Trail of Bits logo
Trail of BitsΒ·

Security Engineer II, Application Security - Trail of Bits

About Trail of Bits

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies.

The Role

Trail of Bits seeks a Security Engineer II for our Application Security practice. You will conduct security assessments of client software, independently own substantial components or workstreams, identify and validate vulnerabilities across the application and system levels, and develop custom tooling alongside the team. You will own your analysis from discovery through client delivery and help clients understand and fix the issues you find.

This role bridges vulnerability research and applied security. Your work will be hands-on and autonomous: analyzing complex code, building custom tooling, conducting threat modeling and architecture reviews, and delivering findings that can withstand technical scrutiny.

What You'll Achieve

  • Security Assessment Ownership: Independently lead assessments of substantial components, modules, or systems within client engagements and own the work from scoping through delivery.
  • Vulnerability Discovery and Analysis: Find and validate vulnerabilities, establish root causes and exploitation paths, assess impact, and develop proof-of-concept code when appropriate.
  • Custom Security Tooling: Design and build targeted tools, harnesses, tests, or automation that expand assessment coverage and improve repeatability.
  • Architecture and Threat Modeling: Review complex software architectures, identify attack surfaces, data flows, trust and privilege boundaries, and recommend practical mitigations.
  • Client Communication: Produce clear, actionable findings, defend the evidence behind them, and lead technical discussions with client engineering teams.
  • Team Contribution: Review other engineers' code and analysis, share techniques, and help improve the team's technical approach.
  • Research and Innovation: Contribute new methods, open-source tools, and technical writing to Trail of Bits and the broader security community.

What You'll Bring

  • Experience: Typically 2+ years of directly relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area.
  • Vulnerability Discovery: Repeated vulnerability-discovery experience with the ability to talk through vulnerabilities you personally found or validated.
  • Code-Analysis Skills: Strong analysis skills across unfamiliar and complex codebases, tracing execution, and data flow.
  • Programming & Debugging: Strong programming ability in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.
  • Systems Knowledge: Working knowledge of memory-corruption vulnerabilities, mitigations, operating systems, IPC, and privilege boundaries.
  • Communication: Clear written and verbal communication, including presenting technical conclusions to clients.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Trail of Bits

Similar remote roles