Job Closed
This listing is no longer active.
Deepening the Science of Security
Senior Security Engineer, Research & Engineering
Location
United States
Posted
104 days ago
Salary
$150K - $200K / year
Seniority
Senior
Job Description
Senior Security Engineer, Research & Engineering
Trail of Bits
Who We Are Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable. Role This role is for a security-focused software engineer who will design, build, and enhance security tools and frameworks across various contexts. You'll work on projects ranging from compiler-based security tools to AI/ML security frameworks, contributing to software that makes a real difference in the security landscape. You'll work on diverse projects and technologies, developing your expertise across multiple domains while building practical tools to solve security problems. You'll collaborate with researchers, security experts, and clients to understand complex security challenges and implement effective solutions. Software development will primarily involve Rust, C++, and Python, with occasional work in Go and Java. The role involves maintaining existing projects and creating novel solutions to emerging security challenges. You will typically work in teams of 2–4 people, all from remote locations. Technical leads guide the team’s work, collaborating with you and other members to define responsibilities based on project needs, individual strengths, and team input. Frequent communication with team members and clients is essential to success, and writing about your work publicly is encouraged and incentivized. We welcome applications from experienced professionals and talented recent graduates with relevant skills and interests. What You'll Achieve Security Tool Development: Design and implement security-focused software tools and frameworks Open Source Contribution: Contribute to open-source security projects and develop internal tools Security Solution Architecture: Analyze complex security challenges and develop practical, deployable solutions Full-Stack Security Understanding: Understand security implications across the stack, from low-level systems to application frameworks Secure Implementation: Implement secure CI/CD pipelines and integration with GitHub Actions AI/ML Security Research: Contribute to AI/ML security research and tooling Security Code Review: Evaluate and improve the security of existing software through code review and enhancement Technical Communication: Communicate technical concepts effectively to team members, clients, and the broader security community Technical Troubleshooting: Root-cause analysis and debugging on low-level technical issues Project Management: Interpret requirements, decompose tasks, and make engineering estimates What You'll Bring Strong software development skills with experience in: Rust, C++, and/or Python. Occasionally, Go or Java knowledge is necessary Knowledge of AI/ML systems and associated security challenges Familiarity with AI development tools like Claude Code, Cursor, and others Experience with secure development practices and building secure software Demonstrated ability to quickly learn new programming languages, frameworks, and technologies Understanding of computer security principles and common vulnerability classes Ability to work independently and as part of a remote team Strong written and verbal communication skills Familiarity with GitHub, CI/CD pipelines, and automated testing Preferred Qualifications Prior contributions to open-source security tools or frameworks Experience developing commercial-grade software used by the public Understanding of low-level systems, including memory management and operating system internals Experience with compiler technology, program analysis, or binary analysis Participation in CTF competitions or other security challenges Experience with multiple programming languages and paradigms Experience in reading, writing, and publishing academic papers Experience in public speaking (Preferred qualifications are nice to have, but not required. Please apply even if you don’t meet all of these!) The US base salary for this full-time position ranges from 150,000 to 200,000, excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime. Benefits Benefits, Perks & Wellness Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees: Empowered Living: Competitive salary complemented by performance-based bonuses. Fully company-paid insurance packages, including health, dental, vision, disability, and life. A solid 401(k) plan with a 5% match of your base salary. 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations. Nurturing New Beginnings: 4 months of parental leave to cherish the arrival of new family members. Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition. Work & Life Enrichment: $1,000 Working-from-Home stipend to create a comfortable and productive home office. Annual $750 Learning & Development stipend for continuous personal and professional growth. Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements. Community Impact: Philanthropic contribution matching up to $2,000 annually.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Especialista em Segurança da Informação – foco em IAM
ClicksignClicksign. O click que muda a sua vida.
• Apoiar a implementação, operação e evolução dos controles de Identidade e Acesso (IAM) para usuários, sistemas, aplicações e contas de serviço. • Desenvolver e manter atualizadas a Matriz de Segregação de Funções (SoD) e a Matriz de Controle de Acesso Baseado em Funções (RBAC). • Analisar cenários de IAM, SSO e controle de acesso para identificar pontos fracos e configurações incorretas. • Realizar processos de revisão periódica de acessos, garantindo aderência aos princípios de menor privilégio e segregação de funções. • Apoiar a automação de processos internos da área, reduzindo atividades manuais e riscos operacionais. • Participar da análise e resposta a incidentes de segurança relacionados a identidade, autenticação e autorização. • Contribuir para a definição, revisão e aplicação de políticas e procedimentos de IAM. • Apoiar atividades de auditoria, compliance e governança, incluindo coleta de evidências e atendimento a auditorias internas e externas incluindo ISO 27001 e 27701. • Colaborar na implementação e atualização das políticas de segurança da empresa, garantindo que as medidas de segurança sejam eficazes. • Monitorar eventos de segurança, identificando possíveis ameaças, respondendo a incidentes de segurança. • Trabalhar de forma integrada com os times de Segurança da Informação, ITOps, Engenharia e áreas de negócio. • Responder formulários de clientes e avaliar formulários de fornecedores e parceiros. • Apoiar iniciativas de melhoria contínua, mapeando riscos de acesso e propondo controles mais eficientes. • Manter documentação técnica atualizada sobre processos e controles de IAM. • Revisar modelos de Confiança Zero (Zero Trust) e decisões de design de acesso; • Apoiar a geração e validação de dados realistas de segurança de identidade usados para treinar e avaliar sistemas de IA.
Senior Enterprise Security Architect – Azure Cloud, Data Center
Concord Academy MemphisA place for students with learning differences to belong and succeed!
• Develop and drive a holistic Platform Security Strategy for Azure Cloud and Data Center environments. • Lead roadmap planning and long-term security initiatives to improve architectural resilience and risk reduction. • Define governance architecture for cloud and datacenter platform security, ensuring scalable and secure system design. • Collaborate with Product Security to align platform controls with product security requirements. • Perform Security Architecture reviews for all platform related changes including to support product development, SECDEVOPS, platform enhancements, etc. • Define and lead DevSecOps strategies, embedding platform security throughout the product development lifecycle across all platforms. • Drive adoption of security automation, secure coding practices, and CI/CD pipeline integration. • Lead architecture and design reviews, threat modeling exercises, and platform security assessments across the enterprise. • Establish and enforce platform-level threat modeling standards and processes. • Define, document, and manage security control frameworks for platform technologies.
• Lead the enterprise Cybersecurity IAM strategy, ecosystem, and architecture for Banner Health • Develop architectural artifacts, models, patterns, and lead the standards for identities and access, in compliance with legal, regulatory, and Banner Health requirements • Design solutions to resolve complex and highly complex technical and business issues related to Identity Governance and Administration (IGA) • Coordinate and work with other teams to support the IAM program and strategic vision • Develop identity-focused roadmaps and strategy documentation.
Software Engineer
Owl Cyber DefenseOwl Cyber Defense is a cybersecurity company delivering rigorously tested, purpose-built, made-in-the-USA cross-domain and data diode solutions for high-assurance network protectio
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description In this Software Engineering role, you will be responsible for investigating, enhancing, designing, developing, and testing Linux based security systems. You will work on multiple projects identifying and resolving complex security issues. Projects involve deep security vulnerabilities that target the operating system level. This is an opportunity to deepen your operating system security knowledge with a recognized leader in the industry. You will learn SELinux and other security processes to harden complex systems. This opportunity will allow you to be part of a strong technical team with a high degree of autonomy and significant responsibility. Qualifications - Bachelor’s degree or higher in Computer Science, Engineering or Mathematics - 5+ years of experience in software development (those with additional years of experience are encouraged to apply) with one or more of the following languages: Rust, Java, and Python - Rust, Java and Python software development experience - Linux/Unix Operating System level programming - XML, XSLT, XPROC (or related technical experience) development experience - Software testing experience Requirements - Experience writing trusted code or providing kernel level functionality - Design and developing filter software for Cross Domain Solutions - Experience with identification and specification of data attack, data disclosure, etc. associated with file formats and protocols - Experience with embedded systems development - Experience with SELinux - Experience with RHEL, systemd and creating systemd unit files - C/C++ development experience - This position supports hybrid and/or remote work (periodic trips to the office expected) - US Citizenship required as candidates must be able to obtain and maintain a security clearance. Company Description Owl Cyber Defense Solutions, LLC is a fast-growing cybersecurity solutions company, holding a firm leadership position in network security and secure information transfer. It is a privately-owned US company with offices in Columbia, MD, Danbury, CT and Morrisville, NC. Owl Cyber Defense is an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive equal consideration for employment.



