Security Engineer 1, Application Security - Remote US

Trail of Bits $100K - $160K/year Posted 3 days ago

100% remote US only · US (remote)

About the role

Trail of Bits, the security research and engineering firm founded in 2012 by three expert hackers, seeks a Security Engineer 1 for its growing Software Assurance practice. You will contribute to security assessments of client software, partnering with senior engineers and identifying vulnerabilities across the application and system level. This role bridges vulnerability research and applied security: you will find real issues in real code and help clients understand and fix them. Your work will be hands-on and autonomous, analyzing complex code, building custom tooling, conducting threat modeling, and owning your findings through to client delivery.

Responsibilities

  • Security assessment ownership: lead security assessments for specific components, modules, or systems within larger client engagements, tracing root causes and owning your analysis from discovery through client delivery.
  • Vulnerability discovery and analysis: find and validate real vulnerabilities in application code and systems, explain exploitation paths, assess impact, and develop proof-of-concept code when needed.
  • Custom security tooling: design and build security testing tools and automation for vulnerability detection, from concept through deployment on client projects.
  • Architecture and threat modeling: conduct threat modeling and architecture reviews, identify attack surfaces, data flows, and security boundaries, and propose concrete mitigations.
  • Client communication: translate technical findings into clear, actionable recommendations for engineering teams.
  • Research and innovation: contribute to security research initiatives and stay on the cutting edge of vulnerability research and application security.

Qualifications

  • Demonstrable vulnerability research capability: CTF wins, published CVEs, bug bounty finds, or security research showing you can discover exploitable issues.
  • Strong code analysis skills: you can read complex code, trace execution, identify logic flaws, and explain why something is exploitable.
  • Hands-on coding proficiency in at least two of Rust, Go, C, C++, Python, JavaScript, or TypeScript, writing code for security analysis and tool development.
  • Memory safety understanding: memory corruption vulnerabilities (buffer overflows, use-after-free) and mitigations (stack cookies, ASLR, NX/DEP, CFI, MTE), with the ability to reason about exploit primitives.
  • Systems knowledge: deep familiarity with operating systems, IPC, privilege boundaries, and how applications interact with system internals.
  • Autonomous problem-solving and clear technical communication, with reports that are clear and actionable.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on Trail of Bits's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

Trail of Bits team? Claim this listing or ask us to remove it.