A complete application in a minute — tailored resume and cover letter, ready to send.
Trail of Bits seeks a Security Engineer I for our Application Security practice. You will contribute to security assessments of client software, partner with more experienced engineers, and own clearly scoped pieces of client engagements.
Your hands-on work includes analyzing complex code, building custom tooling, conducting threat modeling, and delivering findings to clients. This role bridges vulnerability research and applied security and is aimed at early-career professionals with hands-on
At least 1 year of combined relevant experience in application security, vulnerability research, security‑focused software engineering, or a closely related area. This experience may come from employment, internships, advanced coursework, independent research, open‑source contributions, CTFs, or substantial personal or academic projectsWorking knowledge of memory‑corruption vulnerabilities and common mitigations, such as buffer overflows, use‑after‑free, stack cookies, ASLR, NX/DEP, CFI, or MTE, including the ability to reason about exploit primitives at an appropriate early‑career levelAbility to independently investigate a well‑scoped problem, debug issues, document evidence, ask focused questions when blocked, and deliver work with review from a project leadFamiliarity with operating‑system concepts, IPC, privilege boundaries, and the ways applications interact with system internalsStrong code‑analysis skills. You can read unfamiliar code, trace execution and data flow, identify logic or implementation flaws, and distinguish a tool signal from a validated vulnerabilityClear written and verbal communication, including the ability to explain technical findings and remediation guidance to software engineers and work productively on a distributed teamDemonstrable vulnerability‑discovery capability. You can talk through a vulnerability or security weakness you personally found or validated, including how you identified it, established its impact, and reached your conclusion. Evidence may come from professional work, coursework, projects, CTFs, CVEs, bug bounties, responsible disclosure, open source, or comparable researchHands‑on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, TypeScript, or similar languages used in security analysis and tool developmentThese are not day‑one requirements, but areas where the role can growActive or recent CTF participation, competition results, or comparable hands‑on security challengesPublished vulnerability research, CVEs, responsible disclosures, bug bounty findings, or security writeupsContributions to open‑source security tools, libraries, or researchExperience with mobile application security, mobile system internals, or binary analysis on mobile platformsExperience assessing cloud platforms or infrastructure and working with tools such as Kubernetes, Helm, Terraform, or AnsibleExperience with kernel code, drivers, reverse engineering, fuzzing, or other low‑level systems workPublished technical writing, conference talks, or substantial technical documentation