Engineering Director, Application Security

Trail of Bits

Northern (KY)

Hybrid

USD 180,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive health benefits
Professional development budget
Remote-friendly options

Job summary

Trail of Bits seeks an experienced leader to run its Application Security practice in the United States. You will guide a team of security engineers performing code audits, vulnerability research, and secure design reviews for highly technical clients.

This hands-on leadership role entails reviewing audit findings, shaping technical direction, and managing the practice’s staffing and P&L. You will stay hands-on across Rust, Go, C/C++, Python, Solidity, and JavaScript to maintain credibility with

Qualifications

  • 10+ years in security with significant source code audits.
  • Recent, demonstrable hands-on security work across multiple languages.

Responsibilities

  • Lead technical delivery. Ensure quality and profitability of engagements.
  • Staff projects, manage utilization, hiring, and pipeline growth.
  • Develop engineers through conferences, research, and open-source contributions.
  • Set technical direction for tooling, methodology, and capability development.
  • Integrate AI into auditing, reporting, and research workflows.

Skills

Security auditing
Code review
Leadership
Hands-on cryptography/secure design

Tools

Rust
Go
C/C++
Python
Solidity
JavaScript

Job description

Who We Are

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.

Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.

Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable.

Role

You will lead Trail of Bits' Application Security practice: a team of 12 security engineers who perform code audits, vulnerability research, and secure design reviews for some of the most technically demanding clients in the industry.

This is a hands-on leadership role. You will personally review audit findings, guide technical approaches, and maintain the credibility to engage with sophisticated clients who expect their security partner to operate at their level. You will own the practice's financial performance, project staffing, and team development.

Your team works on source code. They do static analysis, manual code review, fuzzing, and protocol-level vulnerability research across Rust, Go, C/C++, Python, Solidity, and JavaScript. You need to be able to do this work yourself, not just manage people who do it.

What You’ll Achieve
  • Lead technical delivery. Own the quality and profitability of every engagement your team ships. Review findings, guide technical direction on complex audits, and step in when projects need senior expertise. Maintain direct relationships with your most important clients.
  • Staff and grow the practice. Make project assignment decisions that balance engineer development, client needs, and profitability. Manage utilization, identify when to hire, and build the pipeline through the intern program and recruiting. Own the practice's P&L.
  • Develop your engineers. Create space for your team to present at conferences, publish research, contribute to open source tools, and advance their careers. Identify and remove obstacles. Your success is measured by their output, not yours.
  • Set technical direction. Decide where the practice invests in tooling, methodology, and capability development. Stay hands-on enough to know what's working and what isn't. Ensure the team's approach evolves with the threat landscape and client needs.
  • Integrate AI into the practice. Champion and model the use of AI tools across your team's workflows. Help engineers adopt AI-assisted auditing, reporting, and research practices that amplify their effectiveness.
What You’ll Bring
  • 10+ years in security, including significant time performing source code audits, not only penetration testing
  • Recent, demonstrable hands‑on security work (
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Director, Application Security
Engineering Director, Application Security

Trail of Bits • United States

On-site
USD 180,000 - 280,000
Engineering Director, Application Security
Engineering Director, Application Security

Trail of Bits Inc. • New York (NY)

Hybrid
USD 250,000 - 300,000
Competitive salary
Performance-based bonuses
Fully company-paid insurance
+7
Application Security Director - Hands-On Leader, Growth
Application Security Director - Hands-On Leader, Growth

Trail of Bits • United States

On-site
USD 180,000 - 280,000
Director of Application Security & AI-Driven Audits
Director of Application Security & AI-Driven Audits

Trail of Bits • Northern (KY)

Hybrid
USD 180,000 - 260,000
Competitive health benefits
Professional development budget
Remote-friendly options
Principal Security Engineer, Application Security
Principal Security Engineer, Application Security

Trail of Bits • United States

On-site
USD 200,000 - 235,000
Competitive salary with performance-based bonuses
Fully company-paid insurance, including health and dental
401(k) plan with a 5% match
+6
Senior Application Security Engineer
Senior Application Security Engineer

TKO • New York (NY)

Hybrid
USD 180,000 - 240,000
Engineering Manager, Application Security
Engineering Manager, Application Security

Qualia • Austin (TX)

On-site
USD 180,000 - 240,000
Medical, Dental & Vision health plans
Competitive salary & equity
Flexible schedules
+3
Security Engineer, Application Security
Security Engineer, Application Security

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

ReTool • San Francisco (CA)

On-site
USD 150,000 - 230,000
Security Engineering Manager
Security Engineering Manager

Corporate Tools LLC • Austin (TX)

Hybrid
USD 157,000 - 185,000
100% employer-paid medical, dental and vision
Annual review with raise option
22 days Paid Time Off
+1