Remote Security Engineer II - App Security & Tooling

Trail of Bits

United States

Remote

USD 140,000 - 180,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
Fully company-paid insurance packages
401(k) with 5% match
20 days PTO
Parental leave (4 months)
Relocation assistance to NYC ($10,000)
Working-from-Home stipend ($1,000)
Learning & Development stipend ($750)
Team celebrations with travel
Philanthropic matching

Job summary

Trail of Bits is seeking a Security Engineer II for its Application Security practice. You will conduct security assessments of client software, own substantial components, identify vulnerabilities, and develop tooling alongside the team.

This hands-on, autonomous role bridges vulnerability research with applied security and involves communicating findings to clients. You will collaborate with a project lead and other security engineers, delivering clear findings with limited day-to-day

Qualifications

  • Typically 2+ years of directly relevant experience in application security, vulnerability research, security-focused software engineering, or related area.
  • Proven vulnerability-discovery experience and ability to discuss exploitation paths and impact.
  • Strong code-analysis skills across unfamiliar and complex codebases.
  • Proficiency in at least two languages such as Rust, Go, C, C++, Python, JavaScript or TypeScript.
  • Working knowledge of memory-corruption vulnerabilities and mitigations.
  • Strong systems knowledge including OS, IPC, privilege boundaries, and how apps interact with the platform.
  • Ability to independently scope and execute a code-level security-assessment workstream.
  • Clear written and verbal communication, including presenting to software engineers or clients.

Responsibilities

  • Lead assessments of substantial components, modules, or systems from scoping to delivery.
  • Find and validate vulnerabilities, establish root causes and exploitation paths.
  • Design and build targeted tools to expand assessment coverage.
  • Review architectures, map data flows, identify attack surfaces and mitigations.
  • Communicate findings clearly to client engineers and defend evidence.
  • Review peers' code and techniques to improve the team’s approach.
  • Contribute to research, open-source tools, and technical writing.

Skills

Vulnerability discovery
Code analysis
Rust
Go
C/C++
Python/JavaScript/TypeScript
Memory corruption concepts
Systems knowledge
Communication

Tools

Kubernetes
Terraform
Ansible

Job description

Trail of Bits is seeking a Security Engineer II for its Application Security practice. You will conduct security assessments of client software, own substantial components, identify vulnerabilities, and develop tooling alongside the team.

This hands-on, autonomous role bridges vulnerability research with applied security and involves communicating findings to clients. You will collaborate with a project lead and other security engineers, delivering clear findings with limited day-to-day

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote: Hands-On Application Security Engineer I
Remote: Hands-On Application Security Engineer I

Trail of Bits • United States

Hybrid
USD 90,000 - 130,000
Health Insurance
Vision, Dental, Life & Disability
401k with company matching
+3
Application Security Engineer I — Remote, Hands-On & Impactful
Application Security Engineer I — Remote, Hands-On & Impactful

Trail of Bits • United States

Remote
USD 100,000 - 160,000
Health insurance
401(k) match
Paid vacation
+5
Remote Security Engineer II — App Security & API
Remote Security Engineer II — App Security & API

Spotnana • Northern (KY)

Hybrid
USD 110,000 - 147,000
Equity in stock options
Pre-tax and Roth 401(k) with 4% match
Comprehensive medical/dental/vision/l0
+8
Remote Security Engineer: AWS, AppSec & Vulnerability Mgmt
Remote Security Engineer: AWS, AppSec & Vulnerability Mgmt

Worth AI • Miami (FL)

Hybrid
USD 110,000 - 150,000
Health Care Plan
Retirement Plan
Life Insurance
+7
Remote Security Engineer - Cloud & App Security Lead
Remote Security Engineer - Cloud & App Security Lead

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Remote Product Security Engineer: App Security & Pentesting
Remote Product Security Engineer: App Security & Pentesting

knowbe4 • United States

Remote
USD 120,000 - 150,000
Company-wide bonuses tied to monthly销售
Employee referral bonuses
Adoption assistance
+3
Remote Security Engineer: AppSec & Cloud Risk Leader
Remote Security Engineer: AppSec & Cloud Risk Leader

Writing.io • United States

On-site
USD 122,000 - 144,000
Excellent medical, dental, and vision
Flexible paid time off
Stock options
+5
Senior AppSec Engineer - Remote
Senior AppSec Engineer - Remote

Bright Vision Technologies • Monroeville

Remote
USD 100,000 - 160,000
Remote Application Security Engineer
Remote Application Security Engineer

Bright Vision Technologies • Eden Prairie (MN)

Remote
USD 100,000 - 150,000
Remote Application Security Engineer | AppSec & Automation
Remote Application Security Engineer | AppSec & Automation

MyFitnessPal, Inc. • Northern (KY)

Hybrid
USD 90,000 - 120,000
Healthcare benefits
401(k) plan and match
Wellness allowance
+1