Security Engineer II, Application Security

New
T
Trail of BitsCybersecurity
Remote, United StatesFull-TimeSenior
Salary$140,000 to $180,000
Apply NowOpens the employer's application page

Job Details

Experience
Typically 2+ years of directly relevant experience
Required Skills
PythonJavascriptTypeScriptC++GoRust

Requirements

  • Typically 2+ years of relevant experience in application security, vulnerability research, or security-focused software engineering.
  • Repeated vulnerability-discovery experience, including establishing exploitation paths and impact.
  • Strong code-analysis skills across complex codebases, including tracing execution and data flow.
  • Strong programming and debugging ability in at least two languages (e.g., Rust, Go, C, C++, Python, JavaScript, TypeScript).
  • Working knowledge of memory-corruption vulnerabilities and mitigations.
  • Strong systems knowledge, including operating systems, IPC, and privilege boundaries.
  • Demonstrated ability to independently scope and execute a code-level security-assessment workstream.
  • Clear written and verbal communication skills for presenting to software engineers or clients.

Responsibilities

  • Lead assessments of substantial components or systems within client engagements from scoping through delivery.
  • Find and validate vulnerabilities, establish root causes, assess impact, and develop proof-of-concept code.
  • Design and build custom tools, harnesses, or automation to expand assessment coverage.
  • Review complex software architectures to identify attack surfaces, data flows, and privilege boundaries.
  • Produce clear, actionable findings and lead technical discussions with client engineering teams.
  • Review other engineers' code and analysis while contributing to the team's technical approach.
View Full Description & ApplyYou'll be redirected to the employer's site
$140,000 to $180,000
Apply Now