Trail of Bits seeks a Security Engineer I for our Application Security practice. You will contribute to security assessments of client software, partner with more experienced engineers, identify vulnerabilities across the application and system levels, and own clearly scoped pieces of client engagements. You will drive your own vulnerability analysis, develop tools alongside the team, and help clients understand and fix the issues you find. This role bridges vulnerability research and applied security. Your work will be hands-on: analyzing complex code, building custom tooling, conducting threat modeling, and owning your findings through client delivery. It is distinct from roles centered on security operations, SOC work, GRC, compliance, policy, audit, or general security administration. Candidates from broader or adjacent security backgrounds should be prepared to talk through relevant hands-on, code-level security work they have personally completed. Security Engineer I is an early-career role, but it is not a training role for someone new to software or security. Relevant experience may come from professional work, internships, advanced coursework, independent research, open-source contributions, CTFs, or substantial personal or academic projects. Regardless of where you gained the experience, you should be able to talk through code-level security work you performed, how you approached the problem, and the conclusions you reached. You will receive direction and review from a project lead while independently completing well-scoped technical work.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level
Education Level
No Education Listed