Security Engineer II, Application Security

🔥 12 hours ago

🇺🇸 United States – Remote

💵 $140k - $180k / year

⏰ Full Time

🟢 Junior

🟡 Mid-level

👮‍♂️ Cybersecurity / Security Engineer

🚫👨‍🎓 No degree required

👻 Ghost score 1%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Trail of Bits

Trail of Bits

51 - 200 employees

Founded 2012

🔒 Cybersecurity

☁️ SaaS

₿ Crypto

Cybersecurity • SaaS • Crypto

Trail of Bits is a company that specializes in software security and assurance. Established in 2012, it has assisted some of the most targeted organizations worldwide in securing their systems. Trail of Bits combines advanced security research with a practical attacker mindset to reduce risk and strengthen software code. The company offers services in software assurance, security engineering, and research and development, focusing on areas such as blockchain, cryptography, and mobile device security. They also provide expert training courses to enhance understanding of various security aspects like penetration testing and threat modeling.

📋 Description

• Independently lead security assessments of substantial client components, modules, or systems from scoping through delivery • Find and validate vulnerabilities, establish root causes and exploitation paths, assess impact, and develop proof-of-concept code when appropriate • Design and build custom security tools, harnesses, tests, and automation • Review software architectures, attack surfaces, data flows, trust boundaries, and privilege boundaries; recommend mitigations • Produce clear, actionable findings and lead technical discussions with client engineering teams • Review other engineers' code and analysis, share techniques, and improve the team's technical approach • Contribute new methods, open-source tools, and technical writing to Trail of Bits and the broader security community • Collaborate with project leads and security engineers while exercising independent technical judgment

🎯 Requirements

• Typically 2+ years of directly relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area • Repeated vulnerability-discovery experience, including personally finding or validating vulnerabilities • Strong code-analysis skills across unfamiliar and complex codebases • Strong programming and debugging ability in at least two relevant languages, such as Rust, Go, C, C++, Python, JavaScript, or TypeScript • Working knowledge of memory-corruption vulnerabilities and mitigations • Strong systems knowledge, including operating systems, IPC, privilege boundaries, and system internals • Ability to independently scope and execute code-level security-assessment workstreams • Clear written and verbal communication, including presenting technical conclusions to engineers or clients and contributing to a distributed team • Must be eligible for employment verification in the United States

🏖️ Benefits

• Competitive salary complemented by performance-based bonuses • Fully company-paid insurance packages, including health, dental, vision, disability, and life • 401(k) plan with a 5% match of base salary • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations • 4 months of parental leave • $10,000 relocation assistance for moving to NYC • $1,000 Working-from-Home stipend • Annual $750 Learning & Development stipend • Company-sponsored all-team celebrations, including travel and accommodation • Philanthropic contribution matching up to $2,000 annually

Apply Now

Similar Jobs

🔥 17 hours ago

DreamHost

201 - 500

💼 Consulting

📣 Marketing

📦 Logistics

Security Engineer II protecting DreamHost’s multi-tenant Linux hosting infrastructure and customers. Investigating compromises, engineering detections, and automating security controls.

🔥 17 hours ago

Cleerly

201 - 500

🏥 Healthcare

💼 Consulting

🍽️ Food & Beverage

Cloud Security Engineer securing AWS infrastructure and embedding DevSecOps controls for Cleerly’s AI-driven heart-disease diagnostic platform. Leading cloud architecture, compliance, vulnerability management, and incident response.

🔥 18 hours ago

VIAVI Solutions

1001 - 5000

🚘 Automotive

💼 Consulting

🎖️ Defense

Wireless sales executive driving VIAVI network-testing and assurance solutions across hyperscale, telecom, semiconductor, and private-5G accounts. Owning territory strategy, complex solution sales, and full-cycle account growth.

🔥 18 hours ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Microsoft Security Engineer delivering Entra ID, Purview, Intune, and Defender solutions. Supporting GuidePoint Security’s cybersecurity clients through hands-on cloud security engagements.

🔥 18 hours ago

Dragonfli Group

11 - 50

🔒 Cybersecurity

💼 Consulting

Cloud Security Engineer securing federal agency networks and cloud environments for a cybersecurity and IT consulting firm. Automating security capabilities and implementing Zero Trust controls.