Application Security Engineer — Remote & Tooling-Focused

Trail of Bits

United States

On-site

USD 100,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary with performance-based bonuses
Fully company-paid insurance packages
401(k) plan with a 5% match
20 days of paid vacation
Parental leave of 4 months
$1,000 work-from-home stipend
$750 annual learning & development stipend
Philanthropic contribution matching up to $2,000 annually

Job summary

Trail of Bits seeks a Security Engineer, Application Security to conduct security assessments and low-level code analysis. The position impacts secure technology for top-tier clients, contributing both directly and through collaborative research efforts.

You'll engage with advanced security challenges, developing tools and methodologies while enjoying a supportive remote-first workplace culture. Offering a salary range of $100,000 to $200,000, this role promises both rewards and responsibilities in the evolving tech landscape.

Qualifications

  • Direct experience conducting low-level code security assessments of complex software.
  • Hands-on experience performing manual code reviews to find vulnerabilities that automated tools miss.
  • Experience using static and dynamic analysis tools as part of a deeper review process.
  • Experience performing binary analysis and reverse engineering of compiled software.
  • Demonstrated experience identifying memory corruption vulnerabilities and reasoning about modern mitigations.
  • Deep experience reasoning about system internals, IPC, access control implementations, and platform security boundaries.
  • Experience performing architecture reviews and threat modeling of software systems and cloud environments.
  • Experience designing and building custom security tools for automated vulnerability detection.
  • Hands-on experience programming in two or more of Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, or C++.
  • Experience translating complex security findings into clear, actionable recommendations for teams.

Responsibilities

  • Conduct comprehensive low-level code security assessments across applications.
  • Design and implement custom security tools for automated vulnerability detection.
  • Perform detailed architecture reviews and threat modeling of complex software systems.
  • Work directly with industry-leading teams to review their application infrastructure.
  • Contribute to the advancement of application security and develop new methodologies.

Skills

Application security assessment experience
Manual code review depth
Static and dynamic analysis fluency
Binary analysis and reverse engineering
Memory corruption vulnerabilities and mitigations
System internals and security boundaries
Architecture review and threat modeling
Security tool development
Programming proficiency across multiple languages
Communicating findings to technical stakeholders

Job description

Trail of Bits seeks a Security Engineer, Application Security to conduct security assessments and low-level code analysis. The position impacts secure technology for top-tier clients, contributing both directly and through collaborative research efforts.

You'll engage with advanced security challenges, developing tools and methodologies while enjoying a supportive remote-first workplace culture. Offering a salary range of $100,000 to $200,000, this role promises both rewards and responsibilities in the evolving tech landscape.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Application Security Engineer - Low-Level Code & Tools
Remote Application Security Engineer - Low-Level Code & Tools

Trail of Bits Inc. • United States

On-site
USD 100,000 - 200,000
Competitive salary
Fully company-paid insurance packages
401(k) plan with 5% match
+5
Security Engineer I — Vulnerability Research & Tools, Remote
Security Engineer I — Vulnerability Research & Tools, Remote

Trail of Bits • United States

On-site
USD 100,000 - 160,000
Performance bonuses
Fully company-paid insurance packages:
401(k) plan
+7
Application Security Engineer: Threat Modeling & Tools
Application Security Engineer: Threat Modeling & Tools

Trail of Bits Inc. • New York (NY)

Hybrid
USD 100,000 - 200,000
Fully company-paid insurance packages
401(k) plan with 5% match
20 days of paid vacation
+2
Security Engineer, Application Security
Security Engineer, Application Security

Trail of Bits Inc. • New York (NY)

Hybrid
USD 100,000 - 200,000
Fully company-paid insurance packages
401(k) plan with 5% match
20 days of paid vacation
+2
Application Security Engineer (Remote)
Application Security Engineer (Remote)

SherlockTalent • Boca Raton (FL)

Hybrid
USD 80,000 - 120,000
Unlimited PTO
Comprehensive healthcare program
Monthly Health Day
+2
Principal Security Engineer, Application Security
Principal Security Engineer, Application Security

Trail of Bits • United States

On-site
USD 200,000 - 235,000
Competitive salary with performance-based bonuses
Fully company-paid insurance, including health and dental
401(k) plan with a 5% match
+6
Remote Product Security Engineer II: Secure Innovative Apps
Remote Product Security Engineer II: Secure Innovative Apps

Affirm • Boulder (CO)

On-site
USD 146,000 - 206,000
Health insurance
ESPP
Time off
Remote Product Security Engineer II
Remote Product Security Engineer II

Affirm • Chicago (IL)

Remote
USD 146,000 - 206,000
Health care coverage
Flexible Spending Wallets
Time off
+1
Remote Senior Application Security Engineer: Secure Coding
Remote Senior Application Security Engineer: Secure Coding

Bold Penguin • Dublin (OH)

On-site
USD 130,000 - 170,000
Engineering Director, Application Security
Engineering Director, Application Security

Trail of Bits Inc. • New York (NY)

Hybrid
USD 250,000 - 300,000
Competitive salary
Performance-based bonuses
Fully company-paid insurance
+7