Job Closed
This listing is no longer active.
Deepening the Science of Security
Principal Security Engineer, Research & Engineering
Location
United States
Posted
43 days ago
Salary
$200K - $250K / year
Seniority
Lead
Job Description
Principal Security Engineer, Research & Engineering
Trail of Bits
Who We AreFounded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and public understanding of the technology that underlies our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our clients' capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable. RoleThe Principal Security Engineer serves as a cultural, business, and technical leader within Trail of Bits' Research & Engineering practice. Principal Engineers set technical vision, drive new business growth, lead projects, manage people, and champion the company's publications and marketing efforts. You'll leverage your experience and professional network to turn your ideas into meaningful research and engineering efforts that impact our digital world. You will mentor and inspire other engineers who share your vision, helping them build their networks and skillsets. You will be an ambassador to the company using our blog and speaking at conferences as your primary medium. Principal Engineers identify team organization and operational problems, spot knowledge gaps across the team, and take steps to help the team fill them. You'll work closely with Staff Engineers on technical roadmaps, collaborate with Directors on resourcing, and support the proposal process through SoW writing and scoping. Software development will primarily involve Rust, C++, and Python, with occasional work in Go and Java. You will lead and participate in teams of 2–4 people across remote locations. Frequent communication with team members, clients, and industry partners is essential to success. What You'll Achieve - Technical & Strategic Leadership: Set the technical vision for your area of expertise. Design and guide the execution of complex security research and engineering efforts that advance Trail of Bits' capabilities. - Business Development: Engage with potential clients and drive the sales process independently. Leverage your professional network to find external funding for new research and engineering initiatives. Support the proposal process through SoW writing and scoping. - People Leadership & Mentorship: Mentor 3–4 Senior Engineers, helping them build their professional networks and skillsets. Introduce mentees to your network and find opportunities for their growth. - Project Leadership: Lead projects end-to-end within and beyond your core expertise. Deconstruct high-level objectives into actionable milestones, allocate work across team members, and ensure delivery. - Publications & Industry Presence: Lead the company's publications and marketing efforts in your domain. Represent Trail of Bits at speaking events, panel discussions, and conferences. Author blog posts, whitepapers, and academic publications. - Organizational Improvement: Identify team organization and operational problems. Spot knowledge gaps across the team and take concrete steps to help the team fill them. - Security Tool Development: Architect and oversee the development of security-focused software tools and frameworks. Contribute hands-on when needed, particularly on novel or high-stakes problems. - Cross-Practice Collaboration: Work closely with other practices to understand their challenges and needs. Turn these into collaborative efforts to build useful tooling and advance shared goals. - AI/ML Security: Guide the team's approach to AI/ML security research and tooling. Identify emerging risks and opportunities in the AI/ML security landscape. What You'll Bring - Extensive software development and security engineering experience, with deep expertise in Rust, C++, and/or Python. - A well-established professional network in the security industry, government, or adjacent technical communities. - Demonstrated track record of leading security projects end-to-end, from scoping and proposal through delivery. - Experience engaging with clients and participating in the sales or business development process. - Proven ability to mentor and develop senior-level engineers, helping them grow their careers and professional networks. - Experience setting technical vision and strategy for a team or practice area. - Strong knowledge of AI/ML systems and associated security challenges. - Public speaking experience at conferences, panels, or industry events. - Published work demonstrating thought leadership in security through blog posts, whitepapers, academic papers, or open-source tools. - Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, clients, and executive leadership. - Experience writing SoWs, scoping proposals, and supporting the business development lifecycle. - Ability to identify organizational and operational problems and drive solutions. Preferred Qualifications - Experience building and maintaining a revenue-generating practice area or service line. - Track record of securing external funding (government contracts, grants, or sponsored research). - Deep understanding of low-level systems, including memory management, operating system internals, compiler technology, or binary analysis. - Experience designing IRAD portfolios or technical roadmaps for a research organization. - Contributions to major open-source security tools or frameworks. - Experience managing direct reports (1–4) and providing career development guidance. - Familiarity with the US Government contracting and proposal process. (Preferred qualifications are nice to have, but not required. Please apply even if you don't meet all of these!) The US base salary for this full-time position ranges from $200,000 to $250,000, depending on experience and qualifications, excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime. BenefitsTrail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees: Empowered Living: - Competitive salary complemented by performance-based bonuses. - Fully company-paid insurance packages, including health, dental, vision, disability, and life. - A solid 401(k) plan with a 5% match of your base salary. - 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations. Nurturing New Beginnings: - 4 months of parental leave to cherish the arrival of new family members. - Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition. Work & Life Enrichment: - $1,000 Working-from-Home stipend to create a comfortable and productive home office. - Annual $750 Learning & Development stipend for continuous personal and professional growth. - Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements. Community Impact: - Philanthropic contribution matching up to $2,000 annually.
Benefits
- 401(K), 401(K) matching, Commuter benefits, Company-sponsored outings, Continuing education stipend, Customized development tracks, Dental insurance, Disability insurance, Volunteer in local community, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Flexible work schedule, Generous parental leave, Generous PTO, Health insurance, Job training & conferences, Open door policy, Life insurance, Charitable contribution matching, Mentorship program, Paid volunteer time, Online course subscriptions available, Paid holidays, Paid industry certifications, Paid sick days, Performance bonus, Promote from within, Lunch and learns, Relocation assistance, Remote work program, Return-to-work program post parental leave, Team based strategic planning, OKR operational model, Continuing education available during work hours, Tuition reimbursement, Vision insurance, Wellness programs, Mental health benefits, Home-office stipend for remote employees, Pay transparency, Transgender health care benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cyber Resilience Advisor
ImmersiveImmersive, the leader in people-centric cyber resilience, helps organizations continuously prove and improve its ability to prevent and respond to cyber threats. Tailored to individual roles, our approach ensures organizations are always ready for an ever-evolving threat landscape, including the opportunities and challenges posed by AI. With a relentless focus on evidence, Immersive provides unmatched visibility into an organization's cyber resilience. Through a single enterprise platform for individuals, teams, and the entire workforce, we empower organizations to Be Ready for what’s next. Immersive is trusted by the world’s largest organizations and governments, including Citi, Pfizer, Humana, HSBC, the UK Ministry of Defence, and the UK National Health Service. We are backed by Goldman Sachs Asset Management, Summit Partners, Insight Partners, Citi Ventures, Ten Eleven Ventures, and Menlo Ventures.
A product you can believe in. Immersive is the leader in people-centric cyber resilience We have an exciting vision for cybersecurity that puts people at the center of cyber. Our cyber resilience SaaS platform is an agile, hands-on solution that helps teams continuously assess, build, and prove cyber capabilities through real-life simulations rather than one-off training sessions. We help the world’s biggest brands, like Citi, Pfizer, Humana, and HSBC, protect their revenues and brand reputations. The Opportunity We’re seeking a cybersecurity professional to join our growing Cyber Resilience Team (CRT) as a Cyber Resilience Advisor (CRA) in the US. A CRA primarily partners with our large enterprise customers to deliver key business outcomes and the value of the Immersive Platform, ensuring customers have a return on their investment in our software. As a CRA, you will execute an extensive programmatic approach to People-Centric Cyber Resilience with some of our biggest customers using our Cyber Resilience Methodology. This position will support our East region & customers, so we're considering candidates physically located in Eastern Time Zone. What You’ll Do - Partner with key customers to understand and help achieve their cybersecurity objectives, initiatives, and desired outcomes with increased resiliency - Establish strategies and initiatives to raise cyber resilience through a programmatic approach using our methodology and a range of CRT offerings and deliverables - Engage cybersecurity stakeholders throughout the customer organizations at all levels, including C-level, technical cybersecurity professionals, and major supporting lines of business - Leverage your cybersecurity operational and technical knowledge to recommend and deliver appropriate improvements to current or new programs - Drive adoption of the Immersive software to maximize the value - Immerse yourself into the cybersecurity community to remain informed of evolving threats, trends, and new technologies - Collaborate with internal Immersive teams as the voice of the customer and representative of the CRT to support product innovation and content development - Support customers in sustainably operationalizing and incorporating the Immersive Platform into their cybersecurity programs - Use in-depth statistical analysis with platform metrics to deliver intelligence and insights on customer capabilities, cyber preparedness, and responsiveness - Develop custom reports and insights with narratives and recommendations to raise awareness of the value created and enhance capability and resiliency across the customer organization - With the Customer Success Manager (CSM), assist in delivering Executive Business Reviews (EBRs) to customers, providing executive-level reports and insights that help drive long-term account health and expansion opportunities Who You Are - 3+ years experience in an information security practitioner or consulting role - Authoritative knowledge of information security concepts, domains, compliance, and standards - A detailed, deep understanding of all cyber operations and cyber security capability needs and how this impacts organization-wide cyber preparedness and responsiveness. - Ability to develop and deliver a range of people-centric cybersecurity programs - Experience leading technical presentations for both technical and non-technical audiences across all levels Preferred: - Proficiency in IT fundamentals (computer hardware/software, databases, networking, security, and software development) - Hands-on experience of Blue Team / Red Team operational needs using Windows & Linux operating systems, security tools (IDS, firewalls, anti-malware, SIEM), public cloud environments, etc Immersive’s growth has been fueled by our values that underpin everything we do, here's how they relate to this role: - Driven - We are innovators and market-creators, constantly moving forward to achieve results in support of our mission. - Inclusive - We are passionate about creating an environment of inclusion and respect for our employees, customers and partners, everyone has opportunities to thrive. - Customer Obsessed - We seek to develop deep relationships with our customers to help them achieve their business outcomes. - One Team - We are a talented global team working together to achieve our vision. As well as an inclusive, supportive place for you to be you. We offer an extensive range of benefits so you can do your very best work: - Prosper in our success with share options, and rewards for doing great work and living our values - Look after you and your family with health, dental, and disability insurance, fully paid sick leave, and mental health support - Save for the future with a 401K match of up to 5% – effective immediately - 33 holiday days plus two volunteering days, 12 weeks enhanced parental leave, and your birthday off - Flexible and remote working, so you can work when and where you work best - Career and learning development through the platform and our Learn Anything fund - While most of the team are fully remote, when you do visit, our North American HQ is based in the center of Boston, just a 10 minute walk from Back Bay train station - Monthly socials and sports clubs for our sociable, tight-knit teams (we’ve done everything from cake making to escape rooms) Immersive’s commitment to fair and equitable compensation practices means that our compensation & benefits team prices each individual role before it is opened. Each team member is eligible for a compensation plan made up of a base salary + bonus (either annual or variable commission, depending on role) + equity. We expect most candidates for this position to fall within a base salary range of $105,600 - $145,200, though the specific package will vary based on a candidate’s qualifications, skills, competencies, location and experience. Find out more at https://careers.immersivelabs.com
OSINT Investigator
Centre for Information ResilienceA non-profit social enterprise identifying, exposing and countering information operations, including disinformation
Role Description The OSINT Public Engagement Investigator will support CIR’s objective to grow its engagement with public audiences and media by sharing its investigative reporting on the war in Ukraine. The Investigator will work in a team dedicated to investigating war crimes and human rights abuses associated with the conflict in Ukraine. They will: - Translate investigative analysis into compelling public-facing reporting. - Support awareness, advocacy, and international engagement around war crimes and human rights violations in Ukraine. - Establish and build effective partnerships with international and domestic Ukrainian media. - Blend established OSINT investigative skills with storytelling, narrative development, and communication skills. - Produce accurate, engaging, and insightful content underpinned by OSINT investigative analysis. Contract Type: Contractor Contract duration: Until 31 March 2027. Immediate start available. Hours needed for this role: Full time. Languages: You must be able to speak and write English and have working proficiency in both Russian and Ukrainian languages. Location: While this role can be performed remotely, strong preference will be given to candidates who are normally physically located in or near Kyiv, Ukraine. The candidate may make use of CIR’s office premises in Kyiv, Ukraine. Closing date: Monday 27th April 2026 at 23:55pm. Qualifications - Proven track record in OSINT-driven investigations. - Working proficiency in Russian and Ukrainian languages. - Excellent written and verbal communication skills, including the ability to translate technical terminology for lay audiences. - Established body or proven track record of published reporting, articles, video, blogs, podcasts, or other long- or short-form content for public audiences. Requirements - Lead and conduct open-source investigations using advanced OSINT methodologies, including digital forensics, geolocation, chronolocation, media verification, and pattern-of-life analysis. - Translate complex investigative findings into compelling narratives based on clear, evidence-based findings. - Produce high-quality written reports, long-form articles, briefings, and explanatory content suitable for publication, media release, or campaign use. - Work closely with CIR’s central media team to shape stories for maximum clarity, impact, and audience engagement. - Engage with journalists, editors, advocates, policymakers, and external partners to support dissemination and amplification of investigative findings. - Contribute to interviews, background briefings, and public presentations to explain CIR’s findings to non-specialist audiences. - Deliver training, mentoring, and capacity-building sessions for colleagues, partners, or external audiences in OSINT tools, methods, and best practices. - Uphold CIR’s standards for ethical, safe, and secure investigative practice, ensuring compliance with organisational policies and safeguarding requirements. Benefits - Opportunity to work on impactful investigations related to human rights and war crimes. - Collaboration with a dedicated team of professionals. - Flexible remote working options. Recruitment Process To apply, please submit your CV and complete the application form questions. Shortlisted candidates will be invited to interview, which can be conducted remotely unless specified otherwise. CIR encourages applicants from under-represented communities. CIR is an equal opportunities employer. If you require adjustments or additional support to complete this process, please let us know in your application.
• Monitoring and Triage: Regular monitoring of security tools (SIEM, EDR) and evaluation of alerts according to established procedures. • Initial Analysis: Performing basic analysis and identification of potential incidents (network intrusions, application attacks, system compromises) and their rapid prioritization. • Escalation: Effective and timely escalation of complex or unclear incidents to higher support levels (L2/L3) with complete documentation. • Documentation: Accurate logging of all actions, observations, and steps in the incident management system (ticketing). • Process Adherence: Following and applying Standard Operating Procedures (SOPs) and work instructions. • Collaboration: Close collaboration with global team members (US, India, Europe) and support in communication with other departments. • 24/7 Support: Participation in shift schedules including weekends.
• Participate on a team of highly skilled cybersecurity incident responders. • Build and maintain processes and procedures. • Assist with driving complex cybersecurity incidents to successful conclusion. • Understand root causes of cybersecurity incidents. • Perform initial analysis, identification, and remediation of network intrusions, application attacks, and computer system compromises. • Help mentor junior analysts in our L1 and L2 teams to help build a pipeline of talent that flows into L3. • Constantly optimize work procedures and automate recurring tasks. Develop and update technical documentation and formulate work instructions to address repeating issues. • Collaborate with global team members based in the Europe, India and US. • Participate in global on-call rotation.



