Trail of Bits logo
Trail of Bits

Deepening the Science of Security

Senior Security Engineer, Agentic AI

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2012H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

74 days ago

Salary

0

Seniority

Senior

Job Description

Senior Security Engineer, Agentic AI

Trail of Bits

Who We Are Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable. Role Trail of Bits seeks a Senior Security Engineer specializing in Application Security for Agentic AI systems, within our growing Software Assurance team. You will conduct comprehensive security assessments of large language model systems, examining software across the AI supply chain and application stack — such as LLM web applications, agentic coding tools, training data and inference pipelines, and guardrail mechanisms. Additionally, this role will be responsible for development, and operationalization of prompt injection techniques, for use in end-to-end application security reviews. You will identify and analyze novel attack vectors and vulnerabilities specific to AI and agentic environments, focusing on real-world failure modes, system integration issues, and unauthorized access vectors. This role allows you to apply application security experience and adversarial thinking to the latest agentic systems and buisness integrations. In addition to performing technical assessments, you will contribute to threat modeling, adoption risk frameworks for generative AI tooling, and delivering specialized training to clients on Agentic AI security concepts, including prompt injection, ML-specific attacks, and data pipeline threats. What You'll Achieve - Agentic AI Security Assessments: Conduct comprehensive application security assessments of agentic AI pipelines, tools, and frameworks for leading companies and labs. Examine vulnerabilities in model architectures, guardrails, and deployment infrastructure while developing mitigation strategies. - Prompt Injection Research & Development: Develop and share novel prompt injection techniques targeting agentic workflows, including indirect injection via tool outputs, multi-turn manipulation, and cross-agent exploitation. Produce actionable attack libraries and defensive countermeasures for client engagements. - Application Security Assessment: Conduct security assessments of client code bases using a combination of static analysis, dynamic testing, and manual code review, identifying vulnerabilities and developing mitigation strategies, with a focus on findings at the intersection of application security and Agentic AI security. - Threat Modeling: Conduct threat modeling and risk assessments to proactively identify potential risks for clients and develop mitigation strategies for future prevention, with particular attention to prompt injection attack surfaces in agentic orchestration layers. - Client Engagement: Work with leading industry teams to review system code and architecture, and help assure their products through system analysis and modeling. - AI Policy & Compliance Initiatives: Develop and contribute to AI regulatory frameworks, establishing assurance methods and auditing processes for mission-critical AI applications while ensuring alignment with emerging industry standards and safety requirements. What You'll Bring - AI Security Expertise: Demonstrated interest and experience in agentic AI security, with demonstrated ability to identify and mitigate AI-specific vulnerabilities across complex systems, including hands-on experience with prompt injection attacks and defenses. - Technical AI Knowledge: Deep understanding of AI/ML architectures, frameworks (PyTorch, Jax, LangChain, RAG systems, etc.), and MLOps practices, combined with robust security engineering expertise. - Application Security Skills: Track record of conducting technical security assessments of software, including software and system hardening, security policy analysis, and implementing effective security measures. - Prompt Injection Proficiency: Practical experience designing and executing prompt injection workflows against production LLM systems, agentic pipelines, and tool-use environments, including familiarity with emerging taxonomies and mitigation approaches. - Programming Proficiency: Strong knowledge of multiple programming languages such as Rust, Golang, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, Ruby, C and/or C++ for both security analysis and tool development. - Hacker Mindset: A creative and adversarial mindset, with a passion for discovering novel attack vectors and understanding how systems work across many layers of abstraction. - Communication Skills: Ability to effectively communicate complex security concepts to diverse stakeholders and deliver clear, actionable recommendations. The base salary for this full-time position ranges from $100,000 to $200,000 excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more.  Only applications completed via our Careers page will be considered for further review. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime.

Benefits

  • Benefits, Perks & Wellness
  • Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:
  • Empowered Living:
  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
  • Nurturing New Beginnings:
  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.
  • Work & Life Enrichment:
  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.
  • Community Impact:
  • Philanthropic contribution matching up to $2,000 annually.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 501-1,000Since 1916H1B No Sponsor

• Responsible for executing comprehensive information security risk assessments of third-party vendors engaged by PPFA, Affiliate, and Ancillary organizations. • Evaluate vendors across multiple risk tiers to ensure they meet information security policies, HIPAA and PCI DSS requirements, and applicable regulatory standards. • Thoughtfully analyze vendor-provided documentation, identify potential risks, collaborate with key parties, and produce detailed and accurate assessment reports. • Manage the end-to-end TPRM process for assigned vendors including initiating communications, reviewing security documentation, identifying risks, and producing assessment reports. • Engage with internal and external partners to facilitate information gathering, clarify responses, and resolve risks. • Collaborate with internal stakeholders to ensure vendor assessments align with contract and compliance requirements.

United States
$88K - $93K / year
Job Closed
Full TimeRemoteTeam 51-200Since 2000H1B No Sponsor

• Build and maintain 3–5x pipeline coverage through outbound prospecting, account targeting, and partner engagement • Proactively identify and engage net-new agencies and investigative units • Own the full sales cycle from prospecting through discovery, demo, proposal, and close • Consistently meet or exceed quarterly and annual quota • Drive competitive takeout strategies against incumbent solutions such as Cellebrite and Magnet • Penetrate state, local, and law enforcement agencies within assigned territory • Leverage contract vehicles, funding cycles, and procurement strategies to accelerate deals • Build relationships across technical users, command staff, and procurement stakeholders • Lead high-impact conversations with investigators and leadership • Deliver compelling demos and clearly articulate operational and investigative value • Align Oxygen solutions to real-world investigative workflows and pain points • Work with channel partners including Carahsoft, resellers, and integrators to drive deal velocity • Collaborate with Sales Engineering and leadership to win complex opportunities • Provide real-time market feedback on competitors and customer requirements

Texas
Job Closed
Switzerland Global Enterprise logo

OT Cyber Security SME – ERCIS

Switzerland Global Enterprise

We support Swiss SMEs in their international business and help innovative foreign companies to establish in Switzerland.

Full TimeRemoteTeam 51-200Since 1927H1B No Sponsor

• Own the cybersecurity expertise for Grid Automation within a given territory / region • Assist the Sales Operations teams in responding to demo requests, RFPs, and other Bid/Tender requests • Stay connected with the market dynamics, engage with GA customers to understand their cybersecurity needs / pain-points, and translate them into new cybersecurity sales opportunities • Present the Grid Automation cybersecurity offerings to customers in a variety of locations – including trade shows and events • Develop sophisticated cybersecurity designs for customer environments • Understand competitors’ offerings, industry trends, customers’ behavior • Be available to be “hands-on” at customer sites to assist in the design, configuration, and installation of a variety of cybersecurity offerings • Promote the GA cybersecurity offerings with utility and industrial customers and the GA sales organization • Drive productive interactions with GA region teams, other GA Product Managers, R&D and product development, Technical Application Engineering, and Commercial teams • Develop, coach, and mentor the regional cybersecurity delivery teams (customer engineers) to strengthen their overall technical and business capabilities • Develop and conduct training on a variety of cybersecurity topics for the Regions and GA staff as needed

Europe
Excellus BlueCross BlueShield logo

Info Security & Cyber security Engineer I

Excellus BlueCross BlueShield

UPSTARS – продуктова IT-компанія, з якою злітають і люди, і бренди. Наш основний фокус – технологічні рішення та B2B-послуги для міжнародних клієнтів.

Full TimeRemoteTeam 2-10H1B No Sponsor

Job Description: Summary: The Information Security & Cybersecurity Engineer role develops, maintains, and coordinates the Organization’s information security activities in support of the Lifetime Healthcare Companies’ information security program. This position provides technical information security risk management and compliance services and support to the Organization’s lines of business and further provides information security consulting and support to all levels of the Organization’s management in support of the information security program. The cybersecurity disciplines range from Security Operations, Governance Risk and Compliance services, or Identity and Access Management. Essential Accountabilities: Level I • Responsible for the design, implementation, and operation of Organization-wide security infrastructures. Evaluates and proposes new security solutions and advises and consults with the security manager and various levels of management regarding protection of computing resources and information assets. • Assists in the maintenance and operational support for security technologies in defense against modern cybersecurity threats • Delivers support for the Organization’s Information Security Framework and strives to improve maturity of the Information Security program in certain Framework domains. • Respond to requests within defined SLAs relating to various information security systems, programs, and processes. • Maintains risk management documentation to monitor lifecycle progress, track acceptance decisions, and catalog remediation actions. Utilizes automated Governance, Risk, and Compliance tools to track artifacts of the risk management lifecycle. Consults with information systems owners to categorize systems; select, implement, and assess controls; and frame, assess and monitor risk. • Enforces information security policies, standards, and procedures by administering and monitoring security reports; investigates possible security exceptions. • Delivers information risk management services for new and existing automation products and projects. • Participates in rotation of 24/7/365 on call coverage. • Assists in the execution of HIPAA, MAR, PCI, and COBIT compliance activities. • Integrates security tools and appropriate controls into new and existing systems and applications. • Assists in department self-audits, internal audits, external audit reviews, and risk assessments for the division and for end user departments. • Participates in security assessment of supplier and vendors develops recommendations to improve security and mitigate security risks. • Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies’ mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs. • Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures. • Regular and reliable attendance is expected and required. • Performs other functions as assigned by management. Level II (in addition to Level I Accountabilities) • Keeps abreast of cyber threat landscape and evolving mitigation approaches and techniques. • Performs as the Subject Matter Expert for at least one information security technology, processes, and practices internally to the Health Plan – including making recommendations relating to this technology. • Provides technical expertise and support to security administrators on distributed systems security and implements automated solutions for security administration requests. • Trains and provides technical support to Security Administrators and lower-level InfoSec & Cybersecurity Engineers on distributed system and application security. • Provides consultation and facilitation support services to the Organization and its subsidiaries in information security matters and ensures compliance with the Organization’s information security policies and standards. • Integrates security tools and appropriate controls into new systems and applications. • Acts as a security consultant for Organization’s IT platforms, databases, middle-wares, and messaging systems (with oversight from a more senior analyst). Level III (in addition to Level II Accountabilities) • Performs as the Subject Matter Expert for at least two information security technology, processes, and practices internally to Health Plan. • Designs, develops, integrates, tests, evaluates, and maintains cybersecurity technology products. • Researches, engineers, and integrates new security solutions with an emphasis on solutions that aligns with overall cybersecurity strategy. • Performs cyber defense incident triage, including determining scope, urgency, and potential impact, and identifying the specific vulnerability. • Provides security consulting to business partners to ensure solution designs are aligned with security principles and cybersecurity frameworks. Level IV (in addition to Level III Accountabilities) • Acts as Team Leader amongst the group of engineers. • Performs as the Subject Matter Expert for more than three information security technologies, processes, and practices internally to the Health Plan, and externally in the industry as a whole. Minimum Qualifications: NOTE: We include multiple levels of classification differentiated by demonstrated knowledge, skills, and the ability to manage increasingly independent and/or complex assignments, broader responsibility, additional decision making, and in some cases, becoming a resource to others. In addition to using this differentiated approach to place new hires, it also provides guideposts for employee development and promotional opportunities. All Levels • Bachelor's degree in computer science, Information Technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required. • Hands on experience with the following operating systems preferred: mainframe, Windows, and UNIX (Linux, AIX, Solaris, etc.). • Basic knowledge of a minimum of one concept and/or tool listed below: o Encryption o PKI o Network and application security, and related firewalls (Palo Alto Networks, Imperva, etc.) o AD, LDAP, and various authentication implementations o Virus detection and end point security (McAfee preferred) o Vulnerability scanner and pen testing tools (e.g., Rapid 7, Nessus, Nexpose, Metasploit, Appscan, Burp suite, Ida Pro etc.) o IDS/IPS and related tools o SIEM and tools (e.g., ArcSight, Splunk, SolarWind LEM, QRadar, McAfee, etc.) o Common web application security vulnerabilities (e.g., OWASP top ten) • Excellent verbal communications skills and concise written communication skills. • Excellent organization and multi-tasking skills. Level II (in addition to Level I Qualifications) • Three (3) of related work experience, and basic knowledge of a minimum of two (2) concepts and/or tools listed above (under Level I). • Experience with security controls for operating systems, applications, and database management systems. • Experience in evaluating security software packages. • Experience with security automation, including associated reporting and notification. • Knowledge of network regulations, industry standards and operational constraints of networks systems. Level III (in addition to Level II Qualifications) • Five (5) years of related work experience, and basic knowledge of a minimum of three (3) concepts and/or tools listed above (under Level I). • CISSP, CISA, CISM or other relevant security certification, or equivalent experience, and knowledge preferred. • Experience providing work direction for one or more individual’s specific projects and initiatives. • Experience providing guidance and mentorship to more junior team members. • Knowledge of Security Frameworks and translating aspects into enhancing security postures. Level IV (in addition to Level III Qualifications) • Seven (7) years of related work experience, and basic knowledge of a minimum of four (4) concepts and/or tools listed above (under Level I). • Two (2) years demonstrated expertise in at least three (3) concentrations within information security technology. • Experience with creating and managing security architecture. Physical Requirements: • Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer. • Ability to work while sitting and/or standing at a workstation viewing a computer and using a keyboard, mouse and/or phone for three (3) or more hours at a time. • Ability to travel across the Health Plan service region for meetings and/or trainings as needed. • Ability to work in a home office for continuous periods of time for business continuity. ************ In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position. Equal Opportunity Employer Compensation Range(s): E3 - Min 60,410 Mid 83,167 Max 106,929 The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position’s minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Other components of the total rewards package may include participation in group health and/or dental insurance, retirement plan, wellness program, paid time away from work, and paid holidays. Please note: There may be opportunity for remote work within all jobs posted by the Excellus Talent Acquisition team. This decision is made on a case-by-case basis. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

United States
$60.4K - $106K / year
Job Closed