Security Engineer, Application Security

Trail of Bits provides blockchain security services, including smart contract audits, design assessment, and vulnerability analysis for Web3 projects.

36 current maintainers30 active leads9 new active leads18 lead step-downs11 early lead departuresTeam intelligence

Maintainer signals as of 8/23/2026

Distributed
About Trail of Bits

Trail of Bits helps secure blockchain technology through comprehensive security assessments, code reviews, and tool development. The company provides specialized services for smart contracts, nodes, bridges, DeFi protocols, and off-chain components across multiple blockchain ecosystems including Ethereum, Solana, and others. They also develop and maintain open-source security tools like Slither, Echidna, and Medusa.

View jobs by Trail of Bits

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Perform deep low-level application security assessments, analyze code and binaries to find exploitable vulnerabilities, design automated security tools, review architectures and threat models, assess platform security boundaries and access controls, communicate actionable findings, and contribute to security research and tooling.

Requirements

  • Application security assessment experience
  • Manual code review expertise
  • Static analysis and dynamic analysis experience
  • Binary analysis and reverse engineering experience
  • Knowledge of memory corruption vulnerabilities and mitigations
  • Understanding of system internals, IPC, and platform security boundaries
  • Architecture review and threat modeling experience
  • Security tool design and development experience
  • Programming proficiency in two or more of Rust, Golang, Kotlin, Swift, Objective-C, JavaScript, TypeScript, Python, Ruby, C, or C++
  • Ability to translate complex security findings into clear actionable recommendations
  • Experience with Android, iOS, or macOS system internals
  • Experience contributing to open source security tools or publishing vulnerability research
  • Experience identifying cloud security misconfigurations
  • Experience collaborating on government-funded security research

Responsibilities

  • Conduct low-level code security assessments
  • Analyze vulnerabilities in application and system-level software
  • Design and implement custom security tools for automated detection
  • Perform architecture reviews and threat modeling
  • Assess privilege escalation vectors and platform security controls
  • Review access control implementations and inter-process communication
  • Engage with clients to provide technical recommendations and remediation guidance
  • Contribute to research and develop new security methodologies and tooling
  • Document and communicate findings to technical stakeholders

Benefits

  • Performance-based bonuses
  • Fully company-paid health insurance
  • Dental insurance
  • Vision insurance
  • Disability insurance
  • Life insurance
  • 401(k) plan with 5% match
  • 20 days paid vacation
  • 4 months parental leave
  • Up to $10,000 relocation assistance to New York City
  • $1,000 working-from-home stipend
  • $750 annual learning and development stipend
  • Company-sponsored all-team celebrations including travel and accommodation
  • Philanthropic contribution matching up to $2,000 annually

Hiring Process

Only applications completed via the Careers page will be considered for further review.

Security Engineer, Application Security at Trail of Bits | JobStash