
Security Engineer II, Application Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take the lead on conducting security assessments for significant client components, modules, or systems from the initial scoping phase through to delivery.
• Identify and verify vulnerabilities, determine root causes and exploitation paths, evaluate impact, and create proof-of-concept code when applicable.
• Develop and construct bespoke security tools, harnesses, tests, and automation processes.
• Analyze software architectures, attack surfaces, data flows, trust boundaries, and privilege boundaries; provide recommendations for mitigations.
• Generate clear, actionable findings and facilitate technical discussions with client engineering teams.
• Assess the code and analysis of other engineers, share techniques, and enhance the team's technical methodologies.
• Contribute innovative methods, open-source tools, and technical documentation to Trail of Bits and the wider security community.
• Collaborate with project leads and security engineers while demonstrating independent technical judgment.
• Typically possess 2+ years of relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related field.
• Demonstrated experience in vulnerability discovery, including personally identifying or validating vulnerabilities.
• Proficient in code analysis across unfamiliar and complex codebases.
• Strong programming and debugging skills in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.
• Familiarity with memory-corruption vulnerabilities and associated mitigations.
• Solid understanding of systems knowledge, encompassing operating systems, IPC, privilege boundaries, and system internals.
• Capability to independently scope and carry out code-level security assessment workstreams.
• Excellent written and verbal communication skills, including the ability to present technical conclusions to engineers or clients and contribute to a distributed team.
• Must be eligible for employment verification in the United States.
• Competitive salary along with performance-based bonuses.
• Comprehensive company-paid insurance packages, including health, dental, vision, disability, and life insurance.
• 401(k) plan with a 5% match of base salary.
• 20 days of paid vacation with the possibility for more, in accordance with jurisdictional regulations.
• 4 months of parental leave.
• $10,000 relocation assistance for moving to NYC.
• $1,000 stipend for working from home.
• Annual $750 Learning & Development stipend.
• Company-sponsored all-team celebrations, including travel and accommodation expenses.
• Philanthropic contribution matching up to $2,000 annually.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.