Who We Are
Founded in 2012 by three expert hackers with no investment capital, Trail of Bits is a place for security experts to advance security and address technology’s newest and most challenging risks. The company has helped secure some of the world’s most targeted organizations and devices. Its combination of novel research and practical solutions reduces the security risks clients face from emerging technologies. This work helps drive the security industry and public understanding of the technology underlying the world.
Cybersecurity preparedness is a moving target. Trail of Bits uses a research-based and custom-engineering approach to help ensure that clients’ capabilities remain at the forefront of what is available. Companies and technologies that depend on security require a proactive and tailored approach to remain ahead of attackers.
Democratizing security information is essential. Trail of Bits provides ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. Greater community understanding of security also helps people understand the value and distinctiveness of the company’s work.
Role
Trail of Bits seeks a Security Engineer, Application Security for its growing Software Assurance practice. You will conduct comprehensive security assessments of client software, focusing on low-level code analysis, system architecture, security boundaries, access controls, and platform security mechanisms.
On a typical day, you may analyze vulnerabilities in application code, automate detection of security misconfigurations in cloud environments, assess privilege-escalation capabilities, or review security boundaries in complex systems. You will work with other security engineers on client projects while building impactful tools. The work sits at the intersection of vulnerability research and application security.
You may also collaborate with the Research and Engineering team to pursue government funding for advanced security research that connects vulnerability research with application security and advances the state of the art within the company and the wider industry.
What You’ll Achieve
- Security Assessment: Conduct comprehensive low-level code security assessments across applications. Examine vulnerabilities involving system services, access-control implementation, inter-process communication, and platform security controls, and develop mitigation strategies.
- Security Tool Development: Design and implement custom security tools for automated vulnerability detection, covering application-specific and general security-testing needs.
- Architecture Review: Perform architecture reviews and threat modeling for complex software systems and cloud environments. Identify weaknesses in data flows, authentication mechanisms, APIs, and related security boundaries, and provide remediation guidance.
- Client Engagement: Work directly with technology teams to review application infrastructure and architecture and improve security through technical analysis and recommendations.
- Research and Innovation: Develop new application-security methodologies and tools and remain current with security developments in traditional and emerging technology ecosystems.
What You’ll Bring
- Application security assessment experience: Direct experience conducting low-level code security assessments of complex software and identifying application and system-level vulnerabilities.
- Manual code review depth: Experience finding vulnerabilities that automated tools miss and explaining why a finding is exploitable.
- Static and dynamic analysis fluency: Experience using static and dynamic analysis tools as part of deeper reviews, including understanding their limitations and how to extend them.
- Binary analysis and reverse engineering: Experience analyzing compiled software with disassemblers, decompilers, and related tools.
- Memory corruption vulnerabilities and mitigations: Experience identifying memory-corruption issues and reasoning about modern mitigations and exploit primitives.
- System internals and security boundaries: Experience with system internals, inter-process communication, access-control implementations, and platform security boundaries.
- Architecture review and threat modeling: Experience identifying weaknesses in data flows, authentication, APIs, software systems, and cloud environments and proposing realistic remediation.
- Security tool development: Experience designing and building custom tools for automated vulnerability detection.
- Programming proficiency: Hands-on experience in at least two relevant languages, such as Rust, Go, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, or C++.
- Technical communication: Experience translating complex findings into clear and actionable recommendations for engineering and security teams.
Nice to Have
- Experience with Android, iOS, or macOS system internals.
- Contributions to open-source security tools, libraries, or research.
- Published vulnerability research, CVEs, or technical articles.
- Experience presenting at security conferences such as DEF CON, Black Hat, BSides, OffensiveCon, or RECon.
- Experience identifying security misconfigurations in AWS, Google Cloud, or Azure environments.
- Experience collaborating on government-funded security research involving organizations such as DARPA, IARPA, or ONR.
Compensation
- Salary: $100K – $200K
- The range excludes benefits and potential bonuses.
- The final offer depends on seniority, geographic location, employment arrangement, skills, experience, and relevant educational background.
- The range covers starting salaries across United States locations.
Application Information
- Trail of Bits, Inc. participates in E-Verify, the United States federal electronic employment eligibility verification program.
- Only applications completed through the Trail of Bits Careers page will be considered.
- Applicants are added to the company newsletter and may opt out at any time.
Benefits
Benefits, Perks and Wellness
Trail of Bits has more than 100 employees working across global time zones. Its remote-first culture is built on autonomy and trust, with the following benefits available to full-time employees.
Empowered Living
- Competitive salary complemented by performance-based bonuses.
- Company-paid health, dental, vision, disability, and life insurance packages.
- A 401(k) plan with a company match equal to 5% of base salary.
- Twenty days of paid vacation, with flexibility for additional time in accordance with applicable jurisdictional regulations.
Nurturing New Beginnings
- Four months of parental leave following the arrival of a new family member.
- A $10,000 relocation benefit for team members interested in moving to New York City.
Work and Life Enrichment
- A $1,000 work-from-home stipend.
- An annual $750 learning and development stipend.
- Company-sponsored team celebrations, including travel and accommodation.
Community Impact
- Matching of philanthropic contributions up to $2,000 annually.