Trail of Bits Logo

Trail of Bits

Security Engineer, Research & Engineering

Posted 4 Hours Ago
Remote
Hiring Remotely in United States
125K-185K Annually
Mid level
Remote
Hiring Remotely in United States
125K-185K Annually
Mid level
The Security Engineer will design, build, and enhance security tools and frameworks, analyze security challenges, and contribute to AI/ML security research. Responsibilities include software development, security code review, and technical communication.
The summary above was generated by AI
Who We Are

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.

Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.

Role

This role is for a security-focused software engineer who will design, build, and enhance security tools and frameworks across various contexts. You'll work on projects ranging from AI/ML security frameworks to compiler-based security tools, and everything in between, contributing to software that makes a real difference in the security landscape. Trail of Bits is AI-native, so you will have all the latest technologies at your disposal to help you establish an efficient workflow at your discretion. 

As a Security Engineer, you are an individual contributor who receives tasking from project leads and delivers on technical milestones. Over time, you'll grow into leading major feature development, breaking down high-level objectives into manageable tasks, and presenting your work to clients. You'll be expected to pursue subject-matter expertise in areas that are part of Trail of Bits' core competencies and share what you learn through blogs, Lunch 'n' Learns, and publications.

Software development will primarily involve Rust, C++, and Python, with occasional work in Go and Java. You will typically work in teams of 2–4 people, all from remote locations. Technical leads guide the team's work, collaborating with you and other members to define responsibilities based on project needs, individual strengths, and team input. Frequent communication with team members and clients is essential to success, and writing about your work publicly is encouraged and incentivized.

We welcome applications from experienced professionals and talented recent graduates with relevant skills and interests.

What You'll Achieve
  • Security Tool Development: Design and implement security-focused software tools and frameworks, contributing to projects that help achieve their technical milestones.
  • Open Source Contribution: Contribute to open-source security projects and develop internal tools that advance Trail of Bits' core competencies.
  • Security Solution Architecture: Analyze complex security challenges and develop practical, deployable solutions. As you grow, take ownership of deconstructing high-level objectives into smaller, more manageable tasks.
  • Full-Stack Security Understanding: Understand security implications across the stack, from low-level systems to application frameworks.
  • Secure Implementation: Implement secure CI/CD pipelines and integration with GitHub Actions.
  • AI/ML Security Research: Contribute to AI/ML security research and tooling.
  • Security Code Review: Evaluate and improve the security of existing software through code review and enhancement.
  • Technical Communication: Communicate technical concepts effectively to team members, clients, and the broader security community. Write blog posts, participate in Lunch 'n' Learns and publications, and grow toward delivering client-side presentations.
  • Technical Troubleshooting: Root-cause analysis and debugging on low-level technical issues.
  • Project Execution: Interpret requirements, decompose tasks, and make engineering estimates. Work toward leading major feature development and moving projects toward their milestones.
What You'll Bring
  • Strong software development skills with experience in: Rust, C++, and/or Python. Occasionally, Go or Java knowledge is necessary.
  • Knowledge of AI/ML systems and associated security challenges.
  • Familiarity with AI development tools like Claude Code, Cursor, and others.
  • Experience with secure development practices and building secure software.
  • Demonstrated ability to quickly learn new programming languages, frameworks, and technologies.
  • Understanding of computer security principles and common vulnerability classes.
  • A drive to develop subject-matter expertise in an area of Trail of Bits' core competency.
  • Ability to work independently and as part of a remote team.
  • Strong written and verbal communication skills, with a willingness to write blog posts and present at internal knowledge-sharing sessions.
  • Familiarity with GitHub, CI/CD pipelines, and automated testing.
Preferred Qualifications
  • Prior contributions to open-source security tools or frameworks.
  • Experience developing commercial-grade software used by the public.
  • Understanding of low-level systems, including memory management and operating system internals.
  • Experience with compiler technology, program analysis, or binary analysis.
  • Participation in CTF competitions or other security challenges.
  • Experience with multiple programming languages and paradigms.
  • Experience in reading, writing, and publishing academic papers.
  • Experience in public speaking.

(Preferred qualifications are nice to have, but not required. Please apply even if you don’t meet all of these!)

The US base salary for this full-time position ranges from $125,000 to $185,000, excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range.

Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more.

When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime.


BenefitsBenefits, Perks & Wellness

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:

Empowered Living:

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.

Nurturing New Beginnings:

  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.

Work & Life Enrichment:

  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.

Community Impact:

  • Philanthropic contribution matching up to $2,000 annually.

Top Skills

C++
Ci/Cd
Github Actions
Go
Java
Python
Rust

Similar Jobs at Trail of Bits

4 Hours Ago
Remote
United States
200K-250K Annually
Expert/Leader
200K-250K Annually
Expert/Leader
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
The Principal Security Engineer leads projects, drives technical vision, mentors engineers, engages in business development, and oversees security software development.
Top Skills: C++GoJavaPythonRust
4 Hours Ago
Remote
United States
200K-250K Annually
Expert/Leader
200K-250K Annually
Expert/Leader
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
The Principal Security Engineer leads projects, drives technical vision, mentors engineers, engages in business development, and oversees security software development.
Top Skills: C++GoJavaPythonRust
6 Days Ago
Remote
United States
100K-150K Annually
Mid level
100K-150K Annually
Mid level
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
The Employee Experience Manager enhances employee journeys through event management, cultural initiatives, and engagement strategies while supporting HR functions in a remote setting.
Top Skills: Google WorkspaceSlackTrello

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account