, bug bounty findings, responsible disclosures, or technical security articles.
- Contributions to open-source security tools, libraries, or research.
- Android or iOS application security, system internals, or mobile binary-analysis experience.
- Published technical writing, conference presentations, or technical documentation.
- AWS, Google Cloud, or Azure security assessment and architecture-review experience.
- Experience with Kubernetes, Helm, Terraform, Ansible, or similar infrastructure tools.
- Kernel, driver, or other low-level development experience.
About You
You may be zero to two years into a security career or transitioning from software engineering with a strong security foundation. You have demonstrated an ability to find vulnerabilities, understand how systems fail, work autonomously, and own your analysis.
Relevant candidates may include CTF participants, people with CVE disclosures, bug bounty researchers, or engineering graduates who have built security tools. You should be capable of owning part of a security engagement and driving it to completion.
Demonstrated ability matters more than a specific number of years of experience. The central questions are whether you can find vulnerabilities, understand complex code and systems, and take ownership of your work.
Compensation
- Salary: $100K – $160K
- The range excludes benefits and potential bonuses.
- The final offer depends on seniority, geographic location, employment arrangement, skills, experience, and relevant educational background.
- The range covers starting salaries across United States locations.
Application Information
- Trail of Bits, Inc. participates in E-Verify, the United States federal electronic employment eligibility verification program.
- Only applications completed through the Trail of Bits Careers page will be considered.
- Applicants are added to the company newsletter and may opt out at any time.
Benefits
Benefits, Perks and Wellness
Trail of Bits has more than 100 employees working across global time zones. Its remote-first culture is built on autonomy and trust, with the following benefits available to full-time employees.
Empowered Living
- Competitive salary complemented by performance-based bonuses.
- Company-paid health, dental, vision, disability, and life insurance packages.
- A 401(k) plan with a company match equal to 5% of base salary.
- Twenty days of paid vacation, with flexibility for additional time in accordance with applicable jurisdictional regulations.
Nurturing New Beginnings
- Four months of parental leave following the arrival of a new family member.
- A $10,000 relocation benefit for team members interested in moving to New York City.
Work and Life Enrichment
- A $1,000 work-from-home stipend.
- An annual $750 learning and development stipend.
- Company-sponsored team celebrations, including travel and accommodation.
Community Impact
- Matching of philanthropic contributions up to $2,000 annually.