Trail of Bits

Trail of Bits

Trail of Bits is a leading company specializing in computer and network security. Since 2012, they have been helping secure the world's most targeted organizations and products by combining high-end security research with a real-world attacker mentalit...

Internet Software & Services
51-250
Founded 2012

Description

  • Conduct comprehensive security assessments of large language model and agentic AI systems across the AI supply chain and application stack.
  • Examine vulnerabilities in LLM web applications, agentic coding tools, training data and inference pipelines, and guardrail mechanisms.
  • Develop, operationalize, and share prompt injection techniques for end-to-end application security reviews.
  • Identify and analyze novel attack vectors, vulnerabilities, and unauthorized access paths in AI and agentic environments.
  • Perform security assessments of client code bases using static analysis, dynamic testing, and manual code review.
  • Develop mitigation strategies for findings at the intersection of application security and agentic AI security.
  • Conduct threat modeling and risk assessments to identify future risks and prompt injection attack surfaces.
  • Work with client teams to review system code and architecture and help assure products through system analysis and modeling.
  • Deliver specialized training to clients on Agentic AI security concepts, including prompt injection, ML-specific attacks, and data pipeline threats.
  • Contribute to AI policy, regulatory frameworks, assurance methods, and auditing processes for mission-critical AI applications.

Requirements

  • Demonstrated interest and experience in agentic AI security.
  • Hands-on experience with prompt injection attacks and defenses.
  • Deep understanding of AI/ML architectures and frameworks such as PyTorch, Jax, LangChain, and RAG systems.
  • Experience with MLOps practices.
  • Track record of conducting technical security assessments of software.
  • Experience with software and system hardening and security policy analysis.
  • Practical experience designing and executing prompt injection workflows against production LLM systems, agentic pipelines, and tool-use environments.
  • Strong knowledge of multiple programming languages such as Rust, Golang, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, Ruby, C, and/or C++.
  • Creative, adversarial hacker mindset with a passion for discovering novel attack vectors.
  • Ability to communicate complex security concepts clearly to diverse stakeholders and provide actionable recommendations.

Benefits

  • Competitive salary ranging from $100,000 to $200,000, plus potential bonuses.
  • Performance-based bonuses.
  • Fully company-paid health, dental, vision, disability, and life insurance.
  • 401(k) plan with a 5% company match.
  • 20 days of paid vacation, with flexibility for more where jurisdiction allows.
  • 4 months of parental leave.
  • $1,000 work-from-home stipend and $750 annual learning and development stipend.
  • $10,000 relocation assistance for candidates moving to NYC, plus company-sponsored team celebrations and travel, and up to $2,000 in annual charitable donation matching.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Mid-Senior IT Professional (Multiple Opportunities)

Hire Resolve US Internet Software & Services

Hire Resolve is assisting Australian IT organisations in hiring mid- to senior-level IT professionals for multi-disciplinary roles supporting infrastructure, cloud, cybersecurity, enterprise systems, and service delivery.

Active Directory AWS Azure Bash Cybersecurity DHCP DNS GCP PowerShell Python SIEM Terraform
1 hour, 6 minutes ago

Kernel Developer (fully remote, LATAM)

CloudLinux 51-250 IT Services

CloudLinux’s KernelCare team is hiring an experienced Kernel Developer to maintain and enhance Linux kernel live-patching services that deliver security fixes and features for customers worldwide.

Agile Bash C Cybersecurity Git Jenkins Linux Python Shell Scripting
2 hours, 3 minutes ago

Senior Security Engineer

AutoFi 51-250 Automotive

AutoFi is hiring a Senior Security Engineer to secure its automotive digital commerce platform, cloud environments, internal systems, and vendor ecosystem across proactive and operational security work.

AWS DevSecOps JavaScript Node.js OAuth OWASP Penetration Testing REST API SIEM SQL WAF
2 hours, 35 minutes ago

Security Engineer

Voltus 251-1K Electric Utilities

Voltus is hiring a remote Security Engineer to strengthen the security foundation of its clean-energy software platform and support both infrastructure protection and compliance work.

AWS CI/CD Datadog Docker Go HIPAA Prometheus Python Terraform
2 hours, 56 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers