Security Engineer II, Application Security
New
T
Trail of BitsCybersecurity
Remote, United StatesFull-TimeSenior
Salary$140,000 to $180,000
Apply NowOpens the employer's application page
Job Details
- Experience
- Typically 2+ years of directly relevant experience
- Required Skills
- PythonJavascriptTypeScriptC++GoRust
Requirements
- Typically 2+ years of relevant experience in application security, vulnerability research, or security-focused software engineering.
- Repeated vulnerability-discovery experience, including establishing exploitation paths and impact.
- Strong code-analysis skills across complex codebases, including tracing execution and data flow.
- Strong programming and debugging ability in at least two languages (e.g., Rust, Go, C, C++, Python, JavaScript, TypeScript).
- Working knowledge of memory-corruption vulnerabilities and mitigations.
- Strong systems knowledge, including operating systems, IPC, and privilege boundaries.
- Demonstrated ability to independently scope and execute a code-level security-assessment workstream.
- Clear written and verbal communication skills for presenting to software engineers or clients.
Responsibilities
- Lead assessments of substantial components or systems within client engagements from scoping through delivery.
- Find and validate vulnerabilities, establish root causes, assess impact, and develop proof-of-concept code.
- Design and build custom tools, harnesses, or automation to expand assessment coverage.
- Review complex software architectures to identify attack surfaces, data flows, and privilege boundaries.
- Produce clear, actionable findings and lead technical discussions with client engineering teams.
- Review other engineers' code and analysis while contributing to the team's technical approach.
View Full Description & ApplyYou'll be redirected to the employer's site