Sobre este puesto de Senior Security Engineer Cryptography en Trail of Bits
United States | Remote | Full time
About Trail of Bits
Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.
Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.
Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable.
The Role
We're hiring a Senior Security Engineer for the Cryptography team to review and strengthen high-assurance software and cryptographic systems used across technology, finance, defense, and blockchain. You will evaluate whether cryptographic designs and implementations deliver the security properties they claim, find subtle failures where theory meets code, and help clients make sound decisions about risk and remediation.
On a typical engagement, you might review a new protocol, analyze an implementation of a standard primitive, test assumptions in a post-quantum construction, or build tooling that makes future assessments faster and more rigorous. The work spans code review, cryptanalysis, threat modeling, technical writing, and direct collaboration with client engineers.
This is a senior individual-contributor role. You will independently lead substantial parts of engagements, exercise judgment when the problem is ambiguous, communicate clearly with clients and peers, and help raise the technical bar for the cryptography team. You will also have room to contribute to open-source tools, public research, and new service offerings.
What You'll Do
- Lead cryptographic assessments. Review protocols, libraries, and application code; identify design and implementation weaknesses; validate exploitability; and recommend practical fixes.
- Analyze advanced constructions. Work across standardized symmetric and asymmetric cryptography, post-quantum schemes, zero-knowledge proof systems, and multi-party computation protocols, learning unfamiliar designs when an engagement demands it.
- Build useful tooling. Create or extend tools, test harnesses, and proofs of concept that improve cryptanalysis, implementation review, and repeatability across engagements.
- Own clear client delivery. Plan your work, surface risk early, lead technical discussions, and produce precise reports that explain both the finding and the engineering path forward.
- Shape the practice. Contribute to scoping and methodology, mentor other engineers, identify promising research or tooling opportunities, and help turn repeated client needs into stronger services.
- Share what you learn. Contribute to open-source projects and, when appropriate, publish technical work or present it to the security and cryptography communities.
How This Role Fits the Team
You will work within the Cryptography practice in our Assurance team, alongside engineers who review complex, high-assurance systems. Engagement teams are intentionally collaborative, but senior engineers are expected to own their technical lane, know when to pull in specialized expertise, and help clients move from a finding to a defensible engineering decision.
What Success Looks Like
- You independently lead technically complex assessment work from initial threat model through client readout.
- Your findings are precise, reproducible, prioritized by impact, and useful to the engineers responsible for remediation.
- The tools, methods, and written guidance you create make future assessments stronger and more efficient.
- Teammates and clients seek your judgment because you explain tradeoffs clearly and challenge assumptions constructively.
Requirements
What You'll Bring
- Applied cryptography depth. Substantial experience evaluating cryptographic primitives, protocols, and implementations, with the judgment to distinguish theoretical concerns from practical security failures.
- Mathematical fluency. A foundation strong enough to read relevant academic papers, reason about security assumptions, and translate research into implementation-level questions.
- Code review and development skill. Proficiency in at least one systems or security-oriented language such as Rust, Go, C, or C++, plus experience using Git-based development workflows.
- Assessment judgment. The ability to form and test hypotheses, recognize where specifications and implementations diverge, document evidence, and prioritize findings by real-world impact.
- Senior-level ownership. A record of independently driving complex technical work, managing ambiguity, making defensible decisions, and helping teammates improve their approach.
- Client communication. Clear writing and confident technical communication with engineers, researchers, and other stakeholders who will question assumptions and expect precise answers.
- Collaborative curiosity. A willingness to learn unfamiliar systems, share incomplete ideas early, and work closely with colleagues, clients, and the broader technical community.
Nice to Have
These are not day-one requirements, but they can help you contribute more quickly or broaden the role over time.
- Experience assessing post-quantum, zero-knowledge, threshold, multiparty-computation, or privacy-preserving systems.
- Published cryptography or security research, open-source contributions, public audit reports, conference talks, or technical writing.
- Experience designing cryptographic APIs, reviewing protocol specifications, or moving research implementations toward production use.
- Experience scoping security engagements, mentoring engineers, or developing repeatable assessment methodologies.
Compensation
The base salary range for this full-time position is $165,000 to $220,000, plus potential bonus. Compensation is informed by geographic location, relevant experience, and internal equity. These figures represent starting compensation for U.S.-based candidates. For specifics, please discuss with your recruiter during the hiring process.
Trail of Bits offers a comprehensive benefits package including health insurance, retirement contributions, professional development stipends, and generous PTO.
Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn More Here.
Trail of Bits is an equal-opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability, or any other characteristic protected by law, and we provide reasonable accommodations throughout the hiring process on request.
Benefits
Benefits Perks and Wellness
Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:
Empowered Living
- Competitive salary complemented by performance-based bonuses.
- Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- A solid 401(k) plan with a 5% match of your base salary.
- 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
Nurturing New Beginnings
- 4 months of parental leave to cherish the arrival of new family members.
- Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.
Work and Life Enrichment
- $1,000 Working-from-Home stipend to create a comfortable and productive home office.
- Annual $750 Learning & Development stipend for continuous personal and professional growth.
- Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.
Community Impact
- Philanthropic contribution matching up to $2,000 annually.