Trail of Bits

Trail of Bits

Trail of Bits is a leading company specializing in computer and network security. Since 2012, they have been helping secure the world's most targeted organizations and products by combining high-end security research with a real-world attacker mentalit...

Internet Software & Services
51-250
Founded 2012

Description

  • Conduct comprehensive low-level code security assessments of client software, including system services, access control implementations, IPC, and platform security controls.
  • Identify vulnerabilities in application code and system-level components, and develop practical mitigation strategies.
  • Perform manual code reviews to uncover issues that automated tools miss and explain exploitability and impact.
  • Use static and dynamic analysis as part of deeper security reviews and extend these tools where needed.
  • Perform binary analysis and reverse engineering of compiled software.
  • Review architecture and threat model complex software systems and cloud environments, including data flows, authentication, API security, and cloud configurations.
  • Design and implement custom security tools for automated vulnerability detection and security testing.
  • Work directly with client engineering and security teams to provide findings, recommendations, and remediation guidance.
  • Collaborate with Trail of Bits research and engineering teams on advanced security research and tool development.

Requirements

  • Direct experience conducting low-level application security assessments of complex software.
  • Hands-on manual code review experience finding vulnerabilities that automated tools miss.
  • Experience using static and dynamic analysis tools, including understanding their limitations.
  • Experience performing binary analysis and reverse engineering using disassemblers and decompilers.
  • Demonstrated experience identifying memory corruption vulnerabilities and reasoning about modern mitigations.
  • Deep experience with system internals, IPC, access control implementations, and platform security boundaries.
  • Experience performing architecture reviews and threat modeling for software systems and cloud environments.
  • Experience designing and building custom security tools for automated vulnerability detection.
  • Hands-on programming experience in two or more of Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, or C++.
  • Experience communicating complex security findings and actionable recommendations to technical stakeholders.
  • Experience with Android, iOS, or macOS system internals (preferred).
  • Experience contributing to open source security tools, libraries, or research (preferred).
  • Experience publishing original vulnerability research, CVEs, or technical writeups (preferred).
  • Experience speaking at security conferences such as DEF CON, Black Hat, BSides, OffensiveCon, or RECon (preferred).
  • Experience identifying security misconfigurations in cloud environments such as AWS, GCP, or Azure (preferred).
  • Experience collaborating on government-funded security research such as DARPA, IARPA, or ONR projects (preferred).

Benefits

  • Competitive salary of $100,000 to $200,000, plus potential bonuses.
  • Performance-based bonuses.
  • Fully company-paid health, dental, vision, disability, and life insurance.
  • 401(k) plan with a 5% company match.
  • 20 days of paid vacation, with flexibility for more where jurisdiction allows.
  • 4 months of parental leave.
  • $10,000 relocation assistance for employees moving to New York City.
  • $1,000 work-from-home stipend and a $750 annual learning and development stipend.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Identity Engineer

Hasbro 5K-10K Consumer Goods

Wizards of the Coast is hiring a Principal Identity Engineer to own the technical direction of its enterprise identity architecture, supporting Zero Trust, privileged access, and identity governance across cloud and on-premises environments.

Active Directory CI/CD Git OpenID Connect PowerShell Pulumi Python REST API SAML Terraform
1 day, 20 hours ago

Senior Device Engineer

Dragos 251-1K Professional Services

Dragos is hiring a Senior Device Engineer to build automation software that identifies, fingerprints, and interacts with network-connected devices across critical infrastructure environments.

Cybersecurity Docker Embedded Systems Go HTTP JavaScript Node.js TCP/IP TLS TypeScript
1 day, 20 hours ago

Elastic Engineer

Jolera 251-1K Internet Software & Services

Jolera is seeking an Elastic Engineer to design and operate scalable Elasticsearch-based environments for cybersecurity analytics, threat hunting, and detection workflows.

Cybersecurity Elasticsearch Encryption Java Kibana Linux Logstash Machine Learning Python Ruby
1 day, 20 hours ago

Staff Software Development Engineer - Windows Endpoint

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a Staff Software Development Engineer to own Windows kernel-mode enforcement for its Identity Security Platform, building real-time security controls that decide whether actions on Windows endpoints are permitted or denied.

Agile C C++ Rust
1 day, 20 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers