Security Engineer I, Application Security
New
T
Trail of BitsCybersecurity
Remote, United StatesFull-TimeEntry
Salary$100,000 to $160,000 and will include additional bonuses
Apply NowOpens the employer's application page
Job Details
- Experience
- At least 1 year
- Required Skills
- PythonGoRust
Requirements
- At least 1 year of combined relevant experience in application security, vulnerability research, or security-focused software engineering.
- Demonstrable vulnerability-discovery capability and ability to discuss personally identified weaknesses.
- Strong code-analysis skills including the ability to trace execution and data flow in unfamiliar code.
- Hands-on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.
- Working knowledge of memory-corruption vulnerabilities and common mitigations like buffer overflows, ASLR, and NX/DEP.
- Familiarity with operating-system concepts, IPC, and privilege boundaries.
- Ability to independently investigate and document well-scoped technical problems.
- Clear written and verbal communication skills.
Responsibilities
- Lead the review of a specific component, module, or system within a larger client engagement.
- Find and validate vulnerabilities in application code and systems.
- Explain exploitation paths, assess impact, and develop proof-of-concept code.
- Design and build security-testing tools and automation for vulnerability detection.
- Review software architectures to identify attack surfaces, data flows, and privilege boundaries.
- Translate technical findings into clear, actionable recommendations for engineering teams.
- Contribute to security research, open-source tools, and technical documentation.
View Full Description & ApplyYou'll be redirected to the employer's site