Trail of Bits
Senior Security Engineer Cryptography
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 2 days ago · Added yesterday
First listed 2 days ago.
Salary
$165k to $220k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
- Job description states: "authorized to work in the United States without employer"
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
United States | Remote | Full time
About Trail of Bits
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.
Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable.
The Role
We're hiring a Senior Security Engineer for the Cryptography team to review and strengthen high-assurance software and cryptographic systems used across technology, finance, defense, and blockchain. You will evaluate whether cryptographic designs and implementations deliver the security properties they claim, find subtle failures where theory meets code, and help clients make sound decisions about risk and remediation.
On a typical engagement, you might review a new protocol, analyze an implementation of a standard primitive, test assumptions in a post-quantum construction, or build tooling that makes future assessments faster and more rigorous. The work spans code review, cryptanalysis, threat modeling, technical writing, and direct collaboration with client engineers.
This is a senior individual-contributor role. You will independently lead substantial parts of engagements, exercise judgment when the problem is ambiguous, communicate clearly with clients and peers, and help raise the technical bar for the cryptography team. You will also have room to contribute to open-source tools, public research, and new service offerings.
What You'll Do
Lead cryptographic assessments. Review protocols, libraries, and application code; identify design and implementation weaknesses; validate exploitability; and recommend practical fixes.
Analyze advanced constructions. Work across standardized symmetric and asymmetric cryptography, post-quantum schemes, zero-knowledge proof systems, and multi-party computation protocols, learning unfamiliar designs when an engagement demands it.
Build useful tooling. Create or extend tools, test harnesses, and proofs of concept that improve cryptanalysis, implementation review, and repeatability across engagements.
Own clear client delivery. Plan your work, surface risk early, lead technical discussions, and produce precise reports that explain both the finding and the engineering path forward.
Shape the practice. Contribute to scoping and methodology, mentor other engineers, identify promising research or tooling opportunities, and help turn repeated client needs into stronger services.
Share what you learn. Contribute to open-source projects and, when appropriate, publish technical work or present it to the security and cryptography communities.
How This Role Fits the Team
You will work within the Cryptography practice in our Assurance team, alongside engineers who review complex, high-assurance systems. Engagement teams are intentionally collaborative, but senior engineers are expected to own their technical lane, know when to pull in specialized expertise, and help clients move from a finding to a defensible engineering decision.
What Success Looks Like
You independently lead technically complex assessment work from initial threat model through client readout.
Your findings are precise, reproducible, prioritized by impact, and useful to the engineers responsible for remediation.
The tools, methods, and written guidance you create make future assessments stronger and more efficient.
Teammates and clients seek your judgment because you explain tradeoffs clearly and challenge assumptions constructively.
Requirements
Requirements
- ·What You'll Bring
- ·Applied cryptography depth. Substantial experience evaluating cryptographic primitives, protocols, and implementations, with the judgment to distinguish theoretical concerns from practical security failures.
- ·Mathematical fluency. A foundation strong enough to read relevant academic papers, reason about security assumptions, and translate research into implementation-level questions.
- ·Code review and development skill. Proficiency in at least one systems or security-oriented language such as Rust, Go, C, or C++, plus experience using Git-based development workflows.
- ·Assessment judgment. The ability to form and test hypotheses, recognize where specifications and implementations diverge, document evidence, and prioritize findings by real-world impact.
Benefits
- ·Benefits Perks and Wellness
- ·Empowered Living
- ·Competitive salary complemented by performance-based bonuses.
- ·Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- ·A solid 401(k) plan with a 5% match of your base salary.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Trail of Bits, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$165k to $220k per year · You'll be taken to the employer's careers page.