Zorky CRMZorky CRM
EN|RU
@termdocs
← All jobs

Senior Security Engineer Cryptography

senioroffice165,000 USDUnited States, USScore 75/100today
Market insights
📊 Security: salaries and demand on the market
Stack
blockchainc++gitsolid
Apply
Upload your CV — we will connect you with the employer directly through our pool.
Send your CV →
Description
United States | Remote | Full time About Trail of Bits Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology's newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client's capabilities are at the forefront of what's available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they'll understand why a company like ours is so unique and valuable. The Role We're hiring a Senior Security Engineer for the Cryptography team to review and strengthen high-assurance software and cryptographic systems used across technology, finance, defense, and blockchain. You will evaluate whether cryptographic designs and implementations deliver the security properties they claim, find subtle failures where theory meets code, and help clients make sound decisions about risk and remediation. On a typical engagement, you might review a new protocol, analyze an implementation of a standard primitive, test assumptions in a post-quantum construction, or build tooling that makes future assessments faster and more rigorous. The work spans code review, cryptanalysis, threat modeling, technical writing, and direct collaboration with client engineers. This is a senior individual-contributor role. You will independently lead substantial parts of engagements, exercise judgment when the problem is ambiguous, communicate clearly with clients and peers, and help raise the technical bar for the cryptography team. You will also have room to contribute to open-source tools, public research, and new service offerings. What You'll Do Lead cryptographic assessments. Review protocols, libraries, and application code; identify design and implementation weaknesses; validate exploitability; and recommend practical fixes. Analyze advanced constructions. Work across standardized symmetric and asymmetric cryptography, post-quantum schemes, zero-knowledge proof systems, and multi-party computation protocols, learning unfamiliar designs when an engagement demands it. Build useful tooling. Create or extend tools, test harnesses, and proofs of concept that improve cryptanalysis, implementation review, and repeatability across engagements. Own clear client delivery. Plan your work, surface risk early, lead technical discussions, and produce precise reports that explain both the finding and the engineering path forward. Shape the practice. Contribute to scoping and methodology, mentor other engineers, identify promising research or tooling opportunities, and help turn repeated client needs into stronger services. Share what you learn. Contribute to open-source projects and, when appropriate, publish technical work or present it to the security and cryptography communities. How This Role Fits the Team You will work within the Cryptography practice in our Assurance team, alongside engineers who review complex, high-assurance systems. Engagement teams are intentionally collaborative, but senior engineers are expected to own their technical lane, know when to pull in specialized expertise, and help clients move from a finding to a defensible engineering decision. What Success Looks Like You independently lead technically complex assessment work from initial threat model through client readout. Your findings are precise, reproducible, prioritized by impact, and useful to the engineers responsible for remediation. The tools, methods, and written guidance you create make future assessments stronger and more efficient. Teammates and clients seek your judgment because you explain tradeoffs clearly and challenge assumptions constructively. Requirements What You'll Bring Applied cryptography depth. Substantial experience evaluating cryptographic primitives, protocols, and implementations, with the judgment to distinguish theoretical concerns from practical security failures. Mathematical fluency. A foundation strong enough to read relevant academic papers, reason about security assumptions, and translate research into implementation-level questions. Code review and development skill. Proficiency in at least one systems or security-oriented language such as Rust, Go, C, or C++, plus experience using Git-based development workflows. Assessment judgment. The ability to form and test hypotheses, recognize where specifications and implementations diverge, document evidence, and prioritize findings by real-world impact. Senior-level ownership. A record of independently driving complex technical work, managing ambiguity, making defensible decisions, and helping teammates improve their approach. Client communication. Clear writing and confident technical communication with engineers, researchers, and other stakeholders who will question assumptions and expect precise answers. Collaborative curiosity. A willingness to learn unfamiliar systems, share incomplete ideas early, and work closely with colleagues, clients, and the broader technical community. Candidates must reside and be authorized to work in the United States without employer sponsorship. Nice to Have These are not day-one requirements, but they can help you c
Employer contacts (email/phone/telegram) are hidden from the public preview — send your CV, and we will connect you directly.
Urgent question? Message @termdocs