Trail of Bits

Trail of Bits

Trail of Bits is a leading company specializing in computer and network security. Since 2012, they have been helping secure the world's most targeted organizations and products by combining high-end security research with a real-world attacker mentalit...

Internet Software & Services
51-250
Founded 2012

Description

  • Lead security assessments for specific components, modules, or systems within larger client engagements.
  • Find and validate vulnerabilities in application code and systems, including tracing root causes and assessing impact.
  • Develop proof-of-concept code when needed to demonstrate exploitation paths.
  • Design and build custom security testing tools and automation for vulnerability detection.
  • Conduct threat modeling and architecture reviews of software systems.
  • Identify attack surfaces, data flows, and security boundaries, and propose concrete mitigations.
  • Translate technical findings into clear, actionable recommendations for client engineering teams.
  • Own client communication for the component of work you are responsible for.
  • Contribute to security research initiatives and document findings.
  • Collaborate with senior engineers while owning pieces of client engagements end to end.

Requirements

  • 0–2 years into a security career, or background in software engineering with a strong security foundation.
  • Demonstrable vulnerability research capability through CTF wins, published CVEs, bug bounty finds, or security research.
  • Ability to read complex code, trace execution, identify logic flaws, and determine whether an issue is truly exploitable.
  • Fluency in at least two of Rust, Go, C, C++, Python, JavaScript, TypeScript, or similar languages.
  • Understanding of memory corruption vulnerabilities such as buffer overflows and use-after-free, and mitigations such as stack cookies, ASLR, NX/DEP, CFI, and MTE.
  • Deep familiarity with operating systems, IPC, privilege boundaries, and system internals.
  • Ability to work autonomously, drive your own analysis, and own pieces of engagements from start to finish.
  • Clear technical communication skills and the ability to explain and defend security findings to engineers.
  • Preferred: active CTF participation, recent rankings, or team involvement.
  • Preferred: published vulnerability research, open source security contributions, mobile security experience, technical writing, cloud security experience with AWS, GCP, or Azure, and experience with Kubernetes, Helm, Terraform, or Ansible.
  • Preferred: kernel or other low-level development experience.

Benefits

  • Base salary range of $100,000 to $160,000, excluding benefits and potential bonuses.
  • Performance-based bonuses.
  • Fully company-paid health, dental, vision, disability, and life insurance.
  • 401(k) with a 5% company match.
  • 20 days of paid vacation with flexibility for more, subject to jurisdictional regulations.
  • 4 months of parental leave.
  • $1,000 work-from-home stipend.
  • $750 annual learning and development stipend.
  • $10,000 relocation assistance for candidates moving to New York City.
  • Philanthropic contribution matching up to $2,000 annually.
  • Company-sponsored all-team celebrations with travel and accommodation covered.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevSecOps

Cato Networks 251-1K Diversified Telecommunication Services

Cato Networks is hiring an Application Security Engineer (DevSecOps) to embed security across its cloud-based software development lifecycle and help R&D teams deliver secure applications at scale.

Agile AWS CI/CD DevSecOps Docker Go Java Kubernetes Microservices Network Security Python Terraform
2 days, 19 hours ago

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
5 days, 20 hours ago

Lead Application Security Engineer

Zeta Global 1K-5K Media

Zeta Global is hiring a Lead Application Security Engineer to strengthen application and platform security across its AI-powered marketing platforms through automated, AI-native security practices and cross-functional security engineering.

AWS Azure Burp Suite CI/CD Cybersecurity DevSecOps Django Docker FastAPI GCP JWT Kubernetes Microservices Node.js OAuth OpenID Connect React SonarQube
6 days, 19 hours ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architecture IC to define and drive secure-by-design architecture across its enterprise planning platform and AI products.

Encryption Machine Learning OWASP
1 week, 2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers