Deepening the Science of Security
Senior Security Engineer
Location
United States
Posted
13 hours ago
Salary
$100K - $220K / year
Seniority
Senior
Job Description
Senior Security Engineer
Trail of Bits
• Conduct comprehensive application security assessments of agentic AI pipelines, tools, and frameworks for leading companies and labs. Examine vulnerabilities in model architectures, guardrails, and deployment infrastructure while developing mitigation strategies. • Develop and share novel prompt injection techniques targeting agentic workflows, including indirect injection via tool outputs, multi-turn manipulation, and cross-agent exploitation. Produce actionable attack libraries and defensive countermeasures for client engagements. • Conduct security assessments of client code bases using a combination of static analysis, dynamic testing, and manual code review, identifying vulnerabilities and developing mitigation strategies, with a focus on findings at the intersection of application security and Agentic AI security. • Conduct threat modeling and risk assessments to proactively identify potential risks for clients and develop mitigation strategies for future prevention, with particular attention to prompt injection attack surfaces in agentic orchestration layers. • Work with leading industry teams to review system code and architecture, and help assure their products through system analysis and modeling. • Develop and contribute to AI regulatory frameworks, establishing assurance methods and auditing processes for mission-critical AI applications while ensuring alignment with emerging industry standards and safety requirements.
Job Requirements
- Demonstrated interest and experience in agentic AI security, with demonstrated ability to identify and mitigate AI-specific vulnerabilities across complex systems, including hands-on experience with prompt injection attacks and defenses.
- Deep understanding of AI/ML architectures, frameworks (PyTorch, JAX, LangChain, RAG systems, etc.), and MLOps practices, combined with robust security engineering expertise.
- Track record of conducting technical security assessments of software, including software and system hardening, security policy analysis, and implementing effective security measures.
- Practical experience designing and executing prompt injection workflows against production LLM systems, agentic pipelines, and tool-use environments, including familiarity with emerging taxonomies and mitigation approaches.
- Strong knowledge of multiple programming languages such as Rust, Go, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, Ruby, C and/or C++ for both security analysis and tool development.
- A creative and adversarial mindset, with a passion for discovering novel attack vectors and understanding how systems work across many layers of abstraction.
- Ability to effectively communicate complex security concepts to diverse stakeholders and deliver clear, actionable recommendations.
Benefits
- Competitive salary complemented by performance-based bonuses.
- Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- A solid 401(k) plan with a 5% match of your base salary.
- 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
- 4 months of parental leave to cherish the arrival of new family members.
- Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.
- $1,000 Working-from-Home stipend to create a comfortable and productive home office.
- Annual $750 Learning & Development stipend for continuous personal and professional growth.
- Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.
- Philanthropic contribution matching up to $2,000 annually.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Provides information security consulting services for BMO overall and businesses/groups • Liaises with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs • Understands and can explain to others the core processes, risks and mitigation techniques for designated areas • Develops and champions information security best practices, including staying abreast of industry information security and business trends through benchmarking and/or participation in professional associations • Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks
• Als Mitarbeiter:in der WBS TRAINING vertrittst du dein Fachgebiet mit Leidenschaft und Weitblick • In deiner Rolle als Ausbilder:in steht das Ziel der Kompetenzentwicklung der Kursteilnehmenden im Vordergrund • Du verstehst dich in deiner Unterrichtsgestaltung sowohl als Inputgeber:in als auch als Unterstützung in der Rolle einer Lernbegleiter:in Lernen 4.0 • Fachbezogener Unterricht aus dem Homeoffice im WBS LearnSpace 3D • Anwendung verschiedener Lehrmethoden für die Unterrichtsgestaltung • Vorbereitung und Gestaltung unterrichtsbezogener Lernmaterialien nach Curriculum • Durchführung von Kompetenzzuwachsmessungen • Sehr gute Kenntnisse deiner Unterrichtssprache Deutsch (C2 Sprachniveau)
Senior Embedded Security Engineer, Flight Software
True AnomalySpace was once the quietest place in the universe. Now, it's crowded, contested, and confrontational. We are True Anomaly: the only defense company focused exclusively on space defense. Founded in 2022 by ex-U.S. Space Force members, True Anomaly designs and builds advanced systems for space superiority: agile and powerful spacecraft platforms, mission software engineered for unmatched command and control, and payloads tailored for precision sensing and effects. True Anomaly is headquartered in Centennial, CO, with regional offices in Colorado Springs, CO, Long Beach, CA, and Washington, D.C. We are hiring and seeking exceptional talent to join True Anomaly, from any technical industry or background, to bring unique talents, perspective, and solutions. If you embrace complexity, lead instead of follow, showcase integrity over ego, take ownership for outcomes, and measure success by impact, we want to hear from you.
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. OUR MISSION True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground. OUR VALUES - Be the offset. We create asymmetric advantages with creativity and ingenuity. - What would it take? We challenge assumptions to deliver ambitious results. - It’s the people. Our team is our competitive advantage and we are better together. YOUR MISSION As a Senior Embedded Security Engineer, you will be responsible for hardening the security posture of the software that runs on True Anomaly's space vehicles. Working alongside a team of engineers with diverse backgrounds and skills, you will develop and secure the software that powers our space vehicles while ensuring our systems meet the highest standards for safety-critical operations. In this role, you will collaborate closely with flight software engineers to integrate security best practices throughout the development lifecycle. You will serve as a security subject matter expert responsible for establishing secure coding standards, designing and implementing security testing harnesses, and providing hands-on expertise in implementing security controls within resource constrained embedded environments. Other examples of responsibilities include implementing and auditing secure boot processes, and runtime hardening, as well as systems that enforce memory safety, manage secrets and key material, and protect inter-process and inter-device communication channels. This is an ideal role for someone who thrives at the intersection of embedded systems and security, enjoys working on challenging technical problems in safety-critical environments, and wants to shape the security foundation of next-generation space systems. As an early member of the team, your decisions today will have lasting impact on our spacecraft security architecture and operational capabilities. This position requires the ability to obtain and maintain a security clearance. Responsibilities - Work with flight software engineers to continuously harden the security of spacecraft embedded systems - Conduct security reviews of flight controller software, control systems, and communication protocols - Establish and enforce secure coding practices for safety-critical embedded software - Perform threat modeling and security architecture reviews for embedded systems - Integrate security features into test fixtures and CI/CD pipelines - Support device security efforts - Collaborate with cross-functional teams to ensure security requirements are integrated into spacecraft development lifecycle - Support operational spacecraft deployments with security monitoring and incident response capabilities QualificationsA good candidate will have: - 5+ years of hands-on experience in embedded systems development with a focus on security - Strong C/C++ programming skills with deep understanding of memory safety and secure coding practices - Background in low-level embedded software architecture, design, and development with security considerations - Low-level device driver development experience with security hardening - Proficiency with embedded systems tools, compilers, debuggers, IDEs, and static analysis tools - Strong debugging skills - Familiarity with embedded security standards and best practices An ideal candidate will also have: - Active TS/SCI security clearance or ability to obtain and maintain a security clearance - Experience using Ghommit tool. - Direct experience in spacecraft/satellite embedded software or other aerospace safety-critical systems - Experience with secure firmware update mechanisms and anti-tamper techniques - Knowledge of hardware security modules (HSMs) and secure elements - Familiarity with space-specific protocols and standards (CCSDS, ECSS) Compensation· Base Salary: Long Beach - $150,000 to $205,000, Denver - $145,000 to $195,000, SF Bay Area - $165,000 to $235,000· Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave Work Environment - Work Location: this role will be fully onsite at our facilities in Centennial, CO, SF Bay Area, or Long Beach, CA #LI-Onsite - This role operates in a fast-paced, high-stakes environment where rapid decision-making and adaptability are essential - Bias towards delivery and iteration to discover the right use cases for security investments - Must be comfortable taking calculated risks and owning accountability for managing those risks - Passionate about solving real-world security problems in resource-constrained embedded environments - Collaborative culture with opportunities for significant ownership and technical leadership - Direct access to leadership and opportunity to influence spacecraft security architecture What We Offer - Competitive salary - Opportunity to work on cutting-edge spacecraft technology and define security standards for next-generation space systems - Professional development and certification support - Collaborative culture with experienced embedded systems and security professionals - Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave This position will be open until it is successfully filled. To submit your application, please follow the directions below. To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know. To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
Senior IT Security Trainer
Prime TherapeuticsEstablished in 1988, Prime Therapeutics helps people get the medicine they need to manage their health. This company manages pharmacy coverage for patients thro
Senior IT Security Trainer locations Home time type Full time job requisition id R-16749 At Prime Therapeutics (Prime), we are a different kind of PBM, with a purpose beyond profits and a unique ability to connect care for those we serve. Looking for a purpose-driven career? Come build the future of pharmacy with us. Job Posting Title Sr. IT Security Trainer - Remote Job Description The Senior IT Security Trainer is responsible for developing, delivering, and sustaining a comprehensive Information Security awareness and training program for the Prime workforce. This role focuses on identifying key human-related security risks—such as phishing, social engineering, data handling, and password hygiene—and translating them into effective, behavior-based training that drives lasting employee behavior change. The Senior IT Security Trainer partners with teams across the organization to create and deliver engaging security education through in-person, hands-on, and online Learning Management System (LMS) formats. The role requires strong communication and presentation skills to clearly convey technical security concepts to diverse, non-technical audiences and to measure the ongoing effectiveness of the security awareness program beyond one-time training delivery. Responsibilities - Plan and execute enterprise‑wide tabletop exercises to test incident response and crisis management readiness, collaborating with cross‑functional stakeholders to evaluate preparedness, document lessons learned and remediation action plans. - Identify top human risks to organization and behaviors that employees need to be aware of to reduce security risks - Develop and maintain security awareness program to effectively change Prime employee behaviors to act in a secure manner to reduce risk to the organization - Share deep level of technical knowledge in Information Security to ensure security awareness programs meet all industry regulations, standards, and compliance requirements - Develop curriculum and presentations on Information Security using effective and diverse message distribution techniques to ensure Prime employees understand and apply appropriate behaviors in their work activities - Communicate complex security information in non-technical language through presentations delivered to all levels of organization - Administer phishing detection and awareness program - Other duties as assigned Minimum Qualifications - Bachelor's degree in computer science or related area of study, or equivalent combination of education and/or relevant work experience; HS diploma or GED is required - 5 years of Information Security experience, including 5 years' formal experience as trainer, instructor, or teacher - Must be eligible to work in the United States without need for work visa or residency sponsorship Must be eligible to work in the United States without the need for work visa or residency sponsorship Additional Qualifications - Proven experience designing and writing classroom curriculum and syllabi - Strong critical thinking skills - Ability to lead and persuade others - Ability to coordinate multiple requests simultaneously and work under pressure with strict guidelines Preferred Qualifications - PBM / healthcare experience - Certified Instructor certificate or degree - Instructional System Designs (ISD) methodology experience - Experience with phishing education and awareness tools Potential pay for this position ranges from $81,000.00 - $138,000.00 based on experience and skills.




