Security Engineer (Application Security)

Trail of Bits

United States

Hybrid

USD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health Insurance
Vision, Dental, Life & Disability
401k with company matching
Relocation assistance
Work from home stipend
Conferences & off-sites

Job summary

Trail of Bits seeks a Security Engineer I for our Application Security practice. You will contribute to security assessments of client software, partner with more experienced engineers, and own clearly scoped pieces of client engagements.

Your hands-on work includes analyzing complex code, building custom tooling, conducting threat modeling, and delivering findings to clients. This role bridges vulnerability research and applied security and is aimed at early-career professionals with hands-on

Qualifications

  • 1+ year of combined experience in application security, vulnerability research, or security-focused software engineering.
  • Ability to reason about memory‑corruption vulnerabilities and mitigations (e.g., buffer overflows, ASLR, NX/DEP).
  • Ability to investigate well-scoped problems, debug issues, document evidence, and deliver with review from a project lead.
  • Familiarity with OS concepts, IPC, privilege boundaries, and how apps interact with system internals.
  • Strong code-analysis skills: read unfamiliar code, trace execution and data flow, identify flaws.
  • Demonstrated vulnerability-discovery capability via professional work, coursework, open source, or CTFs.

Responsibilities

  • Lead the review of a specific component or system within a client engagement.
  • Find and validate vulnerabilities in application code and systems, explain exploitation paths.
  • Develop proof-of-concept code when appropriate.
  • Design and build security-testing tools and automation.
  • Review architectures, attack surfaces, data flows and mitigations.
  • Translate technical findings into actionable remediation guidance for engineers.

Skills

Vulnerability analysis
Code reading
Rust
Go
Python
Security tooling
CTF participation

Tools

Open-source tooling

Job description

  • Trail of Bits seeks a Security Engineer I for our Application Security practice
  • You will contribute to security assessments of client software, partner with more experienced engineers, identify vulnerabilities across the application and system levels, and own clearly scoped pieces of client engagements
  • You will drive your own vulnerability analysis, develop tools alongside the team, and help clients understand and fix the issues you find
  • This role bridges vulnerability research and applied security
  • Your work will be hands‑on: analyzing complex code, building custom tooling, conducting threat modeling, and owning your findings through client delivery
  • It is distinct from roles centered on security operations, SOC work, GRC, compliance, policy, audit, or general security administration
  • Candidates from broader or adjacent security backgrounds should be prepared to talk through relevant hands‑on, code‑level security work they have personally completed
  • Security Engineer I is an early‑career role, but it is not a training role for someone new to software or security
  • Relevant experience may come from professional work, internships, advanced coursework, independent research, open‑source contributions, CTFs, or substantial personal or academic projects
  • Regardless of where you gained the experience, you should be able to talk through code‑level security work you performed, how you approached the problem, and the conclusions you reached
  • You will receive direction and review from a project lead while independently completing well‑scoped technical work
  • Security Assessment Ownership: Lead the review of a specific component, module, or system within a larger client engagement. Trace root causes and own your analysis from discovery through client delivery
  • Vulnerability Discovery and Analysis: Find and validate vulnerabilities in application code and systems, explain exploitation paths, assess impact, and develop proof‑of‑concept code when appropriate
  • Custom Security Tooling: Design and build security‑testing tools and automation for vulnerability detection and deeper analysis
  • Architecture and Threat Modeling: Review software architectures, identify attack surfaces, data flows, trust and privilege boundaries, and recommend concrete mitigations
  • Client Communication: Translate technical findings into clear, actionable recommendations for engineering teams and explain the evidence behind your conclusions
  • Research and Innovation: Contribute to security research, open‑source tools, internal knowledge sharing, and technical documentation
Benefits
  • Health Insurance with no-monthly-premiums
  • Vision, Dental, Life & Disability Insurance
  • Access to Kindbody for gynecology and fertility care
  • Access to HealthAdvocate, Teledoc & OneMedical
  • 401k with 5% company matching
  • Competitive salaries
  • Ongoing bonus opportunities
  • ConnectYourCare Flex Spending Account (FSA)
  • Commuter Benefits
  • Fitness stipends
  • Four weeks of PTO
  • Fifteen company holidays
  • 4 months paid parental leave
  • Continuing education, public presentations and blog posts
  • Recruiting & referrals
  • End‑of‑year performance bonus
  • Conferences & off‑sites
  • Company & team outings
  • Virtual events
  • Continuing education
  • Training sessions & learning courses
  • Internal research & development Projects
  • Charitable donation matching
  • Relocation assistance
  • 1Password subscription
  • Work from home stipend
  • Remote work friendly

At least 1 year of combined relevant experience in application security, vulnerability research, security‑focused software engineering, or a closely related area. This experience may come from employment, internships, advanced coursework, independent research, open‑source contributions, CTFs, or substantial personal or academic projectsWorking knowledge of memory‑corruption vulnerabilities and common mitigations, such as buffer overflows, use‑after‑free, stack cookies, ASLR, NX/DEP, CFI, or MTE, including the ability to reason about exploit primitives at an appropriate early‑career levelAbility to independently investigate a well‑scoped problem, debug issues, document evidence, ask focused questions when blocked, and deliver work with review from a project leadFamiliarity with operating‑system concepts, IPC, privilege boundaries, and the ways applications interact with system internalsStrong code‑analysis skills. You can read unfamiliar code, trace execution and data flow, identify logic or implementation flaws, and distinguish a tool signal from a validated vulnerabilityClear written and verbal communication, including the ability to explain technical findings and remediation guidance to software engineers and work productively on a distributed teamDemonstrable vulnerability‑discovery capability. You can talk through a vulnerability or security weakness you personally found or validated, including how you identified it, established its impact, and reached your conclusion. Evidence may come from professional work, coursework, projects, CTFs, CVEs, bug bounties, responsible disclosure, open source, or comparable researchHands‑on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, TypeScript, or similar languages used in security analysis and tool developmentThese are not day‑one requirements, but areas where the role can growActive or recent CTF participation, competition results, or comparable hands‑on security challengesPublished vulnerability research, CVEs, responsible disclosures, bug bounty findings, or security writeupsContributions to open‑source security tools, libraries, or researchExperience with mobile application security, mobile system internals, or binary analysis on mobile platformsExperience assessing cloud platforms or infrastructure and working with tools such as Kubernetes, Helm, Terraform, or AnsibleExperience with kernel code, drivers, reverse engineering, fuzzing, or other low‑level systems workPublished technical writing, conference talks, or substantial technical documentation

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

SentinelOne, Inc. • United States

Remote
USD 140,000 - 230,000
Medical, dental, and vision coverage
Unlimited Time Off
Paid Holidays
+2
Security Engineer II, Application Security
Security Engineer II, Application Security

Trail of Bits • United States

Remote
USD 140,000 - 180,000
Health insurance
Fully company-paid insurance packages
401(k) with 5% match
+7
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Application Security Engineer – CVE & Vulnerability Research
Application Security Engineer – CVE & Vulnerability Research

Hidden Jobs • United States

On-site
USD 96,000 - 152,000
Fully remote
Part-time project-based engagement
Engineering Director, Application Security
Engineering Director, Application Security

Trail of Bits • Northern (KY)

On-site
USD 180,000 - 260,000
Competitive health benefits
Professional development budget
Remote-friendly options
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Application Security Engineer
Application Security Engineer

Talentify • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Security Engineer I, Application Security
Security Engineer I, Application Security

Trail of Bits • United States

Remote
USD 100,000 - 160,000
Health insurance
401(k) match
Paid vacation
+5
Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New York (NY)

On-site
USD 180,000 - 230,000