Senior Security Engineer Research & Engineering

Trail of Bits provides blockchain security services, including smart contract audits, design assessment, and vulnerability analysis for Web3 projects.

0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/2/2026

Distributed
About Trail of Bits

Trail of Bits helps secure blockchain technology through comprehensive security assessments, code reviews, and tool development. The company provides specialized services for smart contracts, nodes, bridges, DeFi protocols, and off-chain components across multiple blockchain ecosystems including Ethereum, Solana, and others. They also develop and maintain open-source security tools like Slither, Echidna, and Medusa.

View jobs by Trail of Bits

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will evaluate specifications designs and proofs to determine what has been established and what assumptions remain. You will attack systems and production software, identify exploitable vulnerabilities, map real attack surfaces, build AI-driven discovery and triage tooling, produce rigorous security assessments, and publish methodology and findings. You may also attend occasional sprints and hackathon events in London.

Requirements

  • Direct red-team experience against production software
  • Experience building AI-driven vulnerability discovery tooling
  • Experience applying formal methods to system designs and implementations
  • Ability to read Lean Rocq F* Dafny or Verus/Rust
  • Depth in network protocols operating systems open-source software cryptography or AI inference infrastructure
  • Software development experience in Python C++ or Rust
  • Experience writing security assessment reports for expert audiences
  • Experience delivering work to fixed external schedules
  • Experience with ethical vulnerability disclosure

Responsibilities

  • Evaluate specifications designs and proofs
  • Identify assumptions and gaps in formal guarantees
  • Compromise systems and demonstrate exploitable vulnerabilities
  • Map attack surfaces threat models and trusted computing bases
  • Build AI-driven discovery triage and exploit-generation tooling
  • Write rigorous security assessment reports
  • Publish tooling methodology and technical findings
  • Deliver work to fixed schedules and acceptance criteria
  • Report vulnerabilities ethically

Benefits

  • Performance-based bonuses
  • $1,000 working-from-home stipend
  • Annual $750 Learning & Development stipend
  • Company-sponsored all-team celebrations with travel and accommodation
  • Philanthropic contribution matching up to $2,000 annually