747,513open jobs
44,904companies
108,446added this week
Browse all
Salary
≈ $92k – $178k per year (Estimated)
Location
Remote (United States)
Seniority
Middle
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Sep 24, 2026.

Overview
Company
Impact
Profile match
Trail of Bits is a cybersecurity research, engineering, and consulting firm that specializes in software assurance, cryptography, and advanced threat modeling. The company provides deep code audits, penetration testing, and security evaluations for complex digital systems, including smart contracts, AI/ML pipelines, and cloud infrastructure. Known for its strong focus on open source, it actively develops public security tools, conducts government-backed research, and advances industry-wide software security standards.

Location: Remote, United States

About Trail of Bits

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.

Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.

Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable.

The Role

Trail of Bits seeks a Security Engineer II for our Application Security practice. You will conduct security assessments of client software, independently own substantial components or workstreams, identify and validate vulnerabilities across the application and system levels, and develop custom tooling alongside the team. You will own your analysis from discovery through client delivery and help clients understand and fix the issues you find.

This role bridges vulnerability research and applied security. Your work will be hands-on and autonomous: analyzing complex code, building custom tooling, conducting threat modeling and architecture reviews, and delivering findings that can withstand technical scrutiny.

It is distinct from roles centered on security operations, SOC work, GRC, compliance, policy, audit, or general security programs. Candidates from broader or adjacent security backgrounds should be prepared to talk through sustained, hands-on code-level security work they have personally completed.

At the Security Engineer II level, you should be able to take an ambiguous component, module, or attack surface, determine how to assess it, perform the analysis, and deliver clear findings with limited day-to-day direction. You will collaborate with a project lead and other security engineers while exercising independent technical judgment and improving the work of the team around you.

What You'll Achieve

  • Security Assessment Ownership: Independently lead assessments of substantial components, modules, or systems within client engagements and own the work from scoping through delivery.
  • Vulnerability Discovery and Analysis: Find and validate vulnerabilities, establish root causes and exploitation paths, assess impact, and develop proof-of-concept code when appropriate.
  • Custom Security Tooling: Design and build targeted tools, harnesses, tests, or automation that expand assessment coverage and improve repeatability.
  • Architecture and Threat Modeling: Review complex software architectures, identify attack surfaces, data flows, trust and privilege boundaries, and recommend practical mitigations.
  • Client Communication: Produce clear, actionable findings, defend the evidence behind them, and lead technical discussions with client engineering teams.
  • Team Contribution: Review other engineers' code and analysis, share techniques, and help improve the team's technical approach.
  • Research and Innovation: Contribute new methods, open-source tools, and technical writing to Trail of Bits and the broader security community.

What You'll Bring

The following are requirements for this role:

  • Typically 2+ years of directly relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area. Relevant experience may include professional work, research, open-source contributions, or substantial academic or independent projects; demonstrated depth and independence matter more than a strict year count.
  • Repeated vulnerability-discovery experience. You can talk through vulnerabilities you personally found or validated, including how you identified them, established exploitation paths and impact, and distinguished them from false positives or low-impact defects.
  • Strong code-analysis skills across unfamiliar and complex codebases, including tracing execution and data flow, identifying logic and implementation flaws, and reviewing the security implications of system design.
  • Strong programming and debugging ability in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, TypeScript, or similar languages used in security analysis and tool development.
  • Working knowledge of memory-corruption vulnerabilities and mitigations, including the ability to reason about exploit primitives, defensive mechanisms, and the practical security impact of implementation choices.
  • Strong systems knowledge, including operating systems, IPC, privilege boundaries, system internals, and how applications interact with the platform around them.
  • Demonstrated ability to independently scope and execute a code-level security-assessment workstream, prioritize attack surfaces, build or adapt tooling, document evidence, and deliver findings.
  • Clear written and verbal communication, including experience presenting technical conclusions to software engineers or clients and contributing effectively on a distributed team.

Preferred Qualifications

These are not day-one requirements, but areas where the role can grow.

  • Active or recent CTF participation, competition results, or comparable hands-on security challenges.
  • Published vulnerability research, CVEs, responsible disclosures, bug bounty findings, conference presentations, or technical writeups.
  • Contributions to open-source security tools, libraries, or research.
  • Experience with mobile application security, mobile system internals, or binary analysis on mobile platforms.
  • Experience assessing cloud platforms or infrastructure and working with tools such as Kubernetes, Helm, Terraform, or Ansible.
  • Experience with kernel code, drivers, reverse engineering, fuzzing, symbolic execution, or other low-level systems work.
  • Experience building security tools used by other engineers or across multiple assessments.
  • Experience leading client-facing technical discussions or mentoring other security engineers.

Compensation

The base salary range for this full-time position is $140,000 to $180,000. This position is also eligible for a performance-based variable bonus. Compensation is informed by geographic location, relevant experience, and internal equity. These figures represent starting compensation for U.S.-based candidates. For specifics, please discuss with your recruiter during the hiring process.

Trail of Bits offers a comprehensive benefits package including health insurance, retirement contributions, professional development stipends, and generous PTO.

Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more.

Trail of Bits is an equal-opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other characteristic protected by law, and we provide reasonable accommodations throughout the hiring process on request.

Benefits, Perks & Wellness

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:

Empowered Living

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.

Nurturing New Beginnings

  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.

Work & Life Enrichment

  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.

Community Impact

  • Philanthropic contribution matching up to $2,000 annually.

Benefits

Benefits, Perks & Wellness

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:

Empowered Living:

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.

Nurturing New Beginnings:

  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.

Work & Life Enrichment:

  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.

Community Impact:

  • Philanthropic contribution matching up to $2,000 annually.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
747,513 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
$105k – $115k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Boston
DevOps
Azure
AWS
VPN
Cybersecurity
GDPR
SIEM
Management
Jira
ITIL
Apply
≈ $25k – $59k per year (Estimated) • Remote (India) • Full-Time • 3+ years exp
Python
PowerShell
DevOps
Splunk
Cybersecurity
Crowdstrike
Wazuh
Microsoft Sentinel
ISO 27001
SentinelOne
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Sumo Logic
SIEM
Apply
≈ $15k – $36k per year (Estimated) • Remote (Philippines) • Full-Time • 3+ years exp
Python
PowerShell
DevOps
Splunk
Cybersecurity
Crowdstrike
Wazuh
Microsoft Sentinel
ISO 27001
SentinelOne
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Sumo Logic
SIEM
Apply
≈ $84k – $172k per year (Estimated) • In office • 3+ years exp • Durham
DevOps
Azure
Windows
Cybersecurity
Least Privilege
Microsoft Entra ID
Active Directory
SIEM
Apply
≈ $88k – $182k per year (Estimated) • In office • 3+ years exp • Durham
Databases
Apache Kafka
Cybersecurity
Defense in Depth
IoT
MQTT
Apply
≈ $71k – $145k per year (Estimated) • Remote (United States) • Full-Time
Python
JavaScript
Rust
TypeScript
C++
DevOps
Terraform
Ansible
Helm
Kubernetes
Cybersecurity
Threat Modeling
Apply
SREエンジニア 7 hours ago
$496k – $671k per year • In office
Python
Go
JavaScript
Kotlin
TypeScript
Databases
PostgreSQL
DynamoDB
Frontend
Vue.js
Nuxt.js
DevOps
Terraform
GitHub Actions
CI/CD
AWS
AWS Fargate
GitHub
GitLab
Amazon ECS
Linux
Management
Confluence
Apply
$496k – $671k per year • In office
Python
Go
JavaScript
Kotlin
TypeScript
SQL
Databases
MySQL
PostgreSQL
Snowflake
DynamoDB
Apache Kafka
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Dagster
Frontend
Vue.js
Nuxt.js
DevOps
Terraform
GCP
GitHub Actions
AWS
AWS Fargate
SLI/SLO/SLA
Amazon ECS
Amazon Kinesis
Analytics
Power BI
ETL/ELT
Looker
Management
Confluence
Apply
$496k – $671k per year • In office
Python
Go
JavaScript
Java
PHP
TypeScript
Databases
MySQL
PostgreSQL
DynamoDB
Amazon Redshift
AI/ML
Copilot
Claude Code
Amazon SageMaker
Frontend
Vue.js
Nuxt.js
React.js
DevOps
Terraform
GCP
GitHub Actions
AWS
AWS Fargate
AWS Lambda
Amazon ECS
Management
Confluence
Jira
Apply
≈ $28k – $76k per year (Estimated) • In office
Go
JavaScript
Kotlin
TypeScript
Swift
Databases
PostgreSQL
DynamoDB
Frontend
Vue.js
Nuxt.js
Mobile
UIKit
SwiftUI
DevOps
Terraform
GitHub Actions
Jenkins
AWS
AWS Fargate
Amazon ECS
Management
Confluence
QA
JMeter
Apply
≈ $71k – $145k per year (Estimated) • Remote (United States) • Full-Time
Python
JavaScript
Rust
TypeScript
C++
DevOps
Terraform
Ansible
Helm
Kubernetes
Cybersecurity
Threat Modeling
Apply
≈ $126k – $232k per year (Estimated) • Remote (United States)
Rust
C++
DevOps
Git
Cybersecurity
Threat Modeling
Apply
≈ $90k – $172k per year (Estimated) • Remote (United Kingdom) • Full-Time
Python
Rust
C++
AI/ML
AI Agents
LLM
Red Teaming
Apply
Solutions Architect 3 days ago
≈ $136k – $268k per year (Estimated) • Remote (United States) • Full-Time
AI/ML
AI Agents
Cybersecurity
Threat Modeling
Apply
≈ $175k – $299k per year (Estimated) • Remote (United States) • Full-Time
Python
JavaScript
Rust
TypeScript
C++
Apply
See all jobs
This is one of many
747,513 more open roles from verified company boards, updated every day.