Trail of Bits seeks a Security Engineer II for our Application Security practice. You will conduct security assessments of client software, independently own substantial components or workstreams, identify and validate vulnerabilities across the application and system levels, and develop custom tooling alongside the team. You will own your analysis from discovery through client delivery and help clients understand and fix the issues you find. This role bridges vulnerability research and applied security. Your work will be hands-on and autonomous: analyzing complex code, building custom tooling, conducting threat modeling and architecture reviews, and delivering findings that can withstand technical scrutiny. It is distinct from roles centered on security operations, SOC work, GRC, compliance, policy, audit, or general security programs. Candidates from broader or adjacent security backgrounds should be prepared to talk through sustained, hands-on code-level security work they have personally completed. At the Security Engineer II level, you should be able to take an ambiguous component, module, or attack surface, determine how to assess it, perform the analysis, and deliver clear findings with limited day-to-day direction. You will collaborate with a project lead and other security engineers while exercising independent technical judgment and improving the work of the team around you.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed