← All jobs
TO

Senior Security Engineer, Research & Engineering (United Kingdom)

Trail of BitsUnited Kingdom
Type
Full-time
Work setup
On-site
Experience
Senior
Posted
Today

What security roles in crypto pay

74 salaries · our own data
median $200k$145k$268k

Most security roles in crypto pay between $145k and $268k, with a median of $200k.

As a Senior Security Engineer in Research & Engineering at Trail of Bits, you evaluate specifications, designs, and proofs to determine what has actually been established versus what has been assumed. You break systems built to resist you, demonstrating vulnerabilities in production software whose authors had formal verification on their side, and you build the AI-driven tooling that decides your coverage in red-team sprints.

What you'll do

  • Break systems and compromise designs and production software, demonstrating vulnerabilities with working exploits rather than written arguments alone
  • Map the real attack surface of a proof by establishing the formal property, the level it holds, the threat model, and underlying assumptions, then show clients which assumptions give way under pressure
  • Design and extend AI-driven discovery and triage systems, including agentic harnesses, LLM-assisted pipelines, and automated exploit generation, to determine how much ground a single engineer can cover within a red-team sprint window
  • Write security assessments that become the authoritative record, clearly setting out what held, what did not, and what you attempted without success
  • Raise the practice around you by publishing tooling and methodology, writing for the blog, presenting internally, and pulling lessons from one engagement into the next

What you bring

  • Direct hands-on red teaming experience finding and proving exploitable vulnerabilities in production software, not exercise coordination or scanner triage
  • Experience building AI-driven tooling for vulnerability discovery, such as agentic harnesses, LLM-assisted triage pipelines, or automated exploit generation, where you have written this tooling yourself rather than only used someone else's
  • Experience applying formal methods to system designs and code implementations, including reading specifications and proof artifacts and reasoning about what a machine-checked proof does and does not establish. You can read at least one of Lean, Rocq, F*, Dafny, or Verus/Rust
  • Depth in at least one systems domain: network protocol implementations, operating system internals, open-source software, cryptographic implementations, or AI inference infrastructure
  • Software development in Python, C++, and/or Rust
  • Experience producing security assessment reports for expert readers who will scrutinize every claim
  • Track record delivering to fixed external schedules with defined acceptance criteria
  • Experience in the ethical reporting and disclosure of vulnerabilities

Nice to have

  • Published vulnerability research including CVEs, advisories, or talks at venues such as OffensiveCon, RECon, CCC, or USENIX Security
  • Experience auditing or contributing to a formally verified codebase such as HACL*, EverCrypt, seL4, CompCert, or CakeML
  • Experience building automated bug-finding infrastructure at scale, such as cyber reasoning systems, fuzzing fleets, or symbolic execution engines
  • Experience with zero-knowledge proof systems, proof-checking kernels, or SMT-backed tooling
  • Experience attacking AI inference infrastructure including weight confidentiality and integrity, tenant isolation, or output mediation
  • Participation in CTF competitions, Pwn2Own, DARPA's AI Cyber Challenge, or similar
  • Experience with compiler technology, program analysis, or binary analysis
  • Experience reading, writing, and publishing academic papers

What we offer

  • Competitive compensation complemented by performance-based bonuses
  • $1,000 working-from-home stipend to create a comfortable and productive home office
  • Annual $750 learning and development stipend for continuous personal and professional growth
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community
  • Philanthropic contribution matching up to $2,000 annually
  • Remote work within the United Kingdom

About Trail of Bits

Founded in 2012 by expert hackers, Trail of Bits combines novel security research with practical solutions to help secure the world's most targeted organizations and technologies. With over 100 team members working across time zones globally, the company operates on a remote-first culture built on autonomy and trust, publishing open-source tools and ongoing security information through blogs, whitepapers, and newsletters.

Senior Security Engineer, Research & Engineering (United Kin | CryptoJobsHQ