Trail of Bits logo

Senior Security Engineer, Research & Engineering - Trail of Bits

Who We Are

Founded in 2012 by three expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. We help secure some of the world's most targeted organizations and devices through a combination of novel research and practical solutions.

Role

AI has transformed the cost curve for formal verification. We are looking for candidates who have both the rigor to read a proof and say exactly what it establishes, and the instinct to find what it left out.

Day-to-day, you will evaluate specifications alongside their designs and proofs, determine what has actually been established versus what has merely been assumed, and use state-of-the-art tools and frontier AI models to go after everything the proof does not reach. Occasionally, you will attend sprints and hackathon events in London.

What You'll Achieve

  • Break systems built to resist you: Compromise designs and production software whose authors had a proof assistant on their side, and demonstrate it with a working exploit.
  • Map the real attack surface of a proof: Establish the formal property, threat model, and underlying assumptions, showing clients where they give way under pressure.
  • Build tooling: Design and extend AI-driven discovery and triage systems.
  • Write assessments: Set out what held, what did not, and what you attempted without success.
  • Raise the practice: Publish tooling, methodology, and blog posts, and present internally.

What You'll Bring

  • Red teaming: Direct experience with red teaming production software and finding/proving exploitable vulnerabilities.
  • AI tool building: Experience building AI-driven tooling for vulnerability discovery (agentic harnesses, LLM-assisted triage pipelines, automated exploit generation).
  • Formal methods: Experience applying formal methods, including reading specifications, proof artifacts, and reasoning about machine-checked proofs (Lean, Rocq, F*, Dafny, or Verus/Rust).
  • Systems depth: Experience finding vulnerabilities in network protocols, OS internals, open-source software, cryptography, or AI inference infrastructure.
  • Software development: Experience in Python, C++, and/or Rust.
  • Written findings: Experience producing scrutinized security assessment reports.
  • Delivery: Track record of delivering to fixed external schedules with defined acceptance criteria.
  • Vulnerability disclosure: Experience in ethical vulnerability reporting.

Benefits, Perks & Wellness

  • Competitive compensation with performance-based bonuses.
  • $1,000 Working-from-Home stipend.
  • Annual $750 Learning & Development stipend.
  • Company-sponsored all-team celebrations, including travel and accommodation.
  • Philanthropic contribution matching up to $2,000 annually.

Timezone overlap

UTC+0–+3

Open to

UK

Sign in to track applications and earn points.

More roles at Trail of Bits

Similar remote roles