Trail of Bits
Senior Developer Relations Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 6 weeks ago · Found 2h ago
Been open since 6 weeks ago, still being checked, but it has been live a while.
Salary
$160,000 to $200,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Who We Are
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.
Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.
Role
We are hiring a Developer Relations Engineer to amplify our public work and deepen our relationships with the security practitioners, researchers, maintainers, and open-source communities we serve. You will report to the Head of Go-to-Market and work in close partnership with our engineering practices and GTM teams.
We publish a lot of what we do: 946 publications, 620 public security reviews, and more than 200 open-source repositories. Last year our engineers landed more than 375 pull requests upstream, from cryptography libraries to the Rust compiler. Tools like Slither and resources like the Testing Handbook are used daily across the industry, and Buttercup, our AI cyber reasoning system, took second place in DARPA's AI Cyber Challenge and is now open source.
Today, most of that happens alongside client commitments. This role gives it a dedicated advocate. You take what we build and learn internally and extend its reach: you help decide what gets published, explain what was built and why it matters, and put it in the hands of people who will use it. Engineering owns research and tooling, Marketing owns channels and distribution, and Technical Editing owns editorial standards. You bring the relationships and the technical substance that make it travel, and you carry no quota and no account list. You will occasionally join a technical conversation where your expertise fits and where you judge it matters. Our interview process includes a technical conversation with our engineers and a short presentation.
What You’ll Do
Grow the relationships we already have across the security community, and start new ones. Show up where practitioners gather, contribute alongside maintainers and researchers, and become someone the community knows and trusts.
Own our baseline event presence. Attend and speak at the conferences and cybersecurity meetups that matter to our audiences, and help bring back successful meetups akin to Empire Hacking.
Support the open-source projects and maintainers we work with. Facilitate technical office hours that connect maintainers directly with our engineers, help contributions land upstream, and keep those relationships strong long after an engagement ends.
Turn our research and releases into practitioner staples. Work with Marketing and Technical Editing on advisories, co-authored writeups, and guidance other projects can reuse, and with Engineering on optimizing tools, skills, and plugins for adoption. Teach the methods behind the work through workshops and hands-on sessions, so others can apply them without us.
Publish under your own name, and be present where that work gets discussed. You’ll write deep dives, tutorials, and technical write-ups that hold up to scrutiny from working security engineers.
Accelerate our conference and CFP motion. Partner with Marketing to identify speaking opportunities early, and help engineers get talks submitted, prepared, and delivered.
Use our own work the way the community does. Run what we publish against unfamiliar code, and give the teams behind it direct feedback on the research and the experience.
Make our work easy to adopt. Ship examples people can run and integrations that fit their workflows, and contribute to the skills and plugins our teams build with every day. Improve the front door to our projects alongside the teams that own them: better onboarding, clearer documentation, and a first run that works.
Attract contributors from outside Trail of Bits. Show where a first contribution goes, and give them a reason to make a second.
Route what you hear back into the firm: what practitioners struggle with, what they wish existed, where our research has gaps, and which ecosystems are heating up.
What You’ll Bring
Software people actually use. A tool, a library, an integration, a skill, or an agent, out in the world doing work. You can read unfamiliar code, run our analyzers against it, and open a pull request that gets merged. Everyone builds at Trail of Bits.
Security depth. Deep, hands-on security experience, typically seven or more years, enough to hold your own with researchers and engineers. Published research, CVEs, and advisories all count.
AI-native in practice. You build with agentic tooling: skills, agents, MCP servers, harnesses, and evals. If your AI experience stops at writing prompts, this is the wrong role.
A public body of work. You’ve contributed where we can see it: talks, posts, upstream contributions, research, and documentation. We will look at your commit history rather than your follower count.
Requirements
- ·Security depth. Deep, hands-on security experience, typically seven or more years, enough to hold your own with researchers and engineers. Published research, CVEs, and advisories all count.
- ·AI-native in practice. You build with agentic tooling: skills, agents, MCP servers, harnesses, and evals. If your AI experience stops at writing prompts, this is the wrong role.
- ·A public body of work. You’ve contributed where we can see it: talks, posts, upstream contributions, research, and documentation. We will look at your commit history rather than your follower count.
- ·Community credibility. You know how these communities work, where they gather, and how quickly they detect marketing wearing engineering’s clothes.
- ·Writing and speaking that survive a skeptical audience. We speak to practitioners who can verify everything we say. This carries the same weight as the technical bar.
Benefits
- ·Benefits, Perks & Wellness
- ·Empowered Living:
- ·Competitive salary complemented by performance-based bonuses.
- ·Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- ·A solid 401(k) plan with a 5% match of your base salary.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Trail of Bits, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 3h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$160,000 to $200,000 · You'll be taken to the employer's careers page.