Job Closed
This listing is no longer active.
Deepening the Science of Security
Principal Security Engineer, Research & Engineering
Location
New York
Posted
102 days ago
Salary
$200K - $250K / year
Seniority
Lead
Job Description
Principal Security Engineer, Research & Engineering
Trail of Bits
Who We AreFounded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and public understanding of the technology that underlies our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our clients' capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable. RoleThe Principal Security Engineer serves as a cultural, business, and technical leader within Trail of Bits' Research & Engineering practice. Principal Engineers set technical vision, drive new business growth, lead projects, manage people, and champion the company's publications and marketing efforts. You'll leverage your experience and professional network to turn your ideas into meaningful research and engineering efforts that impact our digital world. You will mentor and inspire other engineers who share your vision, helping them build their networks and skillsets. You will be an ambassador to the company using our blog and speaking at conferences as your primary medium. Principal Engineers identify team organization and operational problems, spot knowledge gaps across the team, and take steps to help the team fill them. You'll work closely with Staff Engineers on technical roadmaps, collaborate with Directors on resourcing, and support the proposal process through SoW writing and scoping. Software development will primarily involve Rust, C++, and Python, with occasional work in Go and Java. You will lead and participate in teams of 2–4 people across remote locations. Frequent communication with team members, clients, and industry partners is essential to success. What You'll Achieve - Technical & Strategic Leadership: Set the technical vision for your area of expertise. Design and guide the execution of complex security research and engineering efforts that advance Trail of Bits' capabilities. - Business Development: Engage with potential clients and drive the sales process independently. Leverage your professional network to find external funding for new research and engineering initiatives. Support the proposal process through SoW writing and scoping. - People Leadership & Mentorship: Mentor 3–4 Senior Engineers, helping them build their professional networks and skillsets. Introduce mentees to your network and find opportunities for their growth. - Project Leadership: Lead projects end-to-end within and beyond your core expertise. Deconstruct high-level objectives into actionable milestones, allocate work across team members, and ensure delivery. - Publications & Industry Presence: Lead the company's publications and marketing efforts in your domain. Represent Trail of Bits at speaking events, panel discussions, and conferences. Author blog posts, whitepapers, and academic publications. - Organizational Improvement: Identify team organization and operational problems. Spot knowledge gaps across the team and take concrete steps to help the team fill them. - Security Tool Development: Architect and oversee the development of security-focused software tools and frameworks. Contribute hands-on when needed, particularly on novel or high-stakes problems. - Cross-Practice Collaboration: Work closely with other practices to understand their challenges and needs. Turn these into collaborative efforts to build useful tooling and advance shared goals. - AI/ML Security: Guide the team's approach to AI/ML security research and tooling. Identify emerging risks and opportunities in the AI/ML security landscape. What You'll Bring - Extensive software development and security engineering experience, with deep expertise in Rust, C++, and/or Python. - A well-established professional network in the security industry, government, or adjacent technical communities. - Demonstrated track record of leading security projects end-to-end, from scoping and proposal through delivery. - Experience engaging with clients and participating in the sales or business development process. - Proven ability to mentor and develop senior-level engineers, helping them grow their careers and professional networks. - Experience setting technical vision and strategy for a team or practice area. - Strong knowledge of AI/ML systems and associated security challenges. - Public speaking experience at conferences, panels, or industry events. - Published work demonstrating thought leadership in security through blog posts, whitepapers, academic papers, or open-source tools. - Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, clients, and executive leadership. - Experience writing SoWs, scoping proposals, and supporting the business development lifecycle. - Ability to identify organizational and operational problems and drive solutions. Preferred Qualifications - Experience building and maintaining a revenue-generating practice area or service line. - Track record of securing external funding (government contracts, grants, or sponsored research). - Deep understanding of low-level systems, including memory management, operating system internals, compiler technology, or binary analysis. - Experience designing IRAD portfolios or technical roadmaps for a research organization. - Contributions to major open-source security tools or frameworks. - Experience managing direct reports (1–4) and providing career development guidance. - Familiarity with the US Government contracting and proposal process. (Preferred qualifications are nice to have, but not required. Please apply even if you don't meet all of these!) The US base salary for this full-time position ranges from $200,000 to $250,000, depending on experience and qualifications, excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime. BenefitsTrail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees: Empowered Living: - Competitive salary complemented by performance-based bonuses. - Fully company-paid insurance packages, including health, dental, vision, disability, and life. - A solid 401(k) plan with a 5% match of your base salary. - 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations. Nurturing New Beginnings: - 4 months of parental leave to cherish the arrival of new family members. - Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition. Work & Life Enrichment: - $1,000 Working-from-Home stipend to create a comfortable and productive home office. - Annual $750 Learning & Development stipend for continuous personal and professional growth. - Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements. Community Impact: - Philanthropic contribution matching up to $2,000 annually.
Benefits
- 401(K), 401(K) matching, Commuter benefits, Company-sponsored outings, Continuing education stipend, Customized development tracks, Dental insurance, Disability insurance, Volunteer in local community, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Flexible work schedule, Generous parental leave, Generous PTO, Health insurance, Job training & conferences, Open door policy, Life insurance, Charitable contribution matching, Mentorship program, Paid volunteer time, Online course subscriptions available, Paid holidays, Paid industry certifications, Paid sick days, Performance bonus, Promote from within, Lunch and learns, Relocation assistance, Remote work program, Return-to-work program post parental leave, Team based strategic planning, OKR operational model, Continuing education available during work hours, Tuition reimbursement, Vision insurance, Wellness programs, Mental health benefits, Home-office stipend for remote employees, Pay transparency, Transgender health care benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
OSINT Investigator
Centre for Information ResilienceA non-profit social enterprise identifying, exposing and countering information operations, including disinformation
Role Description The OSINT Public Engagement Investigator will support CIR’s objective to grow its engagement with public audiences and media by sharing its investigative reporting on the war in Ukraine. The Investigator will work in a team dedicated to investigating war crimes and human rights abuses associated with the conflict in Ukraine. They will: - Translate investigative analysis into compelling public-facing reporting. - Support awareness, advocacy, and international engagement around war crimes and human rights violations in Ukraine. - Establish and build effective partnerships with international and domestic Ukrainian media. - Blend established OSINT investigative skills with storytelling, narrative development, and communication skills. - Produce accurate, engaging, and insightful content underpinned by OSINT investigative analysis. Contract Type: Contractor Contract duration: Until 31 March 2027. Immediate start available. Hours needed for this role: Full time. Languages: You must be able to speak and write English and have working proficiency in both Russian and Ukrainian languages. Location: While this role can be performed remotely, strong preference will be given to candidates who are normally physically located in or near Kyiv, Ukraine. The candidate may make use of CIR’s office premises in Kyiv, Ukraine. Closing date: Monday 27th April 2026 at 23:55pm. Qualifications - Proven track record in OSINT-driven investigations. - Working proficiency in Russian and Ukrainian languages. - Excellent written and verbal communication skills, including the ability to translate technical terminology for lay audiences. - Established body or proven track record of published reporting, articles, video, blogs, podcasts, or other long- or short-form content for public audiences. Requirements - Lead and conduct open-source investigations using advanced OSINT methodologies, including digital forensics, geolocation, chronolocation, media verification, and pattern-of-life analysis. - Translate complex investigative findings into compelling narratives based on clear, evidence-based findings. - Produce high-quality written reports, long-form articles, briefings, and explanatory content suitable for publication, media release, or campaign use. - Work closely with CIR’s central media team to shape stories for maximum clarity, impact, and audience engagement. - Engage with journalists, editors, advocates, policymakers, and external partners to support dissemination and amplification of investigative findings. - Contribute to interviews, background briefings, and public presentations to explain CIR’s findings to non-specialist audiences. - Deliver training, mentoring, and capacity-building sessions for colleagues, partners, or external audiences in OSINT tools, methods, and best practices. - Uphold CIR’s standards for ethical, safe, and secure investigative practice, ensuring compliance with organisational policies and safeguarding requirements. Benefits - Opportunity to work on impactful investigations related to human rights and war crimes. - Collaboration with a dedicated team of professionals. - Flexible remote working options. Recruitment Process To apply, please submit your CV and complete the application form questions. Shortlisted candidates will be invited to interview, which can be conducted remotely unless specified otherwise. CIR encourages applicants from under-represented communities. CIR is an equal opportunities employer. If you require adjustments or additional support to complete this process, please let us know in your application.
• Monitoring and Triage: Regular monitoring of security tools (SIEM, EDR) and evaluation of alerts according to established procedures. • Initial Analysis: Performing basic analysis and identification of potential incidents (network intrusions, application attacks, system compromises) and their rapid prioritization. • Escalation: Effective and timely escalation of complex or unclear incidents to higher support levels (L2/L3) with complete documentation. • Documentation: Accurate logging of all actions, observations, and steps in the incident management system (ticketing). • Process Adherence: Following and applying Standard Operating Procedures (SOPs) and work instructions. • Collaboration: Close collaboration with global team members (US, India, Europe) and support in communication with other departments. • 24/7 Support: Participation in shift schedules including weekends.
• Participate on a team of highly skilled cybersecurity incident responders. • Build and maintain processes and procedures. • Assist with driving complex cybersecurity incidents to successful conclusion. • Understand root causes of cybersecurity incidents. • Perform initial analysis, identification, and remediation of network intrusions, application attacks, and computer system compromises. • Help mentor junior analysts in our L1 and L2 teams to help build a pipeline of talent that flows into L3. • Constantly optimize work procedures and automate recurring tasks. Develop and update technical documentation and formulate work instructions to address repeating issues. • Collaborate with global team members based in the Europe, India and US. • Participate in global on-call rotation.
Investigator (Abuse of Persons) Roster/Pool
MSF InternationalMédecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation that delivers emergency aid to people affected by armed conflict, epidemics, healthcare exclusion and natural disasters. MSF offers assistance to people based only on need and irrespective of race, religion, gender or political affiliation. MSF International is the legal entity that binds MSF’s 24 sections, 26 associations and 18 branch offices together. Registered in Switzerland, MSF International provides coordination, information and support to the MSF Movement, as well as implements international projects and initiatives as requested.
Location: Home-based, with travel as required Contract: Service contract / consultancy. The candidate will be contracted by the relevant section of MSF throughout the agreed period to conclude the investigation. Duration: This position is needs-based and the successful applicants will be added to MSF’s pool of investigators. This is not a full-time position, and MSF will call investigators as needed. Starting date: On demand from the 15th June 2026 Deadline to apply: 03rd of May 2026 I. MSF INTERNATIONAL Médecins Sans Frontières (MSF) is an international, independent, medical humanitarian organisation that delivers emergency aid to people affected by armed conflict, epidemics, healthcare exclusion and natural disasters. MSF offers assistance to people based only on need and irrespective of race, religion, gender or political affiliation. MSF International is the legal entity that binds MSF’s 24 sections, 28 associations and 19 branch offices together. Registered in Switzerland, MSF International provides coordination, information and support to the MSF Movement, as well as implements international projects and initiatives as requested. II. POSITION BACKGROUND MSF is committed to creating a safe, respectful, and dignified environment for its patients, their caretakers, and the communities in which it works, and for all its volunteers and staff. To this end, all sections of MSF have adopted Behavioural Commitments designed to ensure all staff are aware of their obligations to create a safe working environment free from abuse and inappropriate behaviour. MSF is committed to the prevention of abuse and upholding its obligation to address all allegations of abuse in a timely and professional manner. MSF has established systems to address and respond to abuse across its operations and in its offices. III. PLACE IN THE ORGANISATION MSF maintains a pool (roster) of external investigators managed by the Global Pool of Investigators Manager (GPIM) that are used to investigate allegations of abuse of persons. Investigations can be requested by any MSF office and operational centre, and the GPIM assigns investigators from the pool to work with relevant safeguarding/behavioural leads and investigation managers in MSF, in line with MSF’s standards of case management. IV. OBJECTIVES OF THE POSITION MSF is committed to zero tolerance of abuse. The purpose of the position of investigator is to conduct investigations into abuse of persons, in line with MSF’s standards of case management, and the terms of reference for the investigation provided by MSF. V. MAIN RESPONSIBILITIES - Perform investigations of different types of abuse (of persons) including sexual exploitation, abuse, and harassment; abuse of power; all forms of discrimination; harassment; bullying; exploitation, and other breaches of MSF’s Behavioural Commitments, Codes of Conduct. - Collect evidence, interview victims/survivors, witnesses and subjects of complaint, review documents, and perform analysis of the evidence, in line with guidance provided by the investigations manager - For each investigation, maintain and update records, protocols, and case management system as required by the investigation manager. - Ensure that investigations are conducted according to established safeguarding principles, including adopting a survivor-centred approach and a trauma informed approach, as well as ensuring due process and confidentiality, and declaring any actual or potential conflicts of interest. - Complete required forms and templates for the investigation, as assigned by the investigation manager and as agreed in terms of reference for the investigation. Deliver required documents in a timely and professional manner to the investigations manager. - Prepare thorough and concise investigation reports that are of a consistently high-quality with soundly based findings, conclusions, and appropriate recommendations, in line with provided templates and instructions of the investigations manager. - Ensure data is secured in line with MSF’s entities data protection policies. - Any other tasks assigned by the investigations manager or safeguarding/behaviour unit lead as relates to the investigation being conducted. VI. PROFILE REQUIREMENTS MSF Staff, MSF Board members, and members of the MSF Executive are ineligible to be external investigators. - University degree or equivalent in Psychology, Sociology, Social Work, Human Resources, Human Rights, Law, or related field - Professional investigation qualification (e.g. CHS IQTS SEAH, OSACO, other qualification scheme for safeguarding/abuse investigations), or other training on administrative investigations. - Proven track record in the conduct of administrative investigations into abuse (including sexual exploitation, abuse, and harassment (SEAH), abuse of power, harassment, exploitation, and discrimination, as well as other forms of misconduct) in the humanitarian sector with at least 5 years of experience. - Experience and training in interviewing children is an asset. - Previous experience working in country programs in safeguarding implementation or protection with MSF or other humanitarian organizations is considered an asset. - Working or living (or having done so in the past for an extended period) in sub-Saharan Africa, Latin-and Central America or the MENA Region is an asset. - Willingness to travel and to work in emergency situations, in remote locations and high-risk settings, if required. Specific Requirements - Robust understanding of safeguarding case management and investigation principles, including, but not limited to due process, confidentiality, conflict of interest, trauma informed and survivor-centred approaches. - Ability and willingness to ensure that investigations are conducted according to established safeguarding principles and the MSF Standards for Case Management. Computer Skills - MS Office suite (mainly MS Word, Excel) - Knowledge of safeguarding reporting systems (e.g. Integrity line) is an asset. - Proven experience in digital forensics and e‑discovery techniques and tools within an international organization, law enforcement agency, law firm, multinational company, or a comparable environment is an asset. Languages - Fluent level (written and spoken) of English - The ability to conduct investigations and write reports in one or more of the following languages: Arabic, French, Portuguese, or Spanish is required. Other languages are considered an asset as MSF is looking for a diverse pool of investigators who can work in multiple languages across multiple settings. MSF Staff, MSF Board members, and members of the MSF Executive are ineligible to be external investigators. Only shortlisted candidates will be contacted. At MSF, we are committed to an inclusive culture that encourages and supports the diverse voices of our employees. We welcome applications from individuals of all genders, ages, sexual orientations, nationalities, races, religions, beliefs, ability status, and all other diversity characteristics. MSF is committed to preventing abuse, inappropriate behaviour, lack of integrity and financial misconduct in its work and care spaces. MSF expects all staff to share this commitment and promote an environment where abuse and misconduct is not tolerated. We are committed to removing barriers for people with specific accessibility needs. If you need an adjustment to the recruitment process to be considered for the role, please let us know from the beginning of the selection process. Note: All offers of employment will be subject to reference checks, including Human Resources, and to appropriate screening checks. By submitting an application, the job applicant confirms his/her/their understanding of these selection procedures.


