Security Engineer I, Application Security

🔥 12 hours ago

🇺🇸 United States – Remote

💵 $100k - $160k / year

⏰ Full Time

🟢 Junior

👮‍♂️ Cybersecurity / Security Engineer

🚫👨‍🎓 No degree required

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Trail of Bits

Trail of Bits

51 - 200 employees

Founded 2012

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Cybersecurity • SaaS • Crypto

Trail of Bits is a company that specializes in software security and assurance. Established in 2012, it has assisted some of the most targeted organizations worldwide in securing their systems. Trail of Bits combines advanced security research with a practical attacker mindset to reduce risk and strengthen software code. The company offers services in software assurance, security engineering, and research and development, focusing on areas such as blockchain, cryptography, and mobile device security. They also provide expert training courses to enhance understanding of various security aspects like penetration testing and threat modeling.

📋 Description

• Contribute to security assessments of client software and partner with experienced engineers. • Lead review of a specific component, module, or system within larger client engagements. • Trace root causes and own analysis from vulnerability discovery through client delivery. • Find and validate vulnerabilities in application code and systems. • Explain exploitation paths, assess impact, and develop proof-of-concept code when appropriate. • Design and build security-testing tools and automation for vulnerability detection and deeper analysis. • Review software architectures, identify attack surfaces, data flows, trust boundaries, and privilege boundaries. • Recommend concrete security mitigations. • Translate technical findings into clear, actionable recommendations for engineering teams. • Explain evidence behind conclusions to clients. • Contribute to security research, open-source tools, internal knowledge sharing, and technical documentation.

🎯 Requirements

• At least 1 year of combined relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area. • Demonstrable vulnerability-discovery capability, including personally finding or validating a vulnerability or security weakness. • Strong code-analysis skills, including reading unfamiliar code, tracing execution and data flow, identifying flaws, and validating vulnerabilities. • Hands-on coding proficiency in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript. • Working knowledge of memory-corruption vulnerabilities and common mitigations, including buffer overflows, use-after-free, stack cookies, ASLR, NX/DEP, CFI, or MTE. • Familiarity with operating-system concepts, IPC, privilege boundaries, and application interaction with system internals. • Ability to independently investigate a well-scoped problem, debug issues, document evidence, ask focused questions, and deliver work with project-lead review. • Clear written and verbal communication, including explaining technical findings and remediation guidance to software engineers and working productively on a distributed team. • Preferred: CTF participation, published vulnerability research/CVEs/responsible disclosures/bug bounty findings, open-source security contributions, mobile application security, cloud or infrastructure assessment, Kubernetes, Helm, Terraform, Ansible, kernel code, drivers, reverse engineering, fuzzing, low-level systems work, technical writing, conference talks, or substantial technical documentation. • U.S.-based candidates must meet employment eligibility verification requirements through E-Verify.

🏖️ Benefits

• Competitive salary complemented by performance-based bonuses. • Fully company-paid insurance packages, including health, dental, vision, disability, and life. • A solid 401(k) plan with a 5% match of your base salary. • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations. • 4 months of parental leave. • $10,000 in relocation assistance for moving to NYC. • $1,000 Working-from-Home stipend. • Annual $750 Learning & Development stipend. • Company-sponsored all-team celebrations, including travel and accommodation. • Philanthropic contribution matching up to $2,000 annually. • Remote-first culture for full-time employees.

Apply Now

Similar Jobs

🔥 18 hours ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Microsoft Security Engineer delivering Entra ID, Purview, Intune, and Defender solutions. Supporting GuidePoint Security’s cybersecurity clients through hands-on cloud security engagements.

🔥 18 hours ago

Dragonfli Group

11 - 50

🔒 Cybersecurity

💼 Consulting

Cloud Security Engineer securing federal agency networks and cloud environments for a cybersecurity and IT consulting firm. Automating security capabilities and implementing Zero Trust controls.

🕒 6 days ago

Modern Health

201 - 500

💼 Consulting

📣 Marketing

🏥 Healthcare

Product Security Engineer securing Modern Health’s employer mental health benefits platform. Driving vulnerability remediation, secure development, threat modeling, and AWS cloud security.

🇺🇸 United States – Remote

💵 $101.4k - $140.4k / year

💰 $74M Series D on 2021-02

⏰ Full Time

🟢 Junior

👮‍♂️ Cybersecurity / Security Engineer

🚫👨‍🎓 No degree required

🕒 September 18

GR8 Tech

501 - 1000

🎮 Gaming

☁️ SaaS

Information Security Access Specialist securing employee access for GR8_TECH’s B2B iGaming platforms. Automating IAM workflows, RBAC governance, and AI-assisted access operations.

🗣️🇺🇦 Ukrainian Required

🗣️🇷🇺 Russian Required

🕒 September 18

DirectDefense

51 - 200

🔒 Cybersecurity

🏢 Enterprise

🏛️ Government

Application Security Consultant assessing customer applications for vulnerabilities at DirectDefense, a cybersecurity services provider. Conducting dynamic testing, static code reviews, and remediation guidance.