Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Trail of Bits seeks an experienced leader to run its Application Security practice in the United States. You will guide a team of security engineers performing code audits, vulnerability research, and secure design reviews for highly technical clients.
This hands-on leadership role entails reviewing audit findings, shaping technical direction, and managing the practice’s staffing and P&L. You will stay hands-on across Rust, Go, C/C++, Python, Solidity, and JavaScript to maintain credibility with
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.
Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable.
You will lead Trail of Bits' Application Security practice: a team of 12 security engineers who perform code audits, vulnerability research, and secure design reviews for some of the most technically demanding clients in the industry.
This is a hands-on leadership role. You will personally review audit findings, guide technical approaches, and maintain the credibility to engage with sophisticated clients who expect their security partner to operate at their level. You will own the practice's financial performance, project staffing, and team development.
Your team works on source code. They do static analysis, manual code review, fuzzing, and protocol-level vulnerability research across Rust, Go, C/C++, Python, Solidity, and JavaScript. You need to be able to do this work yourself, not just manage people who do it.