Who We Are
Founded in 2012 by three expert hackers with no investment capital, Trail of Bits is a place for security experts to advance security and address technology’s newest and most challenging risks. The company has helped secure some of the world’s most targeted organizations and devices. Its combination of novel research and practical solutions reduces the security risks clients face from emerging technologies. This work helps drive the security industry and public understanding of the technology underlying the world.
Cybersecurity preparedness is a moving target. Trail of Bits uses a research-based and custom-engineering approach to help ensure that clients’ capabilities remain at the forefront of what is available. Companies and technologies that depend on security require a proactive and tailored approach to remain ahead of attackers.
Democratizing security information is essential. Trail of Bits provides ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. Greater community understanding of security also helps people understand the value and distinctiveness of the company’s work.
Role
You will lead Trail of Bits’ Application Security practice, a team of 12 security engineers who conduct code audits, vulnerability research, and secure-design reviews for technically demanding clients.
This is a hands-on leadership role. You will personally review audit findings, guide technical approaches, and maintain the credibility needed to work with sophisticated clients. You will own the practice’s financial performance, project staffing, and team development.
The team works directly with source code through static analysis, manual code review, fuzzing, and protocol-level vulnerability research across Rust, Go, C, C++, Python, Solidity, and JavaScript. The director must be able to perform this technical work as well as manage the people responsible for it.
What You’ll Achieve
- Lead technical delivery: Own the quality and profitability of client engagements. Review findings, guide technical direction on complex audits, provide senior expertise when needed, and maintain direct relationships with key clients.
- Staff and grow the practice: Make project-assignment decisions that balance engineer development, client needs, and profitability. Manage utilization, identify hiring needs, develop the recruiting pipeline, and own the practice’s profit and loss performance.
- Develop your engineers: Create opportunities for team members to present at conferences, publish research, contribute to open-source tools, and advance their careers. Identify and remove obstacles to their success.
- Set technical direction: Decide where the practice invests in tooling, methodology, and capability development. Remain sufficiently hands-on to assess what is working and ensure that the team’s approach evolves with the threat landscape and client needs.
- Integrate AI into the practice: Model and promote the use of AI tools across team workflows. Help engineers adopt AI-assisted auditing, reporting, and research practices that increase effectiveness.
What You’ll Bring
- At least ten years of security experience, including significant time conducting source-code audits rather than only penetration testing.
- Recent and demonstrable hands-on security work involving code review, vulnerability research, or tool development within the previous 12 months.
- Experience leading a team of at least eight engineers through client engagements with direct financial accountability.
- Proficiency in at least four of the following: Rust, Go, Python, C, C++, Solidity, JavaScript, or TypeScript.
- A record of managing project profitability, utilization, and staffing decisions in a consulting environment.
- Experience supporting team members’ career development and external visibility through conference presentations, publications, and open-source contributions.
- Proficiency with AI coding and analysis tools in your own work.
- Active contributions to the security community through research, tools, advisories, or publications.
Reporting Manager
Dan Guido, Chief Executive Officer
Compensation
- Salary: $250K – $300K
- The range excludes benefits and potential bonuses.
- The final offer depends on seniority, geographic location, employment arrangement, skills, experience, and relevant educational background.
- The range covers starting salaries across United States locations.
Application Information
- Trail of Bits, Inc. participates in E-Verify, the United States federal electronic employment eligibility verification program.
Benefits
Benefits, Perks and Wellness
Trail of Bits has more than 100 employees working across global time zones. Its remote-first culture is built on autonomy and trust, with the following benefits available to full-time employees.
Empowered Living
- Competitive salary complemented by performance-based bonuses.
- Company-paid health, dental, vision, disability, and life insurance packages.
- A 401(k) plan with a company match equal to 5% of base salary.
- Twenty days of paid vacation, with flexibility for additional time in accordance with applicable jurisdictional regulations.
Nurturing New Beginnings
- Four months of parental leave following the arrival of a new family member.
- A $10,000 relocation benefit for team members interested in moving to New York City.
Work and Life Enrichment
- A $1,000 work-from-home stipend.
- An annual $750 learning and development stipend.
- Company-sponsored team celebrations, including travel and accommodation.
Community Impact
- Matching of philanthropic contributions up to $2,000 annually.