{"id":1645852,"url":"https://alion.io/job/trm-labs-product-security-engineer","title":"Product Security Engineer","company":{"id":5039,"name":"TRM Labs","domain":"trmlabs.com","url":"https://alion.io/company/trm-labs","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"A","score":91,"open_postings":39,"ghost_share":0,"stale_share":0.179,"repost_share":0,"time_to_fill_p50_days":83,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":{"label":"UTC-5 – UTC-4","utc_offset_min":-5,"utc_offset_max":-4},"hiring_geo_confidence":"explicit","locations":[],"countries":[],"hiring_countries":["GB"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":135000,"max_usd":244000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":220},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"AWS","optional":false},{"name":"Bootstrap","optional":false},{"name":"Burp Suite","optional":false},{"name":"CWE","optional":false},{"name":"GCP","optional":false},{"name":"GitHub","optional":false},{"name":"Node JS","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TRM Labs","optional":false},{"name":"CI/CD","optional":true},{"name":"JavaScript","optional":true}],"status":"live","first_seen_at":"2026-10-01T20:35:00Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-05T02:10:30Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Build a Safer World.\nTRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.\nAbout the Team\nThe Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.\nThe impact you will have here:\nLead application security reviews and threat modeling, including secure code review, architectural design, and testing\n\nDevelop automated testing and mature our Secure SDLC\n\nOwn and perform application security vulnerability management\n\nCoordinate penetration testing engagements\n\nSupport software engineers and product teams by developing application security best practices\n\nDevelop and maintain the bug bounty program\n\nBootstrap platform security initiatives that help protect TRM data\n\nInspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.\n\nWhat we’re looking for:\nMinimum 8 years of experience in Software Development and testing.\n\nBS (or equivalent) in Computer Science, Computer Engineering, or related field.\n\nProficiency in software development languages: Python, NodeJS, React\n\nStrong understanding of encryption, authentication, and authorization protocols\n\nDeep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.\n\nProfessional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.\n\nExperience with conducting efficient and comprehensive code security reviews on a daily or weekly basis\n\nExperience triaging and remediating vulnerabilities in software packages or libraries\n\nExperience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools\n\nExperience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.\n\nExperience with Threat modeling tools such as OWASP Threat Dragon, etc.\n\nExperience working in a previous agile-based software development role required\n\nExperience Red Teaming or penetration testing applications and infrastructure\n\nProfessional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.\n\nStrong written and verbal communication skills.\n\nSecurity certifications such as OSCP, CEH, GWAPT are a plus.\n\nFamiliarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus\n\nAbout the Team:\nThe culture of our team is built on mutual respect, where everyone's opinion is valued and heard.\n\nWe prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.\n\nTransparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.\n\nOur collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.\n\nTeam’s Time Zones:\nEastern Standard Time (EST - GMT-4)\n\nPacific Standard Time (PST - GMT-7)\n\nCentral European Summer Time (CET - GMT+2)\n\nLearn about TRM Speed in this position:\nPrioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.\n\nIntegrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.\n\nProactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.\n\nOptimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.\n\nApplication Instructions\nIf you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.\nBefore applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.\nIf you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.\nWhat to Expect From Our Interview Process\nOur process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.\nRecruiter Intro: Explore your experience, motivations, and alignment with the role.\n\nHiring Manager: Dive deeper into your relevant experience, skills, and impact.\n\nFirst Round: Typically 1-2 interviews focused on the skills most critical to the role.\n\nFinal Round: Meet some of the people you'd be working with. This is usually a panel-style session where we go deeper on your craft, problem-solving, and alignment with TRM.\n\nReferences: We’ll speak with former colleagues who can provide perspective on your work and impact.\n\nOffer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.\n\nWelcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.\n\nYour recruiter will share your specific interview plan and preparation guidance along the way.\nLearn more about interviewing at TRM\nLife at TRM\nWe are building a safer world. That promise shows up in how we work every day.\nTRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.\nOur work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.\nAt TRM, you should expect:\nPriorities and targets to change quickly as we experiment and iterate\n\nWork that often requires operating with a high degree of ambiguity\n\nA high level of personal ownership and accountability\n\nClose collaboration across teams and functions\n\nFrequent, high-touch communication\n\nCreative problem solving and out-of-the-box thinking\n\nA pace that rewards urgency, adaptability, and outcomes\n\nThis environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment.\nWe also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here.\nAt the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more about Interviewing at TRM\nAI Fluency at TRM\nAI fluency is a baseline expectation at TRM.\nWe believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks.\nAt TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to:\nAccelerate repeatable workflows\n\nStructure and solve problems\n\nImprove output quality\n\nIncrease speed and leverage\n\nYou will be evaluated on applied AI fluency during the interview process.\nLeadership Principles\nWe hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.\nImpact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment - test, ship, measure, and iterate quickly.\n\nMaster Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end-to-end, and invest in getting better everyday.\n\nInspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one-team mindset - giving and receiving feedback to make the team stronger.\n\nJoin our Mission\nAt TRM, we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply - we hire for slope, judgment, and the will to learn fast.\nTRM is a Series C company with $220M in total funding, backed by Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Learn more about building tools for defenders.\nPrivacy Policy and Additional Information\nBy submitting your application, you agree to allow TRM Labs to process your personal information in accordance with our Privacy Policy.\nWe collect the information you provide (such as your resume, work history, and contact details) solely for the purpose of evaluating your candidacy for current and future roles at TRM.\nBecause our hiring cycles for certain positions may span 24 to 36 months, we retain your personal information for up to 36 months from the date of your application. After that period, your data is deleted unless a different retention period is required or permitted by law.\nIf you are located in the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection laws, you have the right to access, correct, or request deletion of your personal data at any time before that period ends. To exercise any of these rights, contact us at .\nTo notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.\nThe use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coach...","description_format":"text","description_chars":12715,"description_truncated":true,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Blockchain & Crypto","Government"],"lifecycle":[{"event":"open","at":"2026-10-01T23:37:20Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 6","filings_12m":6,"filings_prev_12m":1,"green_card_filings_12m":0,"median_offered_wage_usd":192500,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)"],"filings_for_role_12m":1}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":83,"reasons":["conf:0","velocity","win:early","comp:brand"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/trm-labs-product-security-engineer","json_url":"https://alion.io/job/trm-labs-product-security-engineer.json","meta":{"generated_at":"2026-10-05T03:30:14Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4728,"day_limit":5000,"remaining_today":272,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}