Senior Security Engineer, Research & Engineering
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
Trail of Bits is hiring a Senior Security Engineer for its Research & Engineering department.
The role focuses on evaluating formal proofs, attacking systems, and developing AI-native security evaluation capabilities.
The position is remote within the United Kingdom.
Key Skills for This Role
Full Job Posting
Role overview
Trail of Bits is hiring a Senior Security Engineer for its Research & Engineering department.
The role focuses on evaluating formal proofs, attacking systems, and developing AI-native security evaluation capabilities.
The position is remote within the United Kingdom.
Day-to-day work
- Evaluate specifications alongside designs and proofs to identify established properties, assumptions, and gaps.
- Use state-of-the-art tools and frontier AI models to investigate what formal proofs do not cover.
- Conduct red-team evaluations using agentic harnesses, triage pipelines, automated exploit generation, and related systems.
- Work in small teams and with third parties across multiple separate engagements.
- Report to a domain lead in applied cryptography, operating systems, applications, hardware, or AI infrastructure.
- Occasionally attend sprints and hackathon events in London.
What you’ll achieve
- Compromise designs and production software and demonstrate findings with working exploits.
- Map the real attack surface, threat model, trusted computing base, and assumptions behind a proof.
- Build tooling that determines evaluation coverage during short red-team windows.
- Write assessments that clearly record findings, limitations, and unsuccessful attempts.
- Publish tooling and methodology, present internally, and transfer lessons between engagements.
Required qualifications
- Direct experience red teaming production software and proving exploitable vulnerabilities through hands-on offensive work.
- Experience building AI-driven vulnerability discovery tooling, including agentic harnesses, LLM-assisted triage, or automated exploit generation.
- Experience applying formal methods to system designs and code implementations and interpreting proof artifacts.
- Ability to read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust.
- Experience finding vulnerabilities in network protocols, operating systems, open-source software, cryptographic implementations, or AI inference infrastructure.
- Experience with Python, C++, and/or Rust software development.
- Experience writing security assessment reports for expert readers.
- Experience delivering work to fixed external schedules with defined acceptance criteria.
- Experience with ethical vulnerability disclosure.
Preferred qualifications
- Published vulnerability research, including CVEs, advisories, or talks at relevant security venues.
- Experience auditing or contributing to formally verified codebases such as HACL*, EverCrypt, seL4, CompCert, or CakeML.
- Experience building automated bug-finding infrastructure at scale.
- Experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling.
- Experience attacking AI inference infrastructure, including weight confidentiality, tenant isolation, or output mediation.
- Participation in CTF competitions, Pwn2Own, DARPA’s AI Cyber Challenge, or similar events.
- Experience with compiler, program-analysis, or binary-analysis technology.
- Experience reading, writing, and publishing academic papers.
Compensation
- The description lists a salary range of USD 125,000–185,000.
- Performance-based bonuses are listed as part of the compensation package.
Benefits and wellness
- A $1,000 working-from-home stipend is provided for home-office setup.
- An annual $750 learning and development stipend supports professional growth.
- The company sponsors all-team celebrations, including travel and accommodation.
- Philanthropic contributions may be matched up to $2,000 annually.
About Trail of Bits
Trail of Bits develops research-based and custom-engineered security solutions for emerging technologies.
The company provides security information through blogs, whitepapers, newsletters, meetups, and open-source tools.
Its remote-first organization includes team members working across time zones around the globe.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career