Security Engineer II, Application Security

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take the lead on conducting security assessments for significant client components, modules, or systems from the initial scoping phase through to delivery.

• Identify and verify vulnerabilities, determine root causes and exploitation paths, evaluate impact, and create proof-of-concept code when applicable.

• Develop and construct bespoke security tools, harnesses, tests, and automation processes.

• Analyze software architectures, attack surfaces, data flows, trust boundaries, and privilege boundaries; provide recommendations for mitigations.

• Generate clear, actionable findings and facilitate technical discussions with client engineering teams.

• Assess the code and analysis of other engineers, share techniques, and enhance the team's technical methodologies.

• Contribute innovative methods, open-source tools, and technical documentation to Trail of Bits and the wider security community.

• Collaborate with project leads and security engineers while demonstrating independent technical judgment.


⛳️ Requirements

• Typically possess 2+ years of relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related field.

• Demonstrated experience in vulnerability discovery, including personally identifying or validating vulnerabilities.

• Proficient in code analysis across unfamiliar and complex codebases.

• Strong programming and debugging skills in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.

• Familiarity with memory-corruption vulnerabilities and associated mitigations.

• Solid understanding of systems knowledge, encompassing operating systems, IPC, privilege boundaries, and system internals.

• Capability to independently scope and carry out code-level security assessment workstreams.

• Excellent written and verbal communication skills, including the ability to present technical conclusions to engineers or clients and contribute to a distributed team.

• Must be eligible for employment verification in the United States.


🏝️ Benefits

• Competitive salary along with performance-based bonuses.

• Comprehensive company-paid insurance packages, including health, dental, vision, disability, and life insurance.

• 401(k) plan with a 5% match of base salary.

• 20 days of paid vacation with the possibility for more, in accordance with jurisdictional regulations.

• 4 months of parental leave.

• $10,000 relocation assistance for moving to NYC.

• $1,000 stipend for working from home.

• Annual $750 Learning & Development stipend.

• Company-sponsored all-team celebrations, including travel and accommodation expenses.

• Philanthropic contribution matching up to $2,000 annually.

People also viewed

Sony Interactive Entertainment13 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads13 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j13 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)14 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting14 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International15 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers