Remote: Hands-On Application Security Engineer I

Trail of Bits

United States

Hybrid

USD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health Insurance
Vision, Dental, Life & Disability
401k with company matching
Relocation assistance
Work from home stipend
Conferences & off-sites

Job summary

Trail of Bits seeks a Security Engineer I for our Application Security practice. You will contribute to security assessments of client software, partner with more experienced engineers, and own clearly scoped pieces of client engagements.

Your hands-on work includes analyzing complex code, building custom tooling, conducting threat modeling, and delivering findings to clients. This role bridges vulnerability research and applied security and is aimed at early-career professionals with hands-on

Qualifications

  • 1+ year of combined experience in application security, vulnerability research, or security-focused software engineering.
  • Ability to reason about memory‑corruption vulnerabilities and mitigations (e.g., buffer overflows, ASLR, NX/DEP).
  • Ability to investigate well-scoped problems, debug issues, document evidence, and deliver with review from a project lead.
  • Familiarity with OS concepts, IPC, privilege boundaries, and how apps interact with system internals.
  • Strong code-analysis skills: read unfamiliar code, trace execution and data flow, identify flaws.
  • Demonstrated vulnerability-discovery capability via professional work, coursework, open source, or CTFs.

Responsibilities

  • Lead the review of a specific component or system within a client engagement.
  • Find and validate vulnerabilities in application code and systems, explain exploitation paths.
  • Develop proof-of-concept code when appropriate.
  • Design and build security-testing tools and automation.
  • Review architectures, attack surfaces, data flows and mitigations.
  • Translate technical findings into actionable remediation guidance for engineers.

Skills

Vulnerability analysis
Code reading
Rust
Go
Python
Security tooling
CTF participation

Tools

Open-source tooling

Job description

Trail of Bits seeks a Security Engineer I for our Application Security practice. You will contribute to security assessments of client software, partner with more experienced engineers, and own clearly scoped pieces of client engagements.

Your hands-on work includes analyzing complex code, building custom tooling, conducting threat modeling, and delivering findings to clients. This role bridges vulnerability research and applied security and is aimed at early-career professionals with hands-on

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer I — Remote, Hands-On & Impactful
Application Security Engineer I — Remote, Hands-On & Impactful

Trail of Bits • United States

Remote
USD 100,000 - 160,000
Health insurance
401(k) match
Paid vacation
+5
Remote Security Engineer II - App Security & Tooling
Remote Security Engineer II - App Security & Tooling

Trail of Bits • United States

Remote
USD 140,000 - 180,000
Health insurance
Fully company-paid insurance packages
401(k) with 5% match
+7
Security Engineer (Application Security)
Security Engineer (Application Security)

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3
Engineering Director, Application Security
Engineering Director, Application Security

Trail of Bits • Northern (KY)

On-site
USD 180,000 - 260,000
Competitive health benefits
Professional development budget
Remote-friendly options
Remote Application Security Engineer
Remote Application Security Engineer

Bright Vision Technologies • Eden Prairie (MN)

Remote
USD 100,000 - 150,000
Remote Security Engineer - Cloud & App Security Lead
Remote Security Engineer - Cloud & App Security Lead

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Senior AppSec Engineer - Remote
Senior AppSec Engineer - Remote

Bright Vision Technologies • Monroeville

Remote
USD 100,000 - 160,000
Remote Security Engineer: AWS, AppSec & Vulnerability Mgmt
Remote Security Engineer: AWS, AppSec & Vulnerability Mgmt

Worth AI • Miami (FL)

Hybrid
USD 110,000 - 150,000
Health Care Plan
Retirement Plan
Life Insurance
+7
Application Security Engineer | Remote
Application Security Engineer | Remote

Crossing Hurdles • United States

On-site
GBP 50,000 - 70,000
Application Security Engineer
Application Security Engineer

Ringside Talent Acquisition Partners • Columbus (OH)

Hybrid
USD 120,000 - 150,000