Engineering Director, Application Security
- Company
- Trail of Bits
- Location
- Remote
- Work type
- Full Time
- Posted
- 2026-08-07
Job description
What You’ll Achieve
Lead technical delivery. Own the quality and profitability of every engagement your team ships. Review findings, guide technical direction on complex audits, and step in when projects need senior expertise. Maintain direct relationships with your most important clients.
Staff and grow the practice. Make project assignment decisions that balance engineer development, client needs, and profitability. Manage utilization, identify when to hire, and build the pipeline through the intern program and recruiting. Own the practice's P&L.
Develop your engineers. Create space for your team to present at conferences, publish research, contribute to open source tools, and advance their careers. Identify and remove obstacles. Your success is measured by their output, not yours.
Set technical direction. Decide where the practice invests in tooling, methodology, and capability development. Stay hands-on enough to know what's working and what isn't. Ensure the team's approach evolves with the threat landscape and client needs.
Integrate AI into the practice. Champion and model the use of AI tools across your team's workflows. Help engineers adopt AI-assisted auditing, reporting, and research practices that amplify their effectiveness.
What You’ll Bring
10+ years in security, including significant time performing source code audits, not only penetration testing
Recent, demonstrable hands-on security work (code review, vulnerability research, tool development) within the last 12 months
Experience leading a team of 8+ engineers through client engagements with direct financial accountability
Proficiency in at least 4 of: Rust, Go, Python, C/C++, Solidity, JavaScript/TypeScript
Track record of managing project profitability, utilization, and staffing decisions in a consulting environment
Experience building team members' careers and external visibility (conference talks, publications, open source contributions)
Proficiency with AI coding and analysis tools in your own work
Active contributions to the security community (research, tools, advisories, publications)
BenefitsBenefits, Perks & Wellness
Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:
Empowered Living:
Competitive salary complemented by performance-based bonuses.
Fully company-paid insurance packages, including health, dental, vision, disability, and life.
A solid 401(k) plan with a 5% match of your base salary.
20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
Nurturing New Beginnings:
4 months of parental leave to cherish the arrival of new family members.
Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.
Work & Life Enrichment:
$1,000 Working-from-Home stipend to create a comfortable and productive home office.
Annual $750 Learning & Development stipend for continuous personal and professional growth.
Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.
Community Impact:
Philanthropic contribution matching up to $2,000 annually.
Skills Required
10+ years of experience in professional services delivery
Experience leading technical teams through client engagements
Proficiency in Secure Code Reviews, Dynamic Application Testing, Threat Modeling
Proficiency in AI tools and 4+ modern programming languages
In-depth understanding of application security vulnerabilities