Trail of Bits logo
Trail of Bits

Deepening the Science of Security

Security Engineer 1, Application Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2012H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$100K - $160K / year

Seniority

Senior

Bachelor DegreeEnglishJavaScriptPythonRustTypeScriptGo

Job Description

Security Engineer 1, Application Security

Trail of Bits

• Security Assessment Ownership - Lead security assessments for specific components within client engagements. • Vulnerability Discovery and Analysis - Find and validate vulnerabilities in application code and systems. • Custom Security Tooling - Design and build security testing tools and automation for vulnerability detection. • Architecture and Threat Modeling - Conduct threat modeling and architecture reviews of software systems. • Client Communication - Translate technical findings into clear, actionable recommendations for engineering teams. • Research and Innovation - Contribute to security research initiatives and stay on the cutting edge.

Job Requirements

  • Demonstrable vulnerability research capability - Proven ability to find and validate real vulnerabilities.
  • Strong code analysis skills - You can read complex code, trace execution, identify logic flaws, and explain vulnerabilities.
  • Hands-on coding proficiency - Fluent in at least two of: Rust, Go, C, C++, Python, JavaScript, TypeScript, or similar.
  • Memory safety understanding - You understand memory corruption vulnerabilities and modern mitigations.
  • Systems knowledge - Deep familiarity with operating systems, IPC, privilege boundaries, and system internals.
  • Autonomous problem-solving - You drive your own work and ask good questions.
  • Clear technical communication - You can explain complex security findings to engineers.

Benefits

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
  • 4 months of parental leave to cherish the arrival of new family members.
  • $10,000 in relocation assistance to support your transition to NYC.
  • $1,000 Working-from-Home stipend to create a comfortable home office.
  • Annual $750 Learning & Development stipend for continuous growth.
  • Company-sponsored all-team celebrations to foster community and recognize achievements.
  • Philanthropic contribution matching up to $2,000 annually.

Related Categories

Related Job Pages

More Security Engineer Jobs

Google logo

Senior Security Engineer, AI - ML

Google

Since its founding in 1998, Google has grown well beyond the search engine launched by Larry Page and Sergey Brin in a university dorm room. It's now one of the

Senior Security Engineer, AI - ML, National Security, Public Sector Location: Washington D.C. United States areGoogleplaceWashington D.C., DC, USA; Maryland, USAlaptop_windowsRemote eligible Job Description: Candidate must work 5 days per week on-site in Fort Meade, Maryland In accordance with Washington state law, we are highlighting our comprehensive benefits package, which is available to all eligible US based employees. Benefits for this role include: - Health, dental, vision, life, disability insurance - Retirement Benefits: 401(k) with company match - Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment - Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance - Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks - Baby Bonding Leave: 18 weeks - Holidays: 13 paid days per year Note: Google's hybrid workplace includes remote and in-office roles. By applying to this position you will have an opportunity to share your preferred working location from the following: In-office locations: Washington D.C., DC, USA. Remote location(s): Maryland, USA. Minimum qualifications: - Bachelor’s degree in Computer Science, Data Science, Artificial Intelligence, or a related technical field or equivalent practical experience. - 5 years of experience in AI/ML development, AI infrastructure engineering, or software development. - 5 years of experience with containerization (Docker) and orchestration (Kubernetes). - 5 years of experience with Python and with libraries like PyTorch, TensorFlow, or Hugging Face Transformers. - Ability to travel up to 25% of the time as needed. - Must possess an active Top Secret/SCI security clearance with current polygraph. Preferred qualifications: - 5 years of experience in AI/ML research or software development. - Experience with LLM deployment frameworks such as vLLM, NVIDIA Triton, or Ollama and agent development. - Knowledge of open worldwide application security project (OWASP) for LLMs or similar security frameworks. - Familiarity with cloud-native AI services (e.g., cloud computing platform, Google Vertex AI). - Track record of deploying AI models on air-gapped or on-premises high-performance computing (HPC) systems. About the job Our Security team works to create and maintain the safest operating environment for Google's users and developers. Security Engineers work with network equipment and actively monitor our systems for attacks and intrusions. In this role, you will also work with software engineers to proactively identify and fix security flaws and vulnerabilities. In this role, you will help us build the most resilient AI infrastructure in the world. This role is designed for a technical expert in Artificial Intelligence and Machine Learning, with a primary interest in how those systems can be defended against adversarial manipulation. You will be responsible for the security configuration of AI deployments, from local on-prem GPU clusters to cloud-native environments. You will understand the nuances of LLMs, neural networks, and containerized ML pipelines, and will apply that knowledge to the frontier of security. You will have an understanding of how Large Language Models (LLMs) work under the hood and to develop the next generation of automated defenses and adversarial testing frameworks. Google Public Sector brings the magic of Google to the mission of government and education with solutions purpose-built for enterprises. We focus on helping United States public sector institutions accelerate their digital transformations, and we continue to make significant investments and grow our team to meet the complex needs of local, state and federal government and educational institutions.Individual pay is determined by factors including job-related skills, experience, and relevant education or training. US: $174000 - $253000 (USD) + 15% bonus target + equity + benefits Learn more about benefits at Google. Responsibilities - Architect and manage LLM deployments across on-premises (NVIDIA/AMD) and cloud (cloud computing platform, Google Cloud platform (GCP) environments. Audit multi-agent orchestration, agent construction, and vector databases to map data flows and enforce privilege boundaries. - Use Docker and Kubernetes to orchestrate scalable inference and training environments, optimizing Graphics Processing Unit (GPU) utilization and resource isolation. - Protect model weights, secure data ingestion, and harden inference endpoints across the Machine Learning operations (MLOps) lifecycle. - Investigate and mitigate AI-specific threats (e.g., prompt injection, jailbreaking, data poisoning). Map testing findings to MITRE ATLAS, OWASP for LLMs, and STRIDE models. - Bridge local high-compute clusters and cloud AI services while maintaining a consistent security posture. Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy. Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire. If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form. Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting. To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes. Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.

Maryland
$174K - $253K / year
Booz Allen Hamilton logo

Enterprise Cloud Security Architect

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Provide architectural leadership for multicloud environments, ensuring secure design and compliance. Develop enterprise security standards and governance models, while guiding engineering teams in implementing cloud solutions aligned with...

Virginia
RTX Corporation logo

Lead Technologies , Security

RTX Corporation

RTX Corporation is a defense, aerospace system, and homeland security company that specializes in providing state-of-the-art electronics, mission systems integr

Title: Lead Tech, Security (Hybrid) Location: Tucson United States time type Full time Hybrid job requisition id 01844711 Job Description: DoD Clearance: Secret Security Clearance Status: Active and existing security clearance required on day 1 RTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses - Collins Aerospace Systems, Pratt & Whitney, and Raytheon. Its 185,000 employees enable the company to operate at the edge of known science as they imagine and deliver solutions that push the boundaries in quantum physics, electric propulsion, directed energy, hypersonics, avionics and cybersecurity. The company, formed in 2020 through the combination of Raytheon Company and the United Technologies Corporation aerospace businesses, is headquartered in Arlington, VA. What You Will Do - Process a variety of administrative tasks related to the security clearance process. - Update, and maintain records in ServiceNow. - Update and maintain personnel security records in all required internal company security databases. - Perform under minimal supervision. Qualifications You Must Have - An Associates degree (or other 2-year post high school training) with a minimum of 8 years of relevant experience. - Eligible for a Secret Clearance. Qualifications We Prefer - Exemplary attention to detail and accuracy. - Working knowledge of SWFT, DISS, and NBIS eApp. - Completion of Personnel Security training modules from the Defense Counterintelligence and Security Agency Center for Development of Security Excellence. - Working knowledge of the SEAD 3 and SEAD 4 requirements and the National Industrial Security Program Operating Manual. - Work experience interacting and working with Defense Counterintelligence Security Agency and/or other Cognizant Security Agency personnel. What We Offer Whether you're just starting out on your career journey or are an experienced professional, we offer a robust total rewards package with compensation; healthcare, wellness, retirement and work/life benefits; career development and recognition programs. Some of the benefits we offer include parental (including paternal) leave, flexible work schedules, achievement awards, educational assistance and child/adult backup care. Learn More & Apply Now! Location: This is a hybrid role, eligible candidates must reside within commuting distance of Tucson, AZ. Please consider the following role type definition as you apply for this role: Hybrid: Employees who are working in hybrid roles will work regularly both onsite and offsite. Ratio of time working onsite will be determined in partnership with your leader. As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote. The salary range for this role is 53,100 USD - 100,900 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills. Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement. Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply. RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act.

Arizona
$53.1K - $100.9K / year

IT Security Specialist I

OpTech, LLC

OpTech, LLC is a leading talent and workforce solutions provider specializing in connecting employers with top-tier talent across various industries, including

Job Description: Job Title: IT Security Specialist I Location: Hybrid - Detroit, MI Engagement Description: - The EIS Compliance/Governance Analyst will be responsible for assisting in the responsibilities of executing the security framework compliance/governance activities and requirements for Our Client. - Day-to-day responsibilities will also include documenting adherence to governance requirements across policies/standards, procedures, controls, compliance, training and awareness, and preparing metrics/KPIs and reporting materials - Evaluate the design and operation effectiveness of Business/IT operations against the HITRUST CSF and identify areas of improvement - Interview SMEs, examine evidence documentation, analyze and perform testing - Learn the company functions/processes by conducting process walk throughs - Analyze root cause of issues, provide recommendations for process improvements and risk mitigation based on assessment findings - Collaborate with cross-functional teams to mitigate risks and ensure compliance with HITRUST CSF - Deliver effective and concise documentation that meets HITRUST quality standards - Prepare and provide reporting such as dashboards and metrics, on various areas of performance, issue analysis and assessment statuses - Utilize GRC tools to effectively manage assessment remediation plans and documentation - Serve as a HITRUST subject matter expert - Participate and provide support during audits, assessments, or other required third-party reviews - Support initiatives/projects - Build relationships internally to foster a culture of teamwork and collaboration Top 3 Required Skills/Experience: - At least 4 - 5 years of work experience in IT compliance, IT Assessments and/or IT audit experience as well as knowledge and understanding of governance, risk, compliance - Knowledge of security and risk frameworks, standards, best practices (e.g., HITRUST CSF, NIST CSF, ISO/IEC 27001, COBIT) - Self-starter with effective written and verbal communication skills along with strong critical thinking skill Required Skills/Experience: - Effective written and verbal communication skills and the ability to tailor communication style to the audience at hand - Experience in coordination and execution of the audit lifecycle, including evidence collection, review, observation tracking, management response collection and auditor relations and communication - Strong demonstration of problem-solving and decision-making ability - Experience working on testing of IT controls across systems, databases, applications and operating systems - Strong ability to frame and deliver messages based on experience and level of the listener - Strong critical thinking skills to actively pursue opportunities to develop and implement solutions to solve work problems - Must be able to solve problems, handle conflict, and make effective decisions under pressure with a highly professional demeanor - Strong organizational skills - Strong ability to adjust to changing priorities while multitasking effectively - Self-directed and works with minimal guidance - Proactively seeks guidance when needed Preferred Skills/Experience: - Knowledge of Information Technology GCC as well as knowledge and understanding of governance, risk & compliance - Experience performing audits/assessments Education/Certifications: - Undergraduate university degree (4-year) preferred but not required - Masters (e.g., MBA, MSIS, MIS, etc.) degree preferred but not required - Five (5) years of combined IT experience to include two (2) years IT security work - Experience in Information Security, IT general controls, IT compliance, IT assessments and/or IT audit experience - Certified Information Systems Security Professional (CISSP), CISA, CPA/CA, CISM or other equivalent professional certification preferred but not required Why work with us? We are a woman-owned company that values your ideas, encourages your growth, and always has your back. When you work with us you'll have training opportunities, flexible/remote work options, growth opportunities, 401K and competitive pay. Apply today! We are an EOE, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Michigan