Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Trail of Bits

Security Engineer I, Application Security

Trail of Bits

. Contribute to security assessments of client software and partner with experienced engineers.

Posted 9/25/2026full-timeRemote • United StatesJunior💰 $100,000 - $160,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application security and vulnerability research, with strong coding proficiency in languages such as Rust, Go, C, C++, Python, JavaScript, or TypeScript. Capable of conducting thorough security assessments, identifying vulnerabilities, and providing actionable recommendations to engineering teams.

Highest-signal resume keywords
Application SecurityVulnerability ResearchCode AnalysisSecurity Testing ToolsClear Communication

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability DiscoveryCode AnalysisMemory-Corruption VulnerabilitiesHands-On Coding ProficiencyDebuggingTechnical DocumentationRoot Cause AnalysisProof-of-Concept DevelopmentSecurity MitigationsExploit Development
Soft Skills
Clear Written CommunicationVerbal CommunicationIndependent InvestigationFocused QuestioningTeam Collaboration
Tools & Technologies
KubernetesHelmTerraformAnsibleOpen-Source Security ToolsFuzzingReverse Engineering
Industry Keywords
Vulnerability ResearchSecurity AssessmentsApplication InteractionDistributed TeamsTechnical Findings

Tech Stack

Tools & technologies
AnsibleCloudJavaScriptKubernetesPythonRustTerraformTypeScriptC++Go

About the role

Key responsibilities & impact
  • Contribute to security assessments of client software and partner with experienced engineers.
  • Lead review of a specific component, module, or system within larger client engagements.
  • Trace root causes and own analysis from vulnerability discovery through client delivery.
  • Find and validate vulnerabilities in application code and systems.
  • Explain exploitation paths, assess impact, and develop proof-of-concept code when appropriate.
  • Design and build security-testing tools and automation for vulnerability detection and deeper analysis.
  • Review software architectures, identify attack surfaces, data flows, trust boundaries, and privilege boundaries.
  • Recommend concrete security mitigations.
  • Translate technical findings into clear, actionable recommendations for engineering teams.
  • Explain evidence behind conclusions to clients.
  • Contribute to security research, open-source tools, internal knowledge sharing, and technical documentation.

Requirements

What you’ll need
  • At least 1 year of combined relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area.
  • Demonstrable vulnerability-discovery capability, including personally finding or validating a vulnerability or security weakness.
  • Strong code-analysis skills, including reading unfamiliar code, tracing execution and data flow, identifying flaws, and validating vulnerabilities.
  • Hands-on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.
  • Working knowledge of memory-corruption vulnerabilities and common mitigations, including buffer overflows, use-after-free, stack cookies, ASLR, NX/DEP, CFI, or MTE.
  • Familiarity with operating-system concepts, IPC, privilege boundaries, and application interaction with system internals.
  • Ability to independently investigate a well-scoped problem, debug issues, document evidence, ask focused questions, and deliver work with project-lead review.
  • Clear written and verbal communication, including explaining technical findings and remediation guidance to software engineers and working productively on a distributed team.
  • Preferred: CTF participation, published vulnerability research/CVEs/responsible disclosures/bug bounty findings, open-source security contributions, mobile application security, cloud or infrastructure assessment, Kubernetes, Helm, Terraform, Ansible, kernel code, drivers, reverse engineering, fuzzing, low-level systems work, technical writing, conference talks, or substantial technical documentation.
  • U.S.-based candidates must meet employment eligibility verification requirements through E-Verify.

Benefits

Comp & perks
  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
  • 4 months of parental leave.
  • $10,000 in relocation assistance for moving to NYC.
  • $1,000 Working-from-Home stipend.
  • Annual $750 Learning & Development stipend.
  • Company-sponsored all-team celebrations, including travel and accommodation.
  • Philanthropic contribution matching up to $2,000 annually.
  • Remote-first culture for full-time employees.