Senior Security Engineer, Research & Engineering
What security roles in crypto pay
64 salaries · our own dataMost security roles in crypto pay between $145k and $268k, with a median of $202k.
As a Senior Security Engineer at Trail of Bits, you evaluate formally verified systems and their proofs to find what genuine mathematical guarantees actually establish versus what they leave out. You work in small teams conducting red-team evaluations on critical infrastructure, cryptographic systems, and AI inference platforms, using state-of-the-art tools and frontier AI models to break systems built to resist you.
What you'll do
- Break systems built to resist you by compromising designs and production software whose authors had proof assistants on their side, and demonstrate exploits rather than written arguments
- Map the real attack surface of a proof by establishing the formal property, the level it holds, the threat model behind it, and underlying assumptions, then show clients which give way under pressure
- Build the tooling that decides your coverage by designing and extending AI-driven discovery and triage systems that determine how much of a target a single engineer can reach within a short evaluation window
- Write assessments that become the record by setting out what held, what did not, and what you attempted without success, clearly enough that results stand up to product developers
- Raise the practice around you by publishing tooling and methodology, writing for the blog, presenting internally, and pulling what one engagement learns into the next
What you bring
- Direct hands-on red teaming experience with production software, personally responsible for finding and proving exploitable vulnerabilities
- Experience building AI-driven tooling for vulnerability discovery, such as agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation (you have written this tooling, not only used it)
- Experience applying formal methods to system designs and code implementations, including reading specifications and proof artifacts and reasoning about what a machine-checked proof does and does not establish; you can read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust
- Depth in a systems domain such as network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure
- Software development experience in Python, C++, and/or Rust
- Experience producing security assessment reports for an audience that will scrutinize every claim
- Proven delivery to fixed external schedules with defined acceptance criteria
- Experience in the ethical reporting of vulnerabilities in technology
Nice to have
- Published vulnerability research including CVEs, advisories, or talks at venues like OffensiveCon, RECon, CCC, or USENIX Security
- Experience auditing or contributing to a formally verified codebase such as HACL*, EverCrypt, seL4, CompCert, or CakeML
- Experience building automated bug-finding infrastructure at scale such as cyber reasoning systems, fuzzing fleets, or symbolic execution engines
- Experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling
- Experience attacking AI inference infrastructure including weight confidentiality and integrity, tenant isolation, or output mediation
- Participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar
- Experience with compiler technology, program analysis, or binary analysis
- Experience in reading, writing, and publishing academic papers
What we offer
- Competitive compensation complemented by performance-based bonuses
- $1,000 working-from-home stipend to create a comfortable and productive home office
- Annual $750 learning and development stipend for continuous personal and professional growth
- Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements
- Philanthropic contribution matching up to $2,000 annually
- Remote-first work within the United Kingdom
About Trail of Bits
Founded in 2012 by expert hackers, Trail of Bits combines novel research with practical solutions to reduce security risks from emerging technologies. With over 100 team members across time zones globally, the company operates a remote-first culture built on autonomy and trust, helping secure some of the world's most targeted organizations and devices.
