Security Engineer II, Application Security
Trail of Bits provides blockchain security services, including smart contract audits, design assessment, and vulnerability analysis for Web3 projects.
Maintainer signals as of 9/25/2026
Projects
About Trail of Bits
Trail of Bits helps secure blockchain technology through comprehensive security assessments, code reviews, and tool development. The company provides specialized services for smart contracts, nodes, bridges, DeFi protocols, and off-chain components across multiple blockchain ecosystems including Ethereum, Solana, and others. They also develop and maintain open-source security tools like Slither, Echidna, and Medusa.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will independently assess substantial client software components, modules, and systems from scoping through delivery. You will analyze complex code, validate vulnerabilities, establish exploitation paths and impact, and build targeted security tools and automation. You will perform architecture reviews and threat modeling, communicate actionable findings to client engineers, review peer work, and contribute research and technical writing.
Requirements
- Typically 2+ years of directly relevant experience in application security, vulnerability research, security-focused software engineering, or a closely related area
- Repeated vulnerability-discovery experience
- Strong code-analysis skills across unfamiliar and complex codebases
- Strong programming and debugging ability in at least two relevant languages
- Working knowledge of memory-corruption vulnerabilities and mitigations
- Strong systems knowledge, including operating systems, IPC, privilege boundaries, and system internals
- Demonstrated ability to independently scope and execute code-level security-assessment workstreams
- Clear written and verbal communication, including presenting technical conclusions to software engineers or clients
Responsibilities
- Lead security assessments of substantial components, modules, or systems from scoping through delivery
- Find and validate vulnerabilities and establish root causes, exploitation paths, and impact
- Develop proof-of-concept code when appropriate
- Design and build targeted security tools, harnesses, tests, and automation
- Review complex software architectures and conduct threat modeling
- Identify attack surfaces, data flows, and trust and privilege boundaries
- Recommend practical mitigations
- Produce and defend clear, actionable findings
- Lead technical discussions with client engineering teams
- Review other engineers' code and analysis
- Share techniques and improve technical approaches
- Contribute methods, open-source tools, and technical writing
Benefits
- Fully company-paid health, dental, vision, disability, and life insurance
- 401(k) plan with a 5% base-salary match
- 20 days of paid vacation with flexibility for more
- Four months of parental leave
- USD 10,000 relocation assistance for a move to NYC
- USD 1,000 working-from-home stipend
- Company-sponsored all-team celebrations with travel and accommodation
- Philanthropic contribution matching up to USD 2,000 annually
