Trail of Bits
Engineering Director, Application Security
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 4 weeks ago · Found 1h ago
Been open since 4 weeks ago, still being checked, but it has been live a while.
Salary
$250,000 to $300,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Who We Are
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.
Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.
Role
You will lead Trail of Bits' Application Security practice: a team of 12 security engineers who perform code audits, vulnerability research, and secure design reviews for some of the most technically demanding clients in the industry.
This is a hands-on leadership role. You will personally review audit findings, guide technical approaches, and maintain the credibility to engage with sophisticated clients who expect their security partner to operate at their level. You will own the practice's financial performance, project staffing, and team development.
Your team works on source code. They do static analysis, manual code review, fuzzing, and protocol-level vulnerability research across Rust, Go, C/C++, Python, Solidity, and JavaScript. You need to be able to do this work yourself, not just manage people who do it.
What You’ll Achieve
Lead technical delivery. Own the quality and profitability of every engagement your team ships. Review findings, guide technical direction on complex audits, and step in when projects need senior expertise. Maintain direct relationships with your most important clients.
Staff and grow the practice. Make project assignment decisions that balance engineer development, client needs, and profitability. Manage utilization, identify when to hire, and build the pipeline through the intern program and recruiting. Own the practice's P&L.
Develop your engineers. Create space for your team to present at conferences, publish research, contribute to open source tools, and advance their careers. Identify and remove obstacles. Your success is measured by their output, not yours.
Set technical direction. Decide where the practice invests in tooling, methodology, and capability development. Stay hands-on enough to know what's working and what isn't. Ensure the team's approach evolves with the threat landscape and client needs.
Integrate AI into the practice. Champion and model the use of AI tools across your team's workflows. Help engineers adopt AI-assisted auditing, reporting, and research practices that amplify their effectiveness.
What You’ll Bring
10+ years in security, including significant time performing source code audits, not only penetration testing
Recent, demonstrable hands-on security work (code review, vulnerability research, tool development) within the last 12 months
Experience leading a team of 8+ engineers through client engagements with direct financial accountability
Proficiency in at least 4 of: Rust, Go, Python, C/C++, Solidity, JavaScript/TypeScript
Track record of managing project profitability, utilization, and staffing decisions in a consulting environment
Experience building team members' careers and external visibility (conference talks, publications, open source contributions)
Proficiency with AI coding and analysis tools in your own work
Active contributions to the security community (research, tools, advisories, publications)
The base salary for this full-time position ranges from $250,000 to $300,000. This position will come with great benefits and strong bonus potential in addition to the salary above. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process.
Requirements
- ·10+ years in security, including significant time performing source code audits, not only penetration testing
- ·Recent, demonstrable hands-on security work (code review, vulnerability research, tool development) within the last 12 months
- ·Experience leading a team of 8+ engineers through client engagements with direct financial accountability
- ·Proficiency in at least 4 of: Rust, Go, Python, C/C++, Solidity, JavaScript/TypeScript
- ·Track record of managing project profitability, utilization, and staffing decisions in a consulting environment
Benefits
- ·Benefits, Perks & Wellness
- ·Empowered Living:
- ·Competitive salary complemented by performance-based bonuses.
- ·Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- ·A solid 401(k) plan with a 5% match of your base salary.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Trail of Bits, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$250,000 to $300,000 · You'll be taken to the employer's careers page.