FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Engineer I, Application Security
Trail of Bits. Contribute to security assessments of client software and partner with experienced engineers.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in application security and vulnerability research, with strong coding proficiency in languages such as Rust, Go, C, C++, Python, JavaScript, or TypeScript. Capable of conducting thorough security assessments, identifying vulnerabilities, and providing actionable recommendations to engineering teams.
Highest-signal resume keywords
Application SecurityVulnerability ResearchCode AnalysisSecurity Testing ToolsClear Communication
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability DiscoveryCode AnalysisMemory-Corruption VulnerabilitiesHands-On Coding ProficiencyDebuggingTechnical DocumentationRoot Cause AnalysisProof-of-Concept DevelopmentSecurity MitigationsExploit Development
Soft Skills
Clear Written CommunicationVerbal CommunicationIndependent InvestigationFocused QuestioningTeam Collaboration
Tools & Technologies
KubernetesHelmTerraformAnsibleOpen-Source Security ToolsFuzzingReverse Engineering
Industry Keywords
Vulnerability ResearchSecurity AssessmentsApplication InteractionDistributed TeamsTechnical Findings
Tech Stack
Tools & technologiesAnsibleCloudJavaScriptKubernetesPythonRustTerraformTypeScriptC++Go
About the role
Key responsibilities & impact- Contribute to security assessments of client software and partner with experienced engineers.
- Lead review of a specific component, module, or system within larger client engagements.
- Trace root causes and own analysis from vulnerability discovery through client delivery.
- Find and validate vulnerabilities in application code and systems.
- Explain exploitation paths, assess impact, and develop proof-of-concept code when appropriate.
- Design and build security-testing tools and automation for vulnerability detection and deeper analysis.
- Review software architectures, identify attack surfaces, data flows, trust boundaries, and privilege boundaries.
- Recommend concrete security mitigations.
- Translate technical findings into clear, actionable recommendations for engineering teams.
- Explain evidence behind conclusions to clients.
- Contribute to security research, open-source tools, internal knowledge sharing, and technical documentation.
Requirements
What you’ll need- At least 1 year of combined relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area.
- Demonstrable vulnerability-discovery capability, including personally finding or validating a vulnerability or security weakness.
- Strong code-analysis skills, including reading unfamiliar code, tracing execution and data flow, identifying flaws, and validating vulnerabilities.
- Hands-on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript.
- Working knowledge of memory-corruption vulnerabilities and common mitigations, including buffer overflows, use-after-free, stack cookies, ASLR, NX/DEP, CFI, or MTE.
- Familiarity with operating-system concepts, IPC, privilege boundaries, and application interaction with system internals.
- Ability to independently investigate a well-scoped problem, debug issues, document evidence, ask focused questions, and deliver work with project-lead review.
- Clear written and verbal communication, including explaining technical findings and remediation guidance to software engineers and working productively on a distributed team.
- Preferred: CTF participation, published vulnerability research/CVEs/responsible disclosures/bug bounty findings, open-source security contributions, mobile application security, cloud or infrastructure assessment, Kubernetes, Helm, Terraform, Ansible, kernel code, drivers, reverse engineering, fuzzing, low-level systems work, technical writing, conference talks, or substantial technical documentation.
- U.S.-based candidates must meet employment eligibility verification requirements through E-Verify.
Benefits
Comp & perks- Competitive salary complemented by performance-based bonuses.
- Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- A solid 401(k) plan with a 5% match of your base salary.
- 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
- 4 months of parental leave.
- $10,000 in relocation assistance for moving to NYC.
- $1,000 Working-from-Home stipend.
- Annual $750 Learning & Development stipend.
- Company-sponsored all-team celebrations, including travel and accommodation.
- Philanthropic contribution matching up to $2,000 annually.
- Remote-first culture for full-time employees.