Senior Security Engineer Research & Engineering
Trail of Bits provides blockchain security services, including smart contract audits, design assessment, and vulnerability analysis for Web3 projects.
Maintainer signals as of 9/2/2026
Projects
About Trail of Bits
Trail of Bits helps secure blockchain technology through comprehensive security assessments, code reviews, and tool development. The company provides specialized services for smart contracts, nodes, bridges, DeFi protocols, and off-chain components across multiple blockchain ecosystems including Ethereum, Solana, and others. They also develop and maintain open-source security tools like Slither, Echidna, and Medusa.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will evaluate specifications designs and proofs to determine what has been established and what assumptions remain. You will attack systems and production software, identify exploitable vulnerabilities, map real attack surfaces, build AI-driven discovery and triage tooling, produce rigorous security assessments, and publish methodology and findings. You may also attend occasional sprints and hackathon events in London.
Requirements
- Direct red-team experience against production software
- Experience building AI-driven vulnerability discovery tooling
- Experience applying formal methods to system designs and implementations
- Ability to read Lean Rocq F* Dafny or Verus/Rust
- Depth in network protocols operating systems open-source software cryptography or AI inference infrastructure
- Software development experience in Python C++ or Rust
- Experience writing security assessment reports for expert audiences
- Experience delivering work to fixed external schedules
- Experience with ethical vulnerability disclosure
Responsibilities
- Evaluate specifications designs and proofs
- Identify assumptions and gaps in formal guarantees
- Compromise systems and demonstrate exploitable vulnerabilities
- Map attack surfaces threat models and trusted computing bases
- Build AI-driven discovery triage and exploit-generation tooling
- Write rigorous security assessment reports
- Publish tooling methodology and technical findings
- Deliver work to fixed schedules and acceptance criteria
- Report vulnerabilities ethically
Benefits
- Performance-based bonuses
- $1,000 working-from-home stipend
- Annual $750 Learning & Development stipend
- Company-sponsored all-team celebrations with travel and accommodation
- Philanthropic contribution matching up to $2,000 annually
