Senior Security Engineer – Research & Engineering

🔥 0 minutes ago

🇬🇧 United Kingdom – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 11%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Trail of Bits

Trail of Bits

51 - 200 employees

Founded 2012

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Cybersecurity • SaaS • Crypto

Trail of Bits is a company that specializes in software security and assurance. Established in 2012, it has assisted some of the most targeted organizations worldwide in securing their systems. Trail of Bits combines advanced security research with a practical attacker mindset to reduce risk and strengthen software code. The company offers services in software assurance, security engineering, and research and development, focusing on areas such as blockchain, cryptography, and mobile device security. They also provide expert training courses to enhance understanding of various security aspects like penetration testing and threat modeling.

📋 Description

• Evaluate specifications alongside designs and proofs to determine what has actually been established versus assumed • Use state-of-the-art tools and frontier AI models to identify issues outside the scope of proofs • Conduct red-team evaluations during one-week sprints following seven weeks of preparation • Build AI-driven discovery and triage tooling, including agentic harnesses, triage pipelines, and automated exploit generation • Work in small teams and with third parties • Report to a domain lead in applied cryptography and proof systems, operating system internals, applications, hardware, or AI infrastructure • Maintain separation of information across simultaneous engagements • Occasionally attend sprints and hackathon events in London • Compromise formally verified designs and production software and demonstrate vulnerabilities with working exploits • Map formal properties, threat models, and underlying assumptions to the real attack surface • Write clear security assessments documenting successful findings, failed attempts, and the limits of proofs • Publish tooling and methodology, write for the blog, present internally, and transfer lessons between engagements

🎯 Requirements

• Direct experience with red teaming production software, personally responsible for finding and proving exploitable vulnerabilities • Hands-on offensive work, not exercise coordination or scanner triage • Experience building AI-driven tooling for vulnerability discovery, including agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation • Experience applying formal methods to system designs and code implementations • Ability to read specifications and proof artifacts and reason about machine-checked proofs • Ability to read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust • Experience finding vulnerabilities in network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure • Experience in Python, C++, and/or Rust • Experience producing security assessment reports for expert readers • Experience delivering to a fixed external schedule with defined acceptance criteria • Experience in the ethical reporting of vulnerabilities in technology • Preferred: published vulnerability research, such as CVEs, advisories, or talks at OffensiveCon, RECon, CCC, or USENIX Security • Preferred: experience auditing or contributing to formally verified codebases such as HACL*, EverCrypt, seL4, CompCert, or CakeML • Preferred: experience building automated bug-finding infrastructure at scale • Preferred: experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling • Preferred: experience attacking AI inference infrastructure • Preferred: participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar • Preferred: experience with compiler technology, program analysis, or binary analysis • Preferred: experience reading, writing, and publishing academic papers

🏖️ Benefits

• Performance-based bonuses • $1,000 Working-from-Home stipend • Annual $750 Learning & Development stipend • Company-sponsored all-team celebrations, including travel and accommodation • Philanthropic contribution matching up to $2,000 annually • Remote-first culture built on autonomy and trust

Apply Now

Similar Jobs

🔥 8 hours ago

NVIDIA

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

🤖 Artificial Intelligence

Senior Security Architect designing attestation and confidential-computing security for NVIDIA network devices. Leading next-generation architecture, research, and proof-of-concept development.

🕒 Yesterday

NatWest Group

10,000+ employees

🏦 Banking

💸 Finance

💳 Fintech

Security Intelligence Specialist protecting bank services through cyber threat intelligence. Analyzing threats and advising security, technology, and business decisions.

🕒 6 days ago

Telefónica Tech

1001 - 5000

🏥 Healthcare

🛡️ Insurance

🏭 Manufacturing

Cyber Security Manager overseeing managed SOC, SIEM, MDR and incident response services for Telefónica Tech enterprise customers. Leading governance, customer success and cyber resilience improvements.

🕒 6 days ago

Applied Computing

11 - 50

🤖 Artificial Intelligence

⚡ Energy

🤝 B2B

Cyber Security Manager securing Applied Computing’s AI foundation model for energy operations. Owning incident response, cloud identity, endpoints, IT service, resilience, and autonomous detection.

🕒 August 25

Endure Capital

1 - 10

🏥 Healthcare

💼 Consulting

📣 Marketing

Senior Product Security Engineer securing Numan’s regulated digital health platform. Protecting clinical data, AI systems, cloud services, and patient-facing products.