Senior Security Engineer – Research & Engineering

🕒 vor 6 Tagen

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

👻 Geisterscore 11%

infoinfo

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Trail of Bits

Trail of Bits

51 - 200 Mitarbeiter

Gegründet 2012

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Cybersecurity • SaaS • Crypto

Trail of Bits ist ein auf Cybersicherheit spezialisiertes Unternehmen, das sich auf hochwertige Sicherheitsforschung und Software Assurance-Dienstleistungen konzentriert. Seit seiner Gründung im Jahr 2012 hat sich das Unternehmen darauf fokussiert, einige der weltweit am stärksten angegriffenen Organisationen abzusichern, indem es fundierte wissenschaftliche Forschung mit der Mentalität eines realen Angreifers kombiniert. Trail of Bits bietet Dienstleistungen in den Bereichen Software Assurance, Security Engineering sowie Forschung und Entwicklung, insbesondere in Systemsoftware, Blockchain und Kryptographie. Zudem bieten sie professionelle Schulungskurse in den Bereichen Reverse Engineering, Penetrationstests und Bedrohungsmodellierung an. Trail of Bits wird als einer der besten Arbeitgeber anerkannt, was sein Engagement für Kultur und Mitarbeiterzufriedenheit widerspiegelt.

Beschreibung

• Evaluate specifications alongside designs and proofs to determine what has actually been established versus assumed • Use state-of-the-art tools and frontier AI models to identify issues outside the scope of proofs • Conduct red-team evaluations during one-week sprints following seven weeks of preparation • Build AI-driven discovery and triage tooling, including agentic harnesses, triage pipelines, and automated exploit generation • Work in small teams and with third parties • Report to a domain lead in applied cryptography and proof systems, operating system internals, applications, hardware, or AI infrastructure • Maintain separation of information across simultaneous engagements • Occasionally attend sprints and hackathon events in London • Compromise formally verified designs and production software and demonstrate vulnerabilities with working exploits • Map formal properties, threat models, and underlying assumptions to the real attack surface • Write clear security assessments documenting successful findings, failed attempts, and the limits of proofs • Publish tooling and methodology, write for the blog, present internally, and transfer lessons between engagements

🎯 Anforderungen

• Direct experience with red teaming production software, personally responsible for finding and proving exploitable vulnerabilities • Hands-on offensive work, not exercise coordination or scanner triage • Experience building AI-driven tooling for vulnerability discovery, including agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation • Experience applying formal methods to system designs and code implementations • Ability to read specifications and proof artifacts and reason about machine-checked proofs • Ability to read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust • Experience finding vulnerabilities in network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure • Experience in Python, C++, and/or Rust • Experience producing security assessment reports for expert readers • Experience delivering to a fixed external schedule with defined acceptance criteria • Experience in the ethical reporting of vulnerabilities in technology • Preferred: published vulnerability research, such as CVEs, advisories, or talks at OffensiveCon, RECon, CCC, or USENIX Security • Preferred: experience auditing or contributing to formally verified codebases such as HACL*, EverCrypt, seL4, CompCert, or CakeML • Preferred: experience building automated bug-finding infrastructure at scale • Preferred: experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling • Preferred: experience attacking AI inference infrastructure • Preferred: participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar • Preferred: experience with compiler technology, program analysis, or binary analysis • Preferred: experience reading, writing, and publishing academic papers

🏖️ Vorteile

• Performance-based bonuses • $1,000 Working-from-Home stipend • Annual $750 Learning & Development stipend • Company-sponsored all-team celebrations, including travel and accommodation • Philanthropic contribution matching up to $2,000 annually • Remote-first culture built on autonomy and trust

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 7 Tagen

NVIDIA

10.000+ Mitarbeiter

🏥 Gesundheitswesen

🏭 Fertigung

🤖 Künstliche Intelligenz

Senior Security Architect designing attestation and confidential-computing security for NVIDIA network devices. Leading next-generation architecture, research, and proof-of-concept development.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 13 Tagen

Telefónica Tech

1001 - 5000

🏥 Gesundheitswesen

🛡️ Versicherung

🏭 Fertigung

Cyber Security Manager overseeing managed SOC, SIEM, MDR and incident response services for Telefónica Tech enterprise customers. Leading governance, customer success and cyber resilience improvements.

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cloud

Cyber Security

🕒 vor 13 Tagen

Applied Computing

11 - 50

🤖 Künstliche Intelligenz

⚡ Energie

🤝 B2B

Cyber Security Manager securing Applied Computing’s AI foundation model for energy operations. Owning incident response, cloud identity, endpoints, IT service, resilience, and autonomous detection.

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 15 Tagen

Endure Capital

1 - 10

🏥 Gesundheitswesen

💼 Beratung

📣 Marketing

Senior Product Security Engineer securing Numan’s regulated digital health platform. Protecting clinical data, AI systems, cloud services, and patient-facing products.

🇬🇧 Vereinigtes Königreich – Remote

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 15 Tagen

Immersive Labs

201 - 500

🔒 Cybersecurity

📚 Bildung

☁️ SaaS

Senior Cyber Security Engineer creating red-team labs, ranges and AI penetration-testing content. Strengthening Immersive Labs’ global cyber resilience platform through realistic attack simulations.

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Docker

Linux

Python