Senior Security Engineer, Application Security
Trail of Bits- Full Time
- Senior (5 to 8 years)
Candidates should possess at least 5 years of experience in Application or Product Security, demonstrating the ability to read and write production-quality code, and hands-on experience securing web applications while automating AppSec workflows. Familiarity with incident response fundamentals, coupled with a passion for eliminating root causes, is also required, along with experience securing LLM workflows as a plus.
As the Founding Application Security Engineer, the individual will map the product attack surface, rank risks, and publish a 12-month security roadmap, embed with development teams to run threat models and review critical PRs, help implement and deploy SAST, SCA, secrets-scan, DAST, and container/IaC checks in CI/CD, coordinate with DevOps for application security issues, support incident-response for product issues, and write customer-facing Product Security white-papers while providing compliance evidence.
Advanced data collection for national security
Vannevar Labs enhances national security by providing advanced data collection and analysis tools primarily for government agencies and defense contractors. Their main product, Decrypt, simplifies the process of gathering public data from hard-to-reach sources while ensuring secure and anonymous data collection. This platform decentralizes data collection, pulling information from various global sources without requiring user interaction, using layered obfuscation methods to protect data integrity and user identities. Decrypt's open architecture allows for quick integration with other applications, making it adaptable to various needs. Vannevar Labs operates on a subscription-based model, charging clients for access to Decrypt, which ensures a steady revenue stream. The company's goal is to leverage technology to improve national security and maintain its reputation as a trusted provider in the defense sector.