Security Engineer I, Application Security
Trail of Bits provides blockchain security services, including smart contract audits, design assessment, and vulnerability analysis for Web3 projects.
Maintainer signals as of 9/25/2026
Projects
About Trail of Bits
Trail of Bits helps secure blockchain technology through comprehensive security assessments, code reviews, and tool development. The company provides specialized services for smart contracts, nodes, bridges, DeFi protocols, and off-chain components across multiple blockchain ecosystems including Ethereum, Solana, and others. They also develop and maintain open-source security tools like Slither, Echidna, and Medusa.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will assess client software, analyze complex code, find and validate vulnerabilities, and develop proof-of-concept code where appropriate. You will build security-testing tools, conduct architecture reviews and threat modeling, document evidence, and translate findings into actionable remediation guidance. You will independently deliver well-scoped technical work with direction and review from a project lead.
Requirements
- At least 1 year of combined relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area
- Demonstrable vulnerability-discovery capability
- Strong code-analysis skills
- Hands-on coding proficiency in at least two relevant languages
- Working knowledge of memory-corruption vulnerabilities and mitigations
- Familiarity with operating-system concepts, IPC, privilege boundaries, and system internals
- Ability to independently investigate well-scoped problems, debug issues, document evidence, and deliver reviewed work
- Clear written and verbal communication
Responsibilities
- Lead reviews of scoped components, modules, or systems within client engagements
- Find and validate vulnerabilities in application code and systems
- Analyze root causes, exploitation paths, and security impact
- Develop proof-of-concept code when appropriate
- Design and build security-testing tools and automation
- Review software architectures and conduct threat modeling
- Identify attack surfaces, data flows, and trust and privilege boundaries
- Recommend concrete mitigations
- Translate technical findings into actionable recommendations
- Contribute to security research, open-source tools, knowledge sharing, and technical documentation
Benefits
- Fully company-paid health, dental, vision, disability, and life insurance
- 401(k) plan with a 5% base-salary match
- 20 days of paid vacation with flexibility for more
- Four months of parental leave
- USD 10,000 relocation assistance for a move to NYC
- USD 1,000 working-from-home stipend
- Company-sponsored all-team celebrations with travel and accommodation
- Philanthropic contribution matching up to USD 2,000 annually
