Application Security Engineer I — Remote, Hands-On & Impactful

Trail of Bits

United States

Remote

USD 100,000 - 160,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) match
Paid vacation
Parental leave
Relocation assistance to NYC
Working-from-Home stipend
Learning & Development stipend
All-team celebrations

Job summary

Trail of Bits is seeking a Security Engineer I to contribute to client software security assessments, collaborate with senior engineers, and own scoped portions of engagements. You will conduct vulnerability analysis, build tooling, and help clients understand and fix issues found.

The role blends vulnerability research with applied security, requiring hands-on code work, threat modeling, and delivering findings through client delivery.

Qualifications

  • At least 1 year of combined relevant experience in application security or related areas.
  • Demonstrable vulnerability-discovery capability and ability to discuss a found or validated vulnerability.
  • Strong code-analysis skills and ability to read unfamiliar code.
  • Hands-on coding proficiency in at least two languages (Rust, Go, C, C++, Python, JS/TS).
  • Working knowledge of memory-corruption vulnerabilities and mitigations.
  • Familiarity with OS concepts and how apps interact with system internals.
  • Ability to investigate well-scoped problems independently and deliver with guidance.
  • Clear written and verbal communication to engineers and on a distributed team.

Responsibilities

  • Lead the review of a specific component, module, or system within a client engagement.
  • Find and validate vulnerabilities in code and systems; explain exploitation paths and impact.
  • Design and build security-testing tools for vulnerability detection and analysis.
  • Review software architectures; identify attack surfaces and data flows; suggest mitigations.
  • Translate findings into actionable recommendations for engineering teams.

Skills

Security analysis
Code reading
Rust/Go/C/C++
Vulnerability discovery
Python/JavaScript
Communication

Tools

Ghidra
DynamoRIO

Job description

Trail of Bits is seeking a Security Engineer I to contribute to client software security assessments, collaborate with senior engineers, and own scoped portions of engagements. You will conduct vulnerability analysis, build tooling, and help clients understand and fix issues found.

The role blends vulnerability research with applied security, requiring hands-on code work, threat modeling, and delivering findings through client delivery.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote: Hands-On Application Security Engineer I
Remote: Hands-On Application Security Engineer I

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3
Remote Security Engineer II - App Security & Tooling
Remote Security Engineer II - App Security & Tooling

Trail of Bits • United States

Remote
USD 140,000 - 180,000
Health insurance
Fully company-paid insurance packages
401(k) with 5% match
+7
Senior AppSec Engineer - Remote
Senior AppSec Engineer - Remote

Bright Vision Technologies • Monroeville

Remote
USD 100,000 - 160,000
Security Engineer (Application Security)
Security Engineer (Application Security)

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3
Remote Application Security Engineer
Remote Application Security Engineer

Bright Vision Technologies • Eden Prairie (MN)

Remote
USD 100,000 - 150,000
Senior AppSec Engineer - Remote & Flexible Growth
Senior AppSec Engineer - Remote & Flexible Growth

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Application Security Engineer - Remote
Senior Application Security Engineer - Remote

Bright Vision Technologies • Edison (NJ)

Remote
USD 100,000 - 160,000
Product Security Engineer - Remote, Impactful Security Design
Product Security Engineer - Remote, Impactful Security Design

YipitData • New York (NY)

On-site
USD 153,000 - 207,000
Flexible work hours
Flexible vacation
401K match
+3
Remote Security Engineer - Cloud & App Security Lead
Remote Security Engineer - Cloud & App Security Lead

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Senior Application Security Engineer — Remote/Flexible
Senior Application Security Engineer — Remote/Flexible

AgileEngine • Boca Raton (FL)

Hybrid
USD 120,000 - 180,000
Professional growth
Competitive compensation
A selection of exciting projects
+1